AI Will Increase the Quantity—and Quality—of Phishing Scams

#summary

AI Will Increase the Quantity—and Quality—of Phishing Scams

The authors break a phishing campaign into finding targets, researching them, writing messages, delivering them and learning which messages worked. They argue that ordinary language-model services can automate much of the costly research and writing that once restricted personalized attacks to valuable targets. In their earlier experiment with 112 recruited recipients, 37% clicked the AI-written email, compared with 74% for the human-expert version and 62% for an expert-edited AI version. They also test models as phishing detectors, but on a very small set of legitimate messages; defense might improve too.

A later study by the same research group found equal 54% click rates for automated and human-expert messages in a different, 101-person trial. Its 12% rate was for generic spam, not expert humans: the frequently repeated claim that AI is four times better than people makes the wrong comparison. Clicks are not credential theft or unrecovered transfers. An observed criminal network did use ChatGPT to assist scams, but its reported victim losses could not be verified; bank freezes and delivery controls remain possible intervening checks. The authors’ forecast of large-scale financial harm still needs a measured click-to-cash-out pathway.

Read at schneier.com · 7 min