Cybersecurity & Protection

AI Spear Phishing Tested: Personalization Triples the Click Rate

Aug 12, 2026 3 min read
All articles

AI makes phishing more dangerous, and measurably so. A large-scale study shows that AI-assisted personalization nearly triples the success rate of phishing emails. The research involved teams from the Berlin Institute for the Foundations of Learning and Data (Bifold), TU Berlin, the French institute Inria, and Ruhr University Bochum.

How the experiment worked

The field experiment involved 7,741 employees of TU Braunschweig. To simulate personalized attacks at scale, the team used only the targets' email addresses as search queries in search engines, gathering publicly available information such as professional background, activities, interests, and affiliations. From this data, locally hosted AI models generated detailed profiles and emails tailored to them.

The result is clear. Generic emails reached a click rate of 3.9 percent, while the automatically personalized messages hit 10.0 percent. In other words, AI-assisted personalization boosted the success rate to almost triple. This effect appeared regardless of whether the generic messages were written by humans or likewise generated by an AI.

Cheap, fast, and hard to filter

Manually written spear-phishing emails achieved the highest click rate at 24.2 percent, but took around seven minutes of effort per message. The AI workflow, by contrast, needed only about 45 seconds per email and cost around 0.03 US dollars per address. That lets attackers scale personalized campaigns very cheaply.

The influence of data volume was unexpected. People with especially extensive online profiles clicked less often than those with low to moderate amounts of data. The reason: with a lot of input data, the language models leaned more toward abstraction and less often reused specific details directly in the messages.

What it means for protection

The authors stress the need for layered protective measures. Technical filters struggle to detect human-seeming messages, and in the experiment the university's security system caught just one of 3,949 emails. Among their recommendations: reduce the amount of linkable personal data online, expand security training to cover AI-assisted personalization, and strengthen technical safeguards like multi-factor authentication.