← Studies

Supports · 2024

Evaluating Large Language Models' Capability to Launch Fully Automated Spear Phishing Campaigns: Validated on Human Subjects

Fred Heiding, Simon Lermen, Andrew Kao, Bruce Schneier, Arun Vishwanath

Key finding

Fully AI-automated spear-phishing emails drew a 54% click-through rate, matching human experts (54%) and far above arbitrary control phishing (12%), a big jump from comparable AI results a year earlier. The AI's reconnaissance profiles were accurate and useful for 88% of targets, and AI can raise attacker profitability up to 50-fold at scale.

Why it matters

Signals that personalized, psychologically tuned social engineering is now cheap and automated, so defenses must rest on recognizing manipulation tactics rather than message quality.

Informs Cite
Heiding, F., Lermen, S., Kao, A., Schneier, B., & Vishwanath, A. (2024). Evaluating Large Language Models' Capability to Launch Fully Automated Spear Phishing Campaigns: Validated on Human Subjects. arXiv:2412.00586. https://arxiv.org/abs/2412.00586