AI phishing personalisation became more convincing as workplace details accumulated in a study of 180 US workers. Across 1,436 valid email evaluations, perceived convincingness rose by an average of 2.4 points for each added personalisation level, while the odds of participants saying they would click rose by 28% per level. The Engineered Persuasion study, submitted on 3 September 2026, tested how names, job titles, responsibilities, colleagues and shared projects changed reactions to simulated phishing emails.
The result explains why AI-assisted phishing does not need a spectacular technical breakthrough to become more effective. An attacker can make a message feel ordinary. A familiar colleague, a plausible project and the right responsibility can turn a suspicious request into something that resembles the routine traffic already filling a worker’s inbox.
How AI Phishing Personalisation Was Built Up
The researchers used four cumulative levels of workplace context. The basic level knew the organisation. Later levels added the recipient’s name and job title, then responsibilities, then coworker and shared-project details. Participants rated how convincing each simulated email felt and reported what they would be inclined to do.
The strongest condition averaged 64.3 on the study’s convincingness scale, compared with 56.6 for the basic condition. Stated click intention rose from 31.9% to 43.0% across those conditions. The researchers also found the effect building incrementally rather than appearing only after one dramatic personal detail.
That makes the threat easy to underestimate. Security training often teaches people to look for obvious anomalies such as poor spelling, a strange greeting or a generic request. Personalisation removes some of those cues. The email can be grammatically clean, address the right person and mention work that genuinely exists.
Why Names and Colleagues Change the Decision
People use context as a shortcut. If a message contains information that fits the workplace, the recipient has fewer reasons to stop and interrogate it. A reference to a colleague can imply social proof. A project name can imply access. A job-specific request can make urgency feel legitimate rather than suspicious.
This is not unique to email. LiveAIWire’s coverage of AI voice-cloning scams showed how familiarity can be weaponised in audio. The attacker does not need to prove an identity with perfect fidelity if the surrounding story already matches what the target expects.
Generative AI lowers the cost of producing those stories at scale. An attacker who can collect public company pages, professional profiles or leaked data can ask a model to turn the material into tailored messages. The model does not need privileged insight into the victim’s mind. It only needs enough correct context to make the request blend into normal work.
What This Means for You at Work
The presence of accurate personal information should no longer count as strong evidence that a message is genuine. A correct title, colleague name or current project may simply show that the sender researched you. The more public an organisation’s staff structure and project activity becomes, the more cheaply that context can be assembled.
Verification therefore needs to move from “does this email know me?” to “does this request make sense through a trusted channel?” If a message asks for credentials, money, a file, a login or an unusual change of process, confirm it independently. A short message to the colleague through an existing internal channel can defeat a carefully personalised lure.
LiveAIWire reported that AI phishing attacks had surged as generative tools made persuasive messages easier to produce. The new experiment adds detail to that trend by showing which kind of information changes perceived legitimacy. Personalisation is not decoration. It changes how the recipient evaluates the request.
Wrong Personal Details Can Still Give the Phish Away
The study also found an important counterweight. Incorrect, vague or channel-inappropriate details could increase suspicion. If the email mentioned a responsibility the recipient did not have, misused a coworker’s role or described a project incorrectly, the attempt could undermine itself.
That means attackers face a quality problem. More data can make a message stronger only when the data fits. A badly merged profile may create more warning signs than a simple generic email. This is one reason organisations should avoid assuming that every AI-generated phish will be expertly tailored.
The researchers also reported a descriptive pattern in which messages containing a named coworker reached particularly high convincingness and stated click intention. That comparison was post-hoc and imbalanced, so it should not be treated as proof that adding one colleague’s name causes a specific increase. The stronger causal evidence comes from the staged personalisation levels across the full design.
Stated Click Intention Is Not the Same as Real Clicking
The largest limitation is behavioural realism. Participants knew they were taking part in a study and evaluating simulated emails. The researchers measured stated intentions, not whether an unsuspecting employee actually clicked a live malicious link. People can behave differently when they know no real account, payment or device is at risk.
The sample was also self-selected and based in the United States. Workplace cultures, communication channels and security practices differ across countries and industries. An email that looks routine in one organisation may look strange in another. The study measures a clear persuasion effect under controlled conditions, not a universal real-world compromise rate.
That distinction matters for security planning. A 28% increase in odds per personalisation level does not mean 28% more employees will be hacked. It means the study’s reported willingness to click became more likely as contextual detail increased. The operational risk depends on filtering, authentication, staff behaviour and whether the attacker can obtain accurate information.
Security Training Needs to Catch Up With Plausible Messages
Traditional phishing advice often focuses on visual defects. That remains useful, but it is not enough when a well-written message can be generated in seconds. Training should place more weight on request verification, unusual process changes and the difference between identity clues and identity proof.
Organisations can also reduce the information available for easy enrichment. Public staff pages and social posts are valuable for recruitment and business development, but they can reveal reporting lines, project names and responsibilities. The answer is not to disappear from the internet. It is to understand which details could make a fraudulent request more persuasive.
Technical controls still matter. Multi-factor authentication, payment approval rules, protected internal messaging and domain security can stop a convincing email from becoming a compromise. LiveAIWire’s coverage of the Five Eyes AI cyberattack warning shows why the defensive focus is increasingly shifting from whether attackers use AI to whether core controls still hold when attacks become faster and cheaper.
The Best Phish May Look Boring
The uncomfortable lesson is that the most effective AI phishing email may not look futuristic. It may look like a normal message from a normal colleague about a normal piece of work. That is precisely what personalisation is designed to achieve.
The study gives defenders a useful rule: familiarity is no longer a reliable trust signal. Accurate names, jobs and colleagues can be copied into a fraudulent message just as easily as a company logo. The stronger question is whether the request survives independent verification. If it does, the extra check costs a minute. If it does not, that minute may be the only part of the attack the AI could not automate.
Public Workplace Data Has Become Security-Relevant Context
The experiment also changes how organisations should think about information that appears harmless in isolation. A staff biography, conference post, job advert or project announcement may not reveal a password, but together those details can help an attacker construct a request that fits the recipient’s real working environment.
That does not mean companies should remove every employee name from the web. It means security teams should treat public context as part of the threat model and design approval processes that do not rely on familiarity alone. When payment changes, account access or sensitive files are involved, the control should still work even if the attacker knows who reports to whom and what the team is working on.
The safest process assumes that an attacker can know the context and still requires a second, trusted signal before a consequential action is approved.
About the Author
Stuart Kerr is Technology Correspondent at LiveAIWire, covering artificial intelligence, cybersecurity and the social impact of emerging technology. LiveAIWire is an independent, human-led technology publication using AI-assisted research, editorial production and original AI-assisted editorial illustrations under his direction.
