Banner Banner

AI Goes Phishing

BIFOLD study shows AI-generated phishing emails are three times as effective as generic ones and cost next to nothing.

Field experiment with 7,700 participants provides the first large-scale evidence of how cheaply and effectively language models can personalize phishing.

An email, apparently from a colleague, with the correct name, a current project, a familiar tone, and a link… who wouldn't click? Personalized phishing has always been the most effective kind, and the most expensive to produce. AI removes the cost. A research team from BIFOLD/TU Berlin, Inria, and Ruhr University Bochum has now put numbers to it, in the largest field study of its kind to date.

Spear phishing increases link click rates by a factor of 2.4

Conventional phishing is often recognizable to trained eyes due to its impersonal wording. By contrast, emails individually tailored to the victim are significantly more convincing. This is known as spear phishing. Until now, this type of attack was labor-intensive, since criminals had to research each target individually by hand. That barrier is now vanishing: large language models can gather publicly available information about a person from the internet and compose a customized phishing email, entirely without human involvement. How much this actually raises the success rate of an attack, and at what cost, had not been measured under realistic conditions so far.

Automated personalization costs just around $0.03 per email

In a controlled field experiment with 7,741 participants, the researchers compared four attack variants: manually created versus AI-generated and generic versus personalized phishing emails. The result: personalized, AI-generated phishing achieved 2.4 times the click rate of generic phishing. The authors' cost analysis shows that this automated personalization costs only around $0.03 per email, making this type of attack economically viable even for criminals with small budgets. While human-crafted attacks still achieve the highest success rates, they cannot be produced at this scale or price.

Several features of the study design suggest the true effect is larger: only simple, locally run language models were used, participants knew in advance that they were taking part in a study, and all had already received security training. In less controlled environments, and with more powerful models, click rates are likely to be higher still.

Protective measures are not keeping up

The study concludes that current defenses are not equipped for automated threats of this kind. The researchers recommend three courses of action. First, organizations and individuals should reduce the public linkability of personal information online. Second, awareness training needs to include personalized attacks, so that users understand that threats can appear personal and targeted. Finally, existing security measures for containment should be applied more rigorously, on the assumption that some accounts will eventually be compromised via personalized phishing.

USENIX Security Symposium 2026

The study will be presented on Wednesday, August 12, 2026, at the USENIX Security Symposium 2026 in Baltimore.

Title: A Large-Scale Study of Personalized Phishing using Large Language Models
Authors: Stefan Czybik (BIFOLD & TU Berlin), Anne Josiane Kouam (Inria & TU Berlin), Peter Heubl (Ruhr University Bochum), Jan Magnus Nold (Ruhr University Bochum), Konrad Rieck (BIFOLD & TU Berlin)
Preprint: https://www.usenix.org/conference/usenixsecurity26/presentation/czybik