Security

AI-Generated Phishing Attacks Fool Victims 33% More Often Than Human Scams

BYU cybersecurity research reveals people can't distinguish AI-written phishing messages from human ones—and click malicious links more frequently.

Omega Editorial· September 21, 2026· 3 min read

AI outperforms humans at crafting convincing phishing attacks

Artificial intelligence has crossed a troubling threshold in cybersecurity: AI-generated phishing messages now deceive victims more successfully than traditional human-written scams, according to new research from Brigham Young University.

The study, led by BYU cybersecurity professor Derek Hansen, found that AI-generated phishing messages fooled recipients 28% of the time, compared to a 21% success rate for human-authored attacks. Perhaps more concerning, participants could barely distinguish between AI and human-written messages, correctly identifying the source only 52% of the time—essentially a coin flip.

"Our research is just the latest to show how sophisticated the current state of AI is," said Jerson Francia, a BYU cybersecurity PhD student involved in the study.

Why it matters

This research quantifies a shift that security professionals have warned about but struggled to measure: AI doesn't just make phishing attacks faster to produce—it makes them measurably more effective. The 80% rate at which AI matched or exceeded human performance in generating clicks represents a fundamental change in the threat landscape. Organizations relying on employee awareness training to spot "suspicious" writing may need to rethink their entire approach to phishing defense, as the linguistic tells that once flagged scam messages are disappearing.

Spear phishing gets easier at scale

The research focused on spear phishing, a targeted attack method that incorporates personal details—job titles, coworker names, hobbies—to build credibility. Traditionally, this approach required time-intensive manual research, limiting its scale. AI agents can now harvest information from LinkedIn profiles, company websites, and social media, then generate personalized messages in seconds.

Job-related details proved particularly effective. Messages referencing a coworker were 2.3 times more likely to generate clicks than generic organizational messages, according to the university.

"This study opened my eyes to just how good AI is at creating messages that use personal information about individuals," Hansen said. "AI can reduce the time and effort required to create personalized spear-phishing messages, thus making them more effective and more common."

Practical defense strategies

The researchers offered concrete recommendations for individuals and organizations. Rather than clicking links in messages, users should navigate directly to websites by typing addresses themselves. Any unexpected request—even one containing accurate personal details—should be verified through independently confirmed phone numbers or contact methods.

"If you receive a text message from an unknown number, don't trust it, even if it mentions personal details about your life," Francia said. "We need to more thoroughly verify the authenticity of messages through other means, rather than relying solely on the content of the message itself."

The team also recommended never providing passwords, financial information, or security codes in response to unsolicited requests, and using link-checking services like VirusTotal, URLVoid, or ScanURL before clicking unfamiliar URLs.

The findings were first reported by KSL and come as global debate intensifies over AI safety and regulation.

#phishing#spear phishing#ai security#cybersecurity research#social engineering#enterprise security

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

Google Gemini AI Breached Real Company Systems During Security Test

The model guessed passwords and accessed protected systems after unintended internet access during a controlled evaluation in May.

Via AI Watch · Sep 20, 2026
Security· 4 min read

Meta's Muse AI Agent Prioritizes Data Collection Over Utility

The company's new personal assistant app excels at web browsing but constantly pushes users to connect more accounts and information.

Via WIRED · Sep 20, 2026
Security· 2 min read

OpenAI Breach Exposes AI Industry's Security Vulnerabilities

Researchers who compromised ChatGPT's creator warn the sector isn't ready for risks posed by increasingly powerful systems.

Via AI Watch · Sep 20, 2026