Research
Each Level of LLM Personalization Raises Phishing Click Intent Odds by 28%
arXiv 2609.04410 recruited 180 U.S. working adults for a disclosed survey rating AI-generated phishing emails built at four cumulative personalization levels: workplace only, then recipient name and job title, then job responsibilities, then coworker and shared-project context. Across 1,436 valid evaluations, convincingness rose 2.40 points per level in a sensitivity analysis and the odds of expressing click intention rose 28% per level. A post-hoc analysis found messages from a named person referencing a supplied coworker outperformed messages from a department, and among non-clickers reporting declined while deletion increased, which quietly degrades the security-team signal.
↳ Follow the thread