Definition · AI security
Phishing
Phishing is social engineering delivered electronically, such as by email, text message, phone or video call, that tricks a person into giving up access, credentials, information or money. MITRE ATLAS catalogues phishing as attack technique AML.T0052 and states that generative AI, including language models and voice or video deepfakes, is enabling attackers to scale targeted phishing.
Last reviewed
Key points
- MITRE ATLAS catalogues phishing as attack technique AML.T0052. It states that generative AI is enabling attackers to scale spearphishing, the targeted kind aimed at a specific person, company or industry.
- ATLAS files two AI sub-techniques. In one, a language model is instructed to act as a social engineer and coax a user into revealing private information such as credentials. In the other, a deepfake voice or video impersonates an executive or colleague.
- In a 2024 study, 54% of recipients clicked the link in fully AI-automated spear-phishing emails, the same as for emails written by human experts; 12% clicked a generic phishing email. Each group was about 25 people recruited at universities and told to expect marketing emails.
- ATLAS's defences are user training and deepfake detection. For voice and video it recommends checking through an independent channel, such as a known call-back number, before acting on a sensitive request.
How it works
MITRE ATLAS calls all phishing “electronically delivered social engineering”. Spearphishing is the targeted kind, written for a specific person, company or industry.
ATLAS lists phishing as technique AML.T0052. Its entry and two sub-techniques (narrower variants of the technique) describe three ways generative AI helps:
- Writing the lure. A language model generates the phishing text. This is in the main technique, AML.T0052.
- Running the conversation. A language model can be given a system prompt that tells it to phish, then chat with the victim and draw out sensitive information such as credentials. This is sub-technique AML.T0052.000.
- Faking a trusted person. A deepfake voice or video impersonates an executive or colleague, on a live call or in a recorded message. This is sub-technique AML.T0052.001.
Why it matters
AI-written spear phishing can work as well as an expert’s. In a 2024 study by Heiding and colleagues, fully AI-automated emails got a 54% click-through rate, meaning the share of recipients who clicked the email’s link. Emails by human experts also got 54%; a generic phishing email got 12%. The study was small: 101 people recruited at universities, randomly split into four groups of about 25, and told to expect marketing emails.
Model refusals are a weak barrier. Most models in the study refused to write a “phishing email” but complied when the request just said “email”. The authors note that a good phishing email and a legitimate one differ only in the sender’s intentions, so stricter guardrails would also block legitimate uses.
How to defend against it
ATLAS lists two defences: user training and deepfake detection. For a sensitive request made by voice or video, ATLAS recommends verifying through an independent channel, such as a known call-back number, before acting on it.
In practice
One reported deepfake case began with a phishing email. According to Hong Kong police, as reported by CNN, a finance worker in Hong Kong first suspected an email from the company’s UK office that asked for a secret transaction. His doubts went away after a video call with people he took for the chief financial officer and other colleagues. All of them were deepfake re-creations. He sent 200 million Hong Kong dollars, about $25.6 million. Police did not name the company. The engineering firm Arup later confirmed to CNN that it was the victim and that “fake voices and images were used”, and said none of its internal systems were compromised.
In May 2025 the FBI warned of a campaign, running since April, that sent text messages and AI-generated voice messages claiming to come from senior US officials. Many of the targets were current or former senior US federal or state government officials and their contacts. The aim was to build rapport, then gain access to their personal accounts.
The attacker does not always need their own model. In an exercise recorded by ATLAS, researchers hid an indirect prompt injection in a web page. A user had given Bing Chat permission to read open websites. While the page was open and the user chatted with Bing Chat, the injection turned it into a social engineer that tried to extract the user’s personal information. The user did not have to ask about the page.
Questions and answers
How is AI used in phishing?
MITRE ATLAS's phishing entry and its two sub-techniques describe three uses. Language models generate targeted phishing text. A language model can itself be set up as a live social engineer that chats with a victim and draws out credentials. Deepfake voice or video impersonates a trusted person on a call or in a recorded message.
Are AI-written phishing emails more effective than human-written ones?
In a 2024 study by Heiding and colleagues, they were as effective as emails written by human experts, not more. Fully AI-automated spear-phishing emails and expert-written ones both got 54% of recipients to click their link, against 12% for a generic phishing email. The 101 recruited participants were split into four groups of about 25, so each rate comes from a small group. The difference is cost: the AI tool researched and wrote to each target automatically.
How do you defend against a deepfake phishing call?
Verify through a channel the attacker does not control. MITRE ATLAS recommends checking through an independent channel, such as a known call-back number, before acting on a sensitive request made by voice or video. The FBI gives the same advice and warns that AI-generated content is often difficult to identify.
Sources
- MITRE ATLAS, technique AML.T0052 Phishing (collection 2026.09)MITRE
- Evaluating Large Language Models' Capability to Launch Fully Automated Spear Phishing Campaigns: Validated on Human Subjects (Heiding, Lermen, Kao, Schneier, Vishwanath; arXiv preprint)arXiv, 30 Nov 2024
- Arup revealed as victim of $25 million deepfake scam involving Hong Kong employeeCNN, 16 May 2024
- Senior US Officials Impersonated in Malicious Messaging Campaign (Alert I-051525-PSA)FBI Internet Crime Complaint Center, 15 May 2025