[{"data":1,"prerenderedAt":28},["ShallowReactive",2],{"nr-en-ki-spear-phishing-verdreifacht-erfolgsquote":3},{"slug":4,"title":5,"dek":6,"date":7,"time":8,"publishedAt":9,"updated":10,"updatedAt":10,"dateFmt":11,"updatedFmt":10,"kind":12,"tier":13,"author":14,"authorName":15,"topics":16,"tracker":10,"trackerLabel":10,"headlineStat":22,"image":23,"ogImage":24,"imageAlt":5,"csv":10,"minutes":25,"words":26,"html":27},"ki-spear-phishing-verdreifacht-erfolgsquote","AI-Powered Spear Phishing Triples Success Rate – Study with 7,700 Participants","An experiment proves: AI-driven personalization makes phishing emails three times more effective. For companies and government agencies, social engineering is becoming an escalating threat.","2026-08-12","12:29","2026-08-12T12:29:00+02:00","","August 12, 2026","daten","standard","ideal-syka","Ideal Syka",[17,18,19,20,21],"AI Security","Phishing","Social Engineering","Employee Security","Cyber Threats","AI-powered phishing triples success rate","\u002Fnewsroom\u002Fimg\u002Fki-spear-phishing-verdreifacht-erfolgsquote.webp","\u002Fog-nr\u002Fki-spear-phishing-verdreifacht-erfolgsquote.en.png",2,486,"\u003Cp>Artificial intelligence is making phishing attacks dramatically more successful. A study involving 7,700 test subjects, reported by Golem, shows that \u003Cstrong>AI-powered personalization triples the click rate\u003C\u002Fstrong> on malicious emails. The result is a wake-up call for IT security in Germany – especially for mid-market companies and government agencies that often operate with older systems and less-trained staff.\u003C\u002Fp>\n\u003Ch2>Quick Facts\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Cstrong>7,700 test subjects\u003C\u002Fstrong> participated in the experiment\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Success rate tripled\u003C\u002Fstrong> through AI-based personalization of phishing emails\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Spear phishing\u003C\u002Fstrong> now uses machine learning to tailor content to individual targets\u003C\u002Fli>\n\u003Cli>Particularly vulnerable: employees without regular security training\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>How AI Is Changing the Phishing Game\u003C\u002Fh2>\n\u003Cp>Traditional phishing campaigns rely on mass emails with generic text – &quot;Please update your password,&quot; &quot;Your account has been locked.&quot; Many users now see through this. \u003Cstrong>With AI, the game changes\u003C\u002Fstrong>: Spear phishing tools analyze public data about targets (LinkedIn profiles, company websites, social media), then generate personalized emails that read like internal messages – complete with the boss&#39;s name, project details, departmental jargon.\u003C\u002Fp>\n\u003Cp>The Golem study shows that this personalization doesn&#39;t just sound more convincing; it systematically bypasses people&#39;s defensive instincts. When someone receives an email tailored precisely to their role, they&#39;re more likely to click the link – even if security training should have prevented it.\u003C\u002Fp>\n\u003Ch2>Who Is Most at Risk?\u003C\u002Fh2>\n\u003Cp>The study suggests that \u003Cstrong>standardized security training alone is insufficient\u003C\u002Fstrong>. Particularly vulnerable are:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>New employees without phishing experience\u003C\u002Fli>\n\u003Cli>Staff in roles with access to sensitive data (finance, HR, IT)\u003C\u002Fli>\n\u003Cli>Organizations with weak two-factor authentication\u003C\u002Fli>\n\u003Cli>Companies not using AI-powered anomaly detection\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>German government agencies and mid-market firms are especially exposed: they often have smaller budgets for advanced security technology and struggle with legacy systems that lack modern phishing filters.\u003C\u002Fp>\n\u003Ch2>What This Means for Organizations\u003C\u002Fh2>\n\u003Cp>The study sends a clear message: \u003Cstrong>Traditional password policies and annual phishing simulations are no longer sufficient.\u003C\u002Fstrong> Companies should act now:\u003C\u002Fp>\n\u003Col>\n\u003Cli>\u003Cstrong>Run more frequent, realistic phishing tests\u003C\u002Fstrong> using AI-generated emails\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Roll out two-factor authentication\u003C\u002Fstrong> consistently – even if it&#39;s inconvenient\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Enable anomaly detection\u003C\u002Fstrong> in email systems to flag unusual senders\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Train employees continuously\u003C\u002Fstrong>, not just once a year\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Create reporting channels\u003C\u002Fstrong> so suspicious emails reach IT security quickly\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>The good news: organizations combining these measures can reduce AI phishing success rates again. The bad news: every company that doesn&#39;t will become an easier target.\u003C\u002Fp>\n\u003Ch2>Takeaway: Why This Matters Now\u003C\u002Fh2>\n\u003Cp>The tripling of success rates is no longer theoretical – it&#39;s reality. For German businesses, this means: the classic defense line of &quot;employees are the last firewall&quot; is becoming more porous. AI makes social engineering industrializable. Companies that don&#39;t respond now should expect significantly more successful attacks in the next 12 months. This isn&#39;t just an IT problem; it&#39;s a business risk.\u003C\u002Fp>\n\u003Ch2>Sources\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.golem.de\u002Fnews\u002Fit-sicherheit-studie-zeigt-hohe-klickraten-durch-ki-spear-phishing-2608-211839.html\">Golem\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>Editorially owned by \u003Ca href=\"\u002Fen\u002Fautor\u002Fideal-syka\">Ideal Syka\u003C\u002Fa>. Sources and method: \u003Ca href=\"\u002Fen\u002Fredaktion\">Newsroom &amp; method\u003C\u002Fa>. Tips and corrections: \u003Ca href=\"mailto:ai@i6eal.de\">ai@i6eal.de\u003C\u002Fa>.\u003C\u002Fem>\u003C\u002Fp>\n",1786546289174]