AI Spear Phishing Messages Outperformed Humans

Researchers found that AI-generated scams successfully tricked more people than human-authored phishing attempts.

Updated on Sept. 20, 2026 in Artificial Intelligence

Isometric editorial illustration of a geometric server rack tower in a minimalist data facility, representing the automation of cyber threats.
A Brigham Young University study found that AI-generated spear phishing messages successfully secured more clicks than human-authored scams, highlighting a significant escalation in cybersecurity threats. AI Illustration. Upload story photo >

Live Poll

Do you trust your ability to distinguish between AI-generated scams and legitimate personal messages?

A study from Brigham Young University revealed that AI-generated spear phishing messages are more effective at securing clicks than those written by humans. The findings suggest that AI significantly increases the volume and persuasiveness of these digital scams.

Why it matters

AI tools allow scammers to craft highly personalized messages with minimal time and effort. This development represents a significant shift in cybersecurity threats, as the speed of generation now scales with the quality of deception.

AI-generated content matched or exceeded human performance in generating scam clicks 80% of the time. Additionally, messages referencing a coworker were 2.3 times more likely to be clicked than those originating from generic organizations.

The players

Brigham Young University

This private research university based in Provo, Utah, serves as the institution where the study was conducted.

The details

Scammers leverage personal data from social media, LinkedIn, and corporate directories to train AI agents to produce convincing, personalized phishing attacks. While AI creates these threats at a higher volume and speed, participants in the study correctly identified the message source as human or AI only 52% of the time.

Timeline

  1. September 20, 2026: Researchers published the findings from Brigham Young University.

The Tech Race

This research highlights a pivotal shift in the AI arms race where the efficiency of generative models directly enables more potent social engineering threats. It signals a move away from manual, time-intensive phishing campaigns toward automated systems that replace legacy, human-crafted attack vectors.

Users should be increasingly wary of messages that reference specific coworkers or professional contacts, as these are statistically the most likely to result in a malicious click. Organizations and individuals must treat personalized digital communication with higher levels of scrutiny to account for the increased success rate of AI-driven deception.

The takeaway

Individuals should adopt a 'verify before clicking' mindset when receiving any message, even those appearing to come from known colleagues. Because AI can easily scrape public data to build rapport, verify the request through a secondary, trusted communication channel before taking action.

Further reading

Learn more about the latest developments in Artificial Intelligence security research.

Source note: This article includes information reported by KSL.

Live Poll

Do you trust your ability to distinguish between AI-generated scams and legitimate personal messages?