Humans or AI? Who or what can scam you more effectively?
A text from your neighborhood gardening club friend Ben offering a deal on seeds might seem too specific to be a scam. But that kind of personalization is exactly what can make phishing messages convincing.
Spear-phishing attacks, which use personal information to make messages more convincing, are becoming increasingly common. A recent study by BYU researchers found that AI-generated phishing messages can be even more effective than human-created scams, with AI matching or outperforming humans in generating clicks in 80% of cases.
The research, led by BYU cybersecurity professor Derek Hansen, found that participants struggled to determine whether a message was AI-generated or human-written, correctly identifying the source only 52% of the time. Messages that included personal details such as a person's job or workplace were the most convincing. As more personal information becomes available online, AI can quickly gather and use this data to create convincing phishing messages at a rapid pace.
To protect against these attacks, the researchers recommend verifying unexpected messages through separate, trusted channels, even if they contain personal details that seem relevant.
Written by urgent.news from Phys.org's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
