Artificial intelligence is making phishing attacks dramatically more successful. A study involving 7,700 test subjects, reported by Golem, shows that AI-powered personalization triples the click rate on malicious emails. The result is a wake-up call for IT security in Germany – especially for mid-market companies and government agencies that often operate with older systems and less-trained staff.
Quick Facts
- 7,700 test subjects participated in the experiment
- Success rate tripled through AI-based personalization of phishing emails
- Spear phishing now uses machine learning to tailor content to individual targets
- Particularly vulnerable: employees without regular security training
How AI Is Changing the Phishing Game
Traditional phishing campaigns rely on mass emails with generic text – "Please update your password," "Your account has been locked." Many users now see through this. With AI, the game changes: Spear phishing tools analyze public data about targets (LinkedIn profiles, company websites, social media), then generate personalized emails that read like internal messages – complete with the boss's name, project details, departmental jargon.
The Golem study shows that this personalization doesn't just sound more convincing; it systematically bypasses people's defensive instincts. When someone receives an email tailored precisely to their role, they're more likely to click the link – even if security training should have prevented it.
Who Is Most at Risk?
The study suggests that standardized security training alone is insufficient. Particularly vulnerable are:
- New employees without phishing experience
- Staff in roles with access to sensitive data (finance, HR, IT)
- Organizations with weak two-factor authentication
- Companies not using AI-powered anomaly detection
German government agencies and mid-market firms are especially exposed: they often have smaller budgets for advanced security technology and struggle with legacy systems that lack modern phishing filters.
What This Means for Organizations
The study sends a clear message: Traditional password policies and annual phishing simulations are no longer sufficient. Companies should act now:
- Run more frequent, realistic phishing tests using AI-generated emails
- Roll out two-factor authentication consistently – even if it's inconvenient
- Enable anomaly detection in email systems to flag unusual senders
- Train employees continuously, not just once a year
- Create reporting channels so suspicious emails reach IT security quickly
The good news: organizations combining these measures can reduce AI phishing success rates again. The bad news: every company that doesn't will become an easier target.
Takeaway: Why This Matters Now
The tripling of success rates is no longer theoretical – it's reality. For German businesses, this means: the classic defense line of "employees are the last firewall" is becoming more porous. AI makes social engineering industrializable. Companies that don't respond now should expect significantly more successful attacks in the next 12 months. This isn't just an IT problem; it's a business risk.
Sources
Editorially owned by Ideal Syka. Sources and method: Newsroom & method. Tips and corrections: ai@i6eal.de.




