The Numbers That Should Concern You
The BYU research, led by cybersecurity professor Derek Hansen, put participants through a test: identify whether a message was written by a human or an AI. The result? People got it right only 52% of the time — barely better than a coin flip.
When it came to actually falling for the scam, AI-generated messages fooled people about 28% of the time, compared to 21% for human-authored ones. That 7-point gap may sound small, but at scale — across millions of messages — it represents a massive increase in successful attacks.
Why Personalization Is the Real Weapon
The specific technique driving these results is spear phishing — targeted messages that reference personal details like your job title, employer, coworkers, or hobbies. Unlike generic phishing blasts, spear phishing feels relevant. It feels like it was written for you.
According to the BYU findings, messages that mentioned a coworker were 2.3 times more likely to be clicked than messages from a generic organization. Job-related details were the most convincing category overall.
Here’s the problem: the personal information needed to build these messages is largely public. LinkedIn profiles, company websites, social media accounts, and organizational directories are enough. AI can scrape and synthesize that data in seconds — something that would take a human scammer hours to do manually, and would be nearly impossible to execute at scale.
AI Agents Are Automating the Attack Pipeline
This isn’t just about better-written emails. Scammers are now deploying AI agents to generate personalized spear phishing attacks in volume. What was once a slow, manual process — research a target, craft a message, send, repeat — can now be automated end to end.
“AI can reduce the time and effort required to create personalized spear-phishing messages, thus making them more effective and more common,” said Professor Hansen.
The implication is significant: the barrier to running a sophisticated, targeted phishing campaign has dropped dramatically. You no longer need a skilled social engineer. You need a prompt and a list of targets.
This broader shift aligns with concerns about AI-powered hacking tools lowering the barrier to cybercrime.
You Can’t Rely on Reading the Message Anymore
This is the uncomfortable core of the BYU findings. The traditional advice — look for awkward phrasing, odd formatting, or impersonal language — no longer holds. AI-generated text is fluent, contextually aware, and increasingly indistinguishable from something a real person wrote.
As BYU put it in their release:
“You may no longer be able to recognize AI-generated phishing simply by how a message is written.”
That means the detection layer has to move. Instead of evaluating the content of a message, you need to verify the source through independent means.
What the Researchers Actually Recommend
The BYU team offered practical, actionable guidance — not vague warnings. Here’s what they suggest:
- Don’t click links in messages. Type the website address directly into your browser instead.
- Verify through a known channel. If a message claims to be from your bank, a coworker, or a vendor, contact them using a phone number or email you already have on file — not one provided in the message.
- Treat unknown numbers with suspicion. Even if a text references personal details about your life, that’s no longer a signal of legitimacy.
- Never share passwords, ID numbers, financial information, or security codes in response to unexpected requests.
- Run suspicious links through tools like VirusTotal, URLVoid, or ScanURL before clicking.
- Report suspicious messages to your workplace, school, or relevant security team.
The Broader Cybersecurity Implication
For individuals, this is a reminder that online privacy has direct security consequences. The more personal data you make publicly available — on LinkedIn, social media, company directories — the more material exists to build a convincing attack against you.
For organizations, the risk is systemic. A single employee clicking a well-crafted spear phishing link can expose credentials, financial data, or internal systems. Security training that focuses on spotting “bad writing” needs to be updated. The new standard is verification, not evaluation.
AI tools are genuinely useful across dozens of workflows. But the same capabilities that make them powerful for productivity make them powerful for manipulation. The BYU research doesn’t argue against AI — it argues for a clearer-eyed understanding of what it can do in the wrong hands.
The smartest move right now isn’t paranoia. It’s updating your default behavior: when in doubt, verify through a channel you control, not one the message provides. That kind of shift also connects to broader questions of AI governance and security priorities.
Comments (0) No comments yet
Want to join this discussion? Login or Register.
No comments yet. Be the first to share your thoughts!