AI Phishing Messages Outperformed Human Scams

Research from Brigham Young University demonstrates that AI agents increase the efficacy of spear phishing by leveraging personalized data.

Updated on Sept. 20, 2026 in Artificial Intelligence

Isometric editorial illustration of a complex lattice of geometric nodes and lines, representing the structure of digital data-driven communication.
Researchers at Brigham Young University found that AI-generated spear phishing messages are significantly more effective at deceiving recipients than those written by humans. AI Illustration. Upload story photo >

Live Poll

Do you trust your ability to distinguish between AI-generated scams and legitimate personal messages?

Researchers at Brigham Young University have found that AI-generated spear phishing messages are more effective at deceiving recipients than those written by humans. The study, published on September 20, 2026, indicates that AI-generated content outperforms human-authored scams in driving clicks at a higher frequency.

Why it matters

AI lowers the barrier to entry for cybercriminals by drastically reducing the time and labor required to craft highly personalized spear phishing attacks. This shift enables the generation of tailored scams at an unprecedented volume and speed.

AI messages matched or outperformed human-written scams in 80% of trials, with messages referencing a coworker resulting in 2.3 times more clicks than generic organizational outreach. Participants were only able to distinguish between AI and human authorship 52% of the time.

The players

Brigham Young University

A research institution based in Provo that conducts studies on human behavior and computer-mediated communication.

The details

Scammers leverage personal data scraped from LinkedIn, social media, and organizational directories to populate AI agents with context. These agents then synthesize the gathered intelligence into personalized spear phishing attacks—a method of deceptive communication targeted at specific individuals or groups. By automating the integration of social graph data, AI eliminates the manual effort once required to make fraudulent messages appear credible.

Timeline

  1. September 20, 2026: Publication of the BYU research findings.

The Tech Race

This finding underscores the shift in the adversarial landscape from generic mass phishing to highly targeted, AI-driven social engineering. It confirms that automated models have now reached a performance milestone that consistently exceeds human capabilities in deceptive engagement.

Individuals should remain skeptical of any message containing highly specific coworker references, as these are statistically the most likely to elicit a harmful click. Organizations may need to move beyond traditional spam filters toward training protocols that emphasize the identification of hyper-personalized social engineering.

The takeaway

The research confirms that AI-authored scams effectively exploit human trust through personalization, making manual verification of senders more critical than ever. Security teams should monitor future updates on whether specific defensive LLM detectors can reliably mitigate this 28% success rate gap.

Further reading

For more on the implications of machine-generated communication, see the latest research in Artificial Intelligence.

Source note: This article includes information reported by KSL.

Live Poll

Do you trust your ability to distinguish between AI-generated scams and legitimate personal messages?

AI Phishing Messages Outperformed Human Scams