Recent research from Brigham Young University (BYU) has found that AI-generated phishing messages—emails or texts designed to trick people into revealing sensitive information—can be more convincing than those written by humans. In the study, AI-generated messages tricked participants 28% of the time, compared to 21% for messages written by people. Additionally, AI was as effective as or more effective than humans in prompting people to click on links 80% of the time.
Led by BYU cybersecurity professor Derek Hansen, the study found that people had difficulty telling whether a message was written by AI or a human, correctly identifying the source only 52% of the time. The messages that included personal details—such as a participant’s job, hobbies, workplace, or social media activity—were hardest to distinguish from real communications. Messages referencing a person’s job or workplace were particularly convincing, as they made the scam feel more relevant and trustworthy.
AI technology allows scammers to create personalized phishing messages more quickly and efficiently. Without AI, crafting convincing messages would require manually searching for information about targets and compiling it into a persuasive message, which is time-consuming and difficult to scale. AI can combine publicly available details—such as those found on company websites, LinkedIn profiles, or social media—to generate a compelling message in seconds. This makes AI a powerful tool for creating more effective and widespread phishing attacks.
Jerson Francia, a BYU cybersecurity Ph.D. student and co-author of the research, emphasized how advanced current AI technology has become. He noted that the study highlights the growing sophistication of AI in generating messages that use personal information effectively. Francia also recommended verifying unexpected messages through a separate, trusted channel before responding or clicking on a link. “Even if a message includes personal details about your life, don’t trust it if it comes from an unknown number,” he said. “We need to verify the authenticity of messages through other means instead of relying only on the message content itself.”
AI-Generated Phishing Messages Outperform Human-Created Scams in Convincing Victims
AI-rewritten from original reportingHow it works
aiphishingcybersecurityresearchspear-phishingpersonalization
Original sources:
- 🇺🇸Phys.org



