In a 2024 study by Heiding, Schneier, Vishwanath and colleagues, fully AI-automated spear phishing emails got a 54% click-through rate. Phishing written by human experts: also 54%. The generic control emails: 12%.
So "look for typos and bad grammar" is dead advice. The writing is fine now. The writing is great now.
Here's what AI has a harder time faking:
- The sending infrastructure and path
- Authentication results and domain alignment
- Reply-to and return-path mismatches
- Where the link actually goes
- What happens in the account after the click
The content got better. The evidence trail didn't disappear. That's where investigation earns its keep.