Supports · 2024
Evaluating Large Language Models' Capability to Launch Fully Automated Spear Phishing Campaigns: Validated on Human Subjects
Fred Heiding, Simon Lermen, Andrew Kao, Bruce Schneier, Arun Vishwanath
Key finding
Fully AI-automated spear-phishing emails drew a 54% click-through rate, matching human experts (54%) and far above arbitrary control phishing (12%), a big jump from comparable AI results a year earlier. The AI's reconnaissance profiles were accurate and useful for 88% of targets, and AI can raise attacker profitability up to 50-fold at scale.
Why it mattersSignals that personalized, psychologically tuned social engineering is now cheap and automated, so defenses must rest on recognizing manipulation tactics rather than message quality.
Informs- Verifies unusual requests through a second channel supports
- Stays alert to personalized, well-written messages supports
Heiding, F., Lermen, S., Kao, A., Schneier, B., & Vishwanath, A. (2024). Evaluating Large Language Models' Capability to Launch Fully Automated Spear Phishing Campaigns: Validated on Human Subjects. arXiv:2412.00586. https://arxiv.org/abs/2412.00586