← Otros blogs

It Used to Take Real Skill to Write a Phishing Email with a 54% Click Rate. Now It Takes None

A peer-reviewed study by Harvard Kennedy School researchers found that a fully AI-automated spear phishing email reaches a 54% click-through rate, matching an email written by a skilled human expert — with no research time and no writing skill required from whoever sends it. Most phishing defense has quietly relied on a limiting factor that was never written down: writing a genuinely convincing, well-researched attack took real skill, which meant only a small number of attackers could produce one. Generative AI removes that limiting factor entirely. The threat did not get psychologically smarter. It got available to anyone.
Phishing
Security awareness
GenAI and security
Social engineering

A security awareness manager pulls up this quarter's phishing module to review it before the next rollout. The examples inside are familiar: a message with a spelling error, an urgent request from an unfamiliar sender, a link that does not match the company domain.

Those examples describe a low-skill attacker. That used to be a safe assumption, because writing a phishing email good enough to fool a careful employee took time, research, and a decent command of written English. Most attackers a typical organization faced simply did not clear that bar.

A peer-reviewed study published this year shows that bar no longer exists.

What the research actually measured

A study from Harvard Kennedy School and the Avant Research Group tested this directly rather than estimating it. Researchers ran a controlled experiment with human participants, comparing four types of phishing email: a generic control message, an email crafted by a human expert, a fully AI-automated email, and an AI email with light human review (Heiding, Lermen, Kao, Schneier, and Vishwanath, published in Expert Systems with Applications, 2026).

The generic control email reached a 12% click-through rate. The human-expert email reached 54%. The fully AI-automated email also reached 54% — matching the human expert with no person writing or reviewing it. The AI version with human-in-the-loop review reached 56%, the highest of the four.

The result that matters is not that AI phishing works. It is that it now performs identically to a skilled human attacker, at a fraction of the time and cost, with no person needing to research the target manually.

Why "low-skill attacker" stopped being a safe assumption

Writing a phishing email that reaches a 54% click rate is not a matter of luck. The Harvard study's human-expert condition involved someone researching the target and crafting a message by hand — the kind of effort that only a limited pool of skilled, motivated attackers would spend on any single target.

That scarcity was doing real defensive work, whether anyone designed it to or not. Most organizations were never facing a flood of expert-level attempts, because writing one took a rare combination of time, skill, and payoff worth the effort.

The fully AI-automated condition in the same study reached the identical 54%, with no person writing or researching anything. The skill barrier that used to separate a low-effort attempt from an expert-level one has been removed from the equation entirely.

Key insight: the limiting factor was attacker scarcity, not attacker psychology

The structural problem is not that employees need to be more alert, and it is not that attackers discovered a new psychological trick. It is that phishing defense has quietly depended on attacker scarcity: the assumption that expert-level attempts would be rare, because producing one required expertise most attackers did not have.

Generative AI did not improve the psychology of phishing. It removed the skill barrier that used to limit how many attackers could produce a convincing, expert-level attempt — which means the volume of high-quality phishing attempts any organization faces is no longer bounded by how many skilled attackers exist.

This is why the fix is not simply "more phishing training." A program built to catch rare, high-effort attempts has no answer for a world where every attempt can be high-effort by default.

What stayed the same, and why it matters less than it seems

The Harvard study's highest-performing emails still relied on familiar psychological levers: urgency, an authority the target would not easily question, a tone that assumes an existing relationship. None of that is new, and it would be a mistake to conclude the fix is simply teaching people to recognize those triggers instead of grammar mistakes.

That framing still assumes attacks worth worrying about are the exception. Once expert-level quality is the default rather than the rare case, the more useful question for a training program is not which psychological trigger a message uses — but whether an employee's habit of verifying an unusual request holds up regardless of how convincing the message looks.

What this means in practice

If expert-level phishing is now the default rather than the exception, a phishing simulation has to test against that default, not against the low-effort version that used to be statistically likely. A simulation built around a templated, error-prone email tests whether someone remembers a rule. One built around a well-researched, contextually appropriate request tests whether a verification habit holds up when nothing about the message itself gives it away — which is the only version of the test that still tells a security leader something useful.

This also means a training program's content has a shorter shelf life than the assumption it was built on. A module designed around "attackers are rare and unskilled" was accurate when that scarcity was real. It no longer is, and a program still built on it will keep testing for the wrong default: treating an expert-level attempt as the edge case, when the research suggests it should be the baseline.

None of this replaces email filtering or technical controls. It changes what a training program can reasonably claim to have tested, once the population of attackers capable of an expert-level attempt is no longer small.

A board asking whether the security team is "ready for AI-driven phishing" is really asking whether that population shift has been priced into the testing program at all — not whether the team has read about it.

The Harvard study did not find that AI phishing might eventually match a skilled human attacker. It found that it already does, at zero additional cost or skill required from whoever sends it — which is a different and larger problem than a smarter attack.

The organizations that stop assuming expert-level attempts are rare are the ones whose training will still describe what their people actually face next quarter.

If your phishing training still treats a well-written, well-researched attempt as the unlikely exception, it is worth checking whether that assumption still holds. That is precisely the question we help security teams test for at Zepo.

Escrito por:
Suscríbase a nuestro boletín
Contenido
Actúa ahora antes de que lo hagan los atacantes
Unifique las simulaciones de deepfake, la formación personalizada y el análisis de riesgos en una única plataforma que cree una defensa mensurable.
Hable con un experto

Cómo Zepo ayuda a las empresas

Cuando todo se conecta, los resultados llegan

Paula Pereira

Gerente de Seguridad de la Información Digital

Recomendaría Zepo a colegas de otras empresas porque creo que ha satisfecho todas nuestras necesidades. Nos ha permitido ejecutar tres tipos de campañas que otras herramientas que hemos probado simplemente no pueden hacer. Y más allá del producto en sí, el apoyo de todo el equipo nos ha ayudado a sacarle mucho más partido.”

+9K

Empleados Protegidos

–10%

Tasa de clics en ataques

+18%

Tasa de finalización de la capacitación

Ramon Fernandez Blanco

Ciberseguridad y Gerente de Producto Digital

Desde la implementación de Zepo, la concienciación de los empleados ha aumentado significativamente. Los empleados ahora debaten activamente sobre ciberseguridad y campañas de phishing, y los correos electrónicos sospechosos se reportan rápidamente en lugar de ser ignorados.”

+600

Empleados Protegidos

–15%

Credenciales enviadas

+26%

Tasa de finalización de la capacitación

Jonathan Nelson

Director de Inteligencia de Riesgos

La visión de Zepo para una solución de ciberseguridad en tiempo real, hiperpersonalizada y multiplataforma es verdaderamente única y está muy por encima de la competencia”

+100

Empleados Protegidos

Anticípate antes de que ataquen.