BYU Study: AI-Generated Spear Phishing (GPT-4) Outperforms Human-Written Lures and Evades Human Detection — Threadlinqs Intelligence
As of 2026-08-09, BYU Study: AI-Generated Spear Phishing (GPT-4) Outperforms Human-Written Lures and Evades Human Detection is a medium-severity phishing threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 5 indicators of compromise.
Threat ID: TL-2026-1964 · Severity: MEDIUM · Status: ACTIVE · Category: PHISHING
A peer-reviewed Brigham Young University pilot study (Journal of Cybersecurity and Privacy, DOI 10.3390/jcp6040129) found GPT-4-generated spear-phishing/smishing texts, personalized from 25
Researchers from Brigham Young University (Jerson Francia, Derek Hansen, Benjamin Schooley, Matthew Taylor, Shydra Valynn Murray, Rebekah Cornelius, and Greg Snow) published "Assessing AI-Generated vs. Human-Authored Spear Phishing SMS Attacks: An Empirical Study" in MDPI's Journal of Cybersecurity and Privacy (ISSN 2624-800X, Volume 6, Issue 4, Article 129, DOI 10.3390/jcp6040129), an expanded, peer-reviewed follow-on to the authors' 2024 preprint that introduced the TRAPD (Threshold Ranking Approach for Personalized Deception) methodology (arXiv:2406.13049).
The study design: 25 volunteer participants each completed a survey disclosing their job, workplace, hobbies, city, and a recent social-media post. This self-reported data was fed into a prompt template to generate personalized spear-phishing/smishing text messages. For each participant, GPT-4 generated six personalized messages while undergraduate students enrolled in a deception course wrote six more under a 15-minute time constraint, screened by a review team that included two cybersecurity professors. Participants then evaluated the resulting 300 printed messages (12 per participant), rating how likely they would be to click/act on each and guessing whether it was AI- or human-authored (the TRAPD ranking, qualitative-feedback, and source-attribution components).
Results: GPT-4-authored messages exceeded the 'would-click' threshold in 28% of judgments versus 21.3% for the human-authored set — a 6.7 percentage-point gap whose 95% confidence interval (2.9 to 16.3 points) spans a range some coverage characterizes as not clearly statistically significant given the small sample. Effectiveness varied sharply by pretext theme: work/workplace-themed messages cleared the click line 38% of the time, hobby-themed messages 19%, and social-media-themed messages 17%. One participant described a fraud-alert-themed AI lure as looking 'literally like the alert we get [at work] when there's a fraud' — illustrating why context-matched, work-adjacent pretexts outperformed generic ones.
Critically, human participants could distinguish AI-generated from human-written messages only 52% of the time — statistically indistinguishable from a coin flip — even though GPT-4 output showed a detectable stylistic tell: 66% of GPT-4 messages contained emoji characters versus just 2% of the human-authored set. That tell was exploitable by machines even though it evaded human notice: a machine-learning classifier trained on text-embedding features of the same message corpus achieved 88.7% balanced accuracy distinguishing AI-authored from human-authored lures.
The TRAPD preprint (arXiv:2406.13049v2) discloses granular methodology beyond the published abstract: the participant survey collected name, email address, sex, age group, self-reported technical ability, hobbies, city/state of residence, occupation/workplace, and 'something from their home that they recently posted on social media'; of an initial 41 recruits, only 25 (61%) returned to complete the ranking interview. The GPT-4 and human-author prompt template was identical for both groups: 'Make a spearphishing message in the form of an SMS for [Name], a [Age] [Sex] who recently shared about [topic]; [context details]. Have them click a link that is not from a legitimate source, but is believable.' Ninety-nine student authors produced 363 candidate messages (screened down to a 246-message retained human-authored set); 246 AI-authored messages were retained in parallel. GPT-4 reliably generated actual (fabricated but well-formed) clickable links exactly as instructed, while human authors substituted a placeholder ('[URL]', 'site', or 'url') in 71% of their messages instead of writing a real link — a concrete capability gap in executing the malicious-link step of the kill chain. In the preprint's logistic-regression model, the click-rate gap (28.0% AI vs. 21.3% human) corresponds to an odds ratio of 1.43 (95% CI 0.847-2.446, p=0.182) and a Bayesi
Target sectors: enterprise, government administration, financial services, health, higher education
Target regions: united states of america
Timeline
- Julian Hazell publishes 'Spear Phishing With Large Language Models' (arXiv:2305.06972), among the earliest works establishing LLM capability to generate personalized spear-phishing content — foundational context for the BYU study.
- Francia, Hansen, Schooley, Taylor, Murray, and Snow post the preprint 'Assessing AI vs Human-Authored Spear Phishing SMS Attacks: An Empirical Study Using the TRAPD Method' to arXiv (2406.13049), introducing the TRAPD methodology and initial pilot results.
- Lermen, Heiding, and Kao publish a related but separate 101-participant study (summarized on LessWrong, full paper arXiv:2412.00586) showing fully-automated AI spear-phishing emails matched human-expert click-through rates (54% vs 54%), providing corroborating context for AI-parity findings in this space.
- The peer-reviewed journal version, 'Assessing AI-Generated vs. Human-Authored Spear Phishing SMS Attacks: An Empirical Study,' is published in MDPI's Journal of Cybersecurity and Privacy (Vol. 6, Issue 4, Article 129, DOI 10.3390/jcp6040129), reporting the 28% vs. 21.3% would-click gap, 52% human detection accuracy, and 88.7% classifier balanced accuracy.
- Help Net Security publishes 'Gut feeling does nothing against AI spear phishing texts,' the first mainstream security-media coverage summarizing the peer-reviewed study's findings and practical recommendations.
- News4Hackers republishes coverage of the study ('Why Your Gut Feeling Can't Stop AI Spear Phishing Attacks'), broadening awareness of the findings among security practitioners.
- Threadlinqs Intelligence Platform ingests and documents the study as a threat-relevant human-factors research finding via automated feed monitoring.
References
- Gut feeling does nothing against AI spear phishing texts
- Assessing AI-Generated vs. Human-Authored Spear Phishing SMS Attacks: An Empirical Study (Journal of Cybersecurity and Privacy, 6(4), Article 129, DOI 10.3390/jcp6040129)
- Assessing AI vs Human-Authored Spear Phishing SMS Attacks: An Empirical Study Using the TRAPD Method (preprint)
- Why Your Gut Feeling Can't Stop AI Spear Phishing Attacks
- Human study on AI spear phishing campaigns (related prior work: Lermen, Heiding, Kao — fully-automated AI spear-phishing vs. human experts)
- Evaluating Large Language Models' Capability to Launch Fully Automated Spear Phishing Campaigns: Validated on Human Subjects
- Spear Phishing With Large Language Models (related prior work establishing LLM spear-phishing capability, incl. LLM safeguard circumvention via prompt engineering)
- Assessing AI vs Human-Authored Spear Phishing SMS Attacks (full-text v2, prompt template and survey-field detail)
- Obtain Capabilities: Artificial Intelligence, Sub-technique T1588.007 - Enterprise | MITRE ATT&CK
- Phishing, Technique T1660 - Mobile | MITRE ATT&CK
- Spearphishing via Social Engineering LLM, AML.T0052.000 | MITRE ATLAS
- LLM Jailbreak, AML.T0054 | MITRE ATLAS
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 5 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, MEDIUM, threat intelligence, cybersecurity, T1598, T1589, T1589.002, T1591.004, T1593.001, T1588.007, T1566, T1660, T1204, T1204.001