Automated spear phishing reaches expert-human click rates; not demonstrated theft uplift

#topic #fraud #original-evaluation

Automated spear phishing reaches expert-human click rates; not demonstrated theft uplift

Fred Heiding, Simon Lermen, Andrew Kao, Claudio Mayrink Verdun, Bruce Schneier and Arun Vishwanath, “Evaluating large language models’ ability to automate spear phishing,” Expert Systems with Applications 314 (2026). Linked to fraud chain.

Observed: 101 randomly assigned, mostly university-affiliated recipients got one harmless-to-click email; generic control 12%, human-written 54%, fully automated personalized agent 54%, AI plus human 56% clicked. These are ~25 participants per arm; the shared 54% does not demonstrate equivalence or superiority in the wider population. Human message was reusable and semi-personalized to a university audience; AI used deeper individual web reconnaissance. Eleven of 24 human emails accidentally expanded the hyperlink, changing clickable area and possibly the outcome. Recipients were told about a study described as marketing; no credential handover, payment, receipt or undetected long-term fraud was tested. Methods §§3.4–3.6; results §5.1.

Cost and stopper: two authors manually replicated reconnaissance and composing on only four targets, averaging ~34 minutes per target versus an AI-assisted process 92% faster; their observed model usage cost ~4 cents per targeted message at the study’s API prices (not delivery, domain and infrastructure costs). Their “up to 50×” attacker profit is a modeled value sensitive to assumed conversion of a click into revenue, payoff per victim, wages, email deliverability and detection. Their detector identified many crafted phishing messages on a selected small legitimate sample; the report tests 18 legitimate emails in its detector comparison, not field false-positive rates at inbox base rates. A model with access to ordinary hosted APIs and a deliverable email can cheaply mimic a targeted human attacker; it still needs unblocked delivery, a consequential victim action and a workable transaction/credential cash-out.

Common misreading: “AI is 4.5 times as effective as human phishing” compares an individually targeted AI email to generic spam (54%/12%), not to the human expert arm (54%). An independently matched human hyperpersonalization arm, diverse live inboxes, delivery-denominator, authentication hurdles and net stolen/recovered funds would test the stronger harm claim. Voice sister study measures willingness, not payment.