IBM researchers said a ChatGPT-generated phishing email was almost as effective in fooling people compared to a man-made version.

  • MysticKetchup
    link
    fedilink
    English
    1132 years ago

    IBM researchers said a ChatGPT-generated phishing email was almost as effective in fooling people compared to a man-made version.

    So it’s less effective than a regular phishing email?

    • snooggums
      link
      fedilink
      352 years ago

      Yes, but being about the same means ChatGPT could be used to create massive amounts or personalized phishing emails at a low cost in a very short time by automation. Basically doing what they do now, but even faster.

        • snooggums
          link
          fedilink
          52 years ago

          No, those ‘mistakes’ are part of the phishing tactic. It weeds out those that are paying too much attention to the details.

        • El Barto
          link
          fedilink
          English
          12 years ago

          Better spelling and punctuation is a bug, not a feature.

          Bad spelling = people who miss those may be easy to fool.

      • @afraid_of_zombies@lemmy.world
        link
        fedilink
        English
        12 years ago

        I wonder how that would work. The last one I did some checking into had a bitcoin address and it (I really don’t understand Bitcoin well) looked like the person moved the fake money from account to account over and over again.

    • FoundTheVegan
      link
      fedilink
      232 years ago

      And crafting a carefully targeted phishing email took a human team around 16 hours, they wrote, while ChatGPT took just minutes

      This is significant because any person with the desire to scam can use ChatGPT from the comfort of their own home over lunch instead of hiring professionals for a few days.

      • @dack@lemmy.world
        link
        fedilink
        English
        72 years ago

        No, it’s significant because attackers can pump out way more emails while also making them customized to their targets and constantly changing to help avoid detectors.

  • @Moobythegoldensock@lemm.ee
    link
    fedilink
    English
    30
    edit-2
    2 years ago

    And crafting a carefully targeted phishing email took a human team around 16 hours

    Ummm what? Back in college, I used to budget 30-45 minutes a page for essays. What the hell are they writing that took a team of people 16 fucking hours for a few paragraphs of text?

  • @Bogasse@lemmy.ml
    link
    fedilink
    English
    162 years ago

    To be honest, phishing emails are so bad that I don’t see how any generational AI couldn’t be better. Just making less than two typos per sentence would e enough.

    Someone explained me that it may be intentional that phishing emails are so bad as it acts as a pre-filter, then you only spend time and ressources dealing with presumably very gullible people.

    • @Artyom@lemm.ee
      link
      fedilink
      English
      42 years ago

      The typos are intentional. They filter out intelligent recipients who wouldn’t fall for the scam.

  • @ThatHermanoGuy@midwest.social
    link
    fedilink
    English
    82 years ago

    Why haven’t people learned yet to simply never click a link in an email? Even if it’s not malicious, it’s still trying to track you.

    • setVeryLoud(true);
      link
      fedilink
      English
      82 years ago

      Images in emails also track you fwiw, as your browser or email client has to send a request to load it. Disable loading images by default.

  • @Rhoeri@lemmy.world
    link
    fedilink
    English
    12 years ago

    The simple fact that people still fall for phishing scams is a great indicator that we’ve always been going nowhere.

    • @afraid_of_zombies@lemmy.world
      link
      fedilink
      English
      42 years ago

      Oh please you can’t be 100% mistrustful all the time. Eventually you are going to slip up and assume good faith. This is why it is important to stop people from doing it instead of blaming victims.

      Also, who knows how many people who do fall for these things are mentally disabled.

    • @RGB3x3@lemmy.world
      link
      fedilink
      English
      42 years ago

      Phishing scams are getting really good these days. It’s no longer the Nigerian prince-type obvious scams.

      They make emails nearly identical to real ones, they’re able to fake sender names, they actually use real English.

      If you think you wouldn’t fall for a phishing email, you’re kidding yourself. All it takes is one lapse of judgement while you’re too busy to realize an email is fake.