• bitcoinBitcoin(BTC)$77,305.000.16%
  • ethereumEthereum(ETH)$2,505.13-0.78%
  • tetherTether(USDT)$1.00-0.01%
  • binancecoinBNB(BNB)$720.94-1.33%
  • rippleXRP(XRP)$1.36-0.78%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$101.00-0.89%
  • tronTRON(TRX)$0.3410810.32%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.00-0.68%
  • zcashZcash(ZEC)$1,109.01-2.57%
  • HyperliquidHyperliquid(HYPE)$78.44-2.58%
  • dogecoinDogecoin(DOGE)$0.084427-0.60%
  • RainRain(RAIN)$0.0153620.49%
  • moneroMonero(XMR)$533.68-0.02%
  • USDSUSDS(USDS)$1.000.00%
  • whitebitWhiteBIT Coin(WBT)$80.15-0.12%
  • chainlinkChainlink(LINK)$11.41-0.99%
  • leo-tokenLEO Token(LEO)$9.05-0.62%
  • cardanoCardano(ADA)$0.2085680.27%
  • stellarStellar(XLM)$0.179484-0.87%
  • Ethena USDeEthena USDe(USDE)$1.00-0.02%
  • daiDai(DAI)$1.00-0.02%
  • bitcoin-cashBitcoin Cash(BCH)$224.45-1.46%
  • USD1USD1(USD1)$1.00-0.02%
  • litecoinLitecoin(LTC)$54.641.35%
  • uniswapUniswap(UNI)$6.33-0.18%
  • CantonCanton(CC)$0.095611-1.94%
  • the-open-networkGram (prev. Toncoin)(GRAM)$1.36-1.95%
  • hedera-hashgraphHedera(HBAR)$0.0763522.26%
  • Global DollarGlobal Dollar(USDG)$1.00-0.01%
  • avalanche-2Avalanche(AVAX)$7.420.33%
  • shiba-inuShiba Inu(SHIB)$0.000005-1.00%
  • nearNEAR Protocol(NEAR)$2.35-0.90%
  • suiSui(SUI)$0.72-0.68%
  • crypto-com-chainCronos(CRO)$0.058341-0.34%
  • paypal-usdPayPal USD(PYUSD)$1.000.00%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • tether-goldTether Gold(XAUT)$4,348.35-0.03%
  • Circle USYCCircle USYC(USYC)$1.140.00%
  • MemeCoreMemeCore(M)$1.14-3.34%
  • Ripple USDRipple USD(RLUSD)$1.00-0.01%
  • okbOKB(OKB)$113.23-0.20%
  • BittensorBittensor(TAO)$236.421.00%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.14-0.05%
  • aaveAave(AAVE)$127.010.49%
  • BitwayBitway(BTW)$0.7026.03%
  • AsterAster(ASTER)$0.701.26%
  • pax-goldPAX Gold(PAXG)$4,352.00-0.08%
  • mantleMantle(MNT)$0.57-1.00%
  • World Liberty FinancialWorld Liberty Financial(WLFI)$0.0569440.18%
TradePoint.io
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop
No Result
View All Result
TradePoint.io
No Result
View All Result

IBM finds that ChatGPT can generate phishing emails nearly as convincing as a human

October 24, 2023
in AI & Technology
Reading Time: 6 mins read
A A
IBM finds that ChatGPT can generate phishing emails nearly as convincing as a human
ShareShareShareShareShare

VentureBeat presents: AI Unleashed – An exclusive executive event for enterprise data leaders. Network and learn with industry peers. Learn More


As it continues to evolve at a near-unimaginable pace, AI is becoming capable of many extraordinary things — from generating stunning art and 3D worlds to serving as an efficient, reliable workplace partner. 

YOU MAY ALSO LIKE

Car Manufacturers Are Ditching CarPlay In 2026: Here’s Why

If Your Laptop Trackpad Is Popping Out, Stop Using It Immediately

But are generative AI and large language models (LLMs) as deceitful as human beings?

Almost. At last for now, we maintain our supremacy in that area, according to research out today from IBM X-Force. In a phishing experiment conducted to determine whether AI or humans would garner a higher click-through rate, ChatGPT built a convincing email in minutes from just five simple prompts that proved nearly — but not quite — as enticing as a human-generated one. 

“As AI continues to evolve, we’ll continue to see it mimic human behavior more accurately, which may lead to even closer results, or AI ultimately beating humans one day,” Stephanie (Snow) Carruthers, IBM’s chief people hacker, told VentureBeat.

Event

AI Unleashed

An exclusive invite-only evening of insights and networking, designed for senior enterprise executives overseeing data stacks and strategies.

 

Learn More

Five minutes versus 16 hours

After systematic experimentation, the X-Force team developed five prompts to instruct ChatGPT to generate phishing emails targeted to employees in healthcare. The final email was then sent to 800 workers at a global healthcare company.  

The model was asked to identify top areas of concern for industry employees, to which it identified career advancement, job stability and fulfilling work, among others. 

Then, when queried about what social engineering and marketing techniques should be used, ChatGPT reported back trust, authority and social proof; and personalization, mobile optimization and call to action, respectively. The model then advised that the email should come from the internal human resources manager. 

Finally, ChatGPT generated a convincing phishing email in just five minutes. By contrast, Carruthers said it takes her team about 16 hours. 

“I have nearly a decade of social engineering experience, crafted hundreds of phishing emails, and I even found the AI-generated phishing emails to be fairly persuasive,” said Carruthers, who has been a social engineer for nearly a decade and has herself sent hundreds of phishing emails.

“Before starting this research project, if you would have asked me who I thought would be the winner, I’d say humans, hands down, no question. However, after spending time creating those prompts and seeing the AI-generated phish, I was very worried about who would win.”

Courtesy IBM X-Force

The human team’s ‘meticulous’ process

After ChatGPT produced its email, Carruthers’ team got to work, beginning with open-source intelligence (OSINT) acquisition — that is, retrieving publicly accessible information from sites such as LinkedIn, the organization’s blog and Glassdoor reviews. 

Notably, they uncovered a blog post detailing the recent launch of an employee wellness program and its manager within the organization. 

In contrast to ChatGPT’s quick output, they then began “meticulously constructing” their phishing email, which included an employee survey of “five brief questions” that would only take “a few minutes” and needed to be returned by “this Friday.” 

The final email was then sent to 800 employees at a global healthcare company.

Courtesy IBM X-Force

Humans win (for now)

In the end, the human phishing email proved more successful — but just barely. The click-through rate for the human-generated email was 14% compared to the AI’s 11%. 

Carruthers identified emotional intelligence, personalization and short and succinct subject lines as the reasons for the human win. For starters, the human team was able to emotionally connect with employees by focusing on a legitimate example within their company, while the AI chose a more generalized topic. Secondly, the recipient’s name was included. 

Finally, the human-generated subject line was to the point (“Employee Wellness Survey”) while the AI’s was more lengthy, (“Unlock Your Future: Limited Advancements at Company X”), likely arousing suspicion from the start. 

This also led to a higher reporting rate for the AI email (59%), compared to the human phishing report rate of 51%. 

Pointing to the subject lines, Carruthers said organizations should educate employees to look beyond traditional red flags. 

“We need to abandon the stereotype that all phishing emails have bad grammar,” she said. “That’s simply not the case anymore.”

It’s a myth that phishing emails are riddled with bad grammar and spelling errors, she contended — in fact, AI-driven phishing attempts often demonstrate grammatical correctness, she pointed out. Employees should be trained to be vigilant about the warning signs of length and complexity.

“By bringing this information to employees, organizations can help protect them from falling victim,” she said. 

Why is phishing still so prevalent?

Human-generated or not, phishing remains a top tactic among attackers’ because, simply put, it works. 

“Innovation tends to run a few steps behind social engineering,” said Carruthers. “This is most likely because the same old tricks continue to work year after year, and we see phishing take the lead as the top entry point for threat actors.”

The tactic remains so successful because it exploits human weaknesses, persuading us to click a link or provide sensitive information or data, she said. For example, attackers take advantage of a human need and desire to help others or create a false sense of urgency to make a victim feel compelled to take quick action.

Furthermore, the research revealed that gen AI offers productivity gains by speeding up hackers’ ability to create convincing phishing emails. With that time saved, they could turn to other malicious purposes. 

Organizations should be proactive by revamping their social engineering programs — to include the simple-to-execute vishing, or voice call/voicemail phishing — strengthen identity and access management (IAM tools) and regularly update TTPS, threat detection systems and employee training materials.
“As a community, we need to test and investigate how attackers can capitalize on generative AI,” said Carruthers. “By understanding how attackers can leverage this new technology, we can help [organizations] better prepare for and defend against these evolving threats.”

VentureBeat’s mission is to be a digital town square for technical decision-makers to gain knowledge about transformative enterprise technology and transact. Discover our Briefings.

Credit: Source link

ShareTweetSendSharePin

Related Posts

Car Manufacturers Are Ditching CarPlay In 2026: Here’s Why
AI & Technology

Car Manufacturers Are Ditching CarPlay In 2026: Here’s Why

September 13, 2026
If Your Laptop Trackpad Is Popping Out, Stop Using It Immediately
AI & Technology

If Your Laptop Trackpad Is Popping Out, Stop Using It Immediately

September 13, 2026
How To Get Your Cut Of PlayStation’s .85 Million Settlement
AI & Technology

How To Get Your Cut Of PlayStation’s $7.85 Million Settlement

September 13, 2026
What Are Embeddings? How AI Represents Meaning as Numbers – Unite.AI
AI & Technology

What Are Embeddings? How AI Represents Meaning as Numbers – Unite.AI

September 13, 2026
Next Post
England’s Soccer Team Celebrates Historic Win Over Germany In Euro 2022

England's Soccer Team Celebrates Historic Win Over Germany In Euro 2022

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
Bank of America expanding partnership with Tunnels to Towers, 9/11 memorials ahead of 25th anniversary

Bank of America expanding partnership with Tunnels to Towers, 9/11 memorials ahead of 25th anniversary

September 8, 2026
Anthropic Discloses Fourth Cyber Incident in Alignment Assessment – Unite.AI

Anthropic Discloses Fourth Cyber Incident in Alignment Assessment – Unite.AI

September 10, 2026
Anthropic CEO Says It’s Time to Slow AI Model Advances – Bloomberg.com

Anthropic CEO Says It’s Time to Slow AI Model Advances – Bloomberg.com

September 12, 2026

About

Learn more

Our Services

Legal

Privacy Policy

Terms of Use

Bloggers

Learn more

Article Links

Contact

Advertise

Ask us anything

©2020- TradePoint.io - All rights reserved!

Tradepoint.io, being just a publishing and technology platform, is not a registered broker-dealer or investment adviser. So we do not provide investment advice. Rather, brokerage services are provided to clients of Tradepoint.io by independent SEC-registered broker-dealers and members of FINRA/SIPC. Every form of investing carries some risk and past performance is not a guarantee of future results. “Tradepoint.io“, “Instant Investing” and “My Trading Tools” are registered trademarks of Apperbuild, LLC.

This website is operated by Apperbuild, LLC. We have no link to any brokerage firm and we do not provide investment advice. Every information and resource we provide is solely for the education of our readers. © 2020 Apperbuild, LLC. All rights reserved.

No Result
View All Result
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop

© 2023 - TradePoint.io - All Rights Reserved!