AI Phishing Messages Outperformed Human Scams
Research from Brigham Young University demonstrates that AI agents increase the efficacy of spear phishing by leveraging personalized data.
Updated on Sept. 20, 2026 in Artificial Intelligence

Live Poll
Do you trust your ability to distinguish between AI-generated scams and legitimate personal messages?
Researchers at Brigham Young University have found that AI-generated spear phishing messages are more effective at deceiving recipients than those written by humans. The study, published on September 20, 2026, indicates that AI-generated content outperforms human-authored scams in driving clicks at a higher frequency.
Why it matters
AI lowers the barrier to entry for cybercriminals by drastically reducing the time and labor required to craft highly personalized spear phishing attacks. This shift enables the generation of tailored scams at an unprecedented volume and speed.
AI messages matched or outperformed human-written scams in 80% of trials, with messages referencing a coworker resulting in 2.3 times more clicks than generic organizational outreach. Participants were only able to distinguish between AI and human authorship 52% of the time.
The players
Brigham Young University
A research institution based in Provo that conducts studies on human behavior and computer-mediated communication.
The details
Scammers leverage personal data scraped from LinkedIn, social media, and organizational directories to populate AI agents with context. These agents then synthesize the gathered intelligence into personalized spear phishing attacks—a method of deceptive communication targeted at specific individuals or groups. By automating the integration of social graph data, AI eliminates the manual effort once required to make fraudulent messages appear credible.
Timeline
September 20, 2026: Publication of the BYU research findings.
The Tech Race
This finding underscores the shift in the adversarial landscape from generic mass phishing to highly targeted, AI-driven social engineering. It confirms that automated models have now reached a performance milestone that consistently exceeds human capabilities in deceptive engagement.
Individuals should remain skeptical of any message containing highly specific coworker references, as these are statistically the most likely to elicit a harmful click. Organizations may need to move beyond traditional spam filters toward training protocols that emphasize the identification of hyper-personalized social engineering.
The takeaway
The research confirms that AI-authored scams effectively exploit human trust through personalization, making manual verification of senders more critical than ever. Security teams should monitor future updates on whether specific defensive LLM detectors can reliably mitigate this 28% success rate gap.
Further reading
For more on the implications of machine-generated communication, see the latest research in Artificial Intelligence.
Source note: This article includes information reported by KSL.
Live Poll
Do you trust your ability to distinguish between AI-generated scams and legitimate personal messages?









