3 ms·
While I broadly agree with the concerns about using LLMs for "commoditized", large-scale phishing, isn't the study a bit lacking? Specifically, "click through"
by serviceberry 2y ago
While I broadly agree with the concerns about using LLMs for "commoditized", large-scale phishing, isn't the study a bit lacking? Specifically, "click through" is a pretty poor metric for success.
If I receive a unique / targeted phishing email, I sure will check it out to understand what's going on and what they're after. That doesn't necessarily mean I'm falling for the actual scam.
- dwood_dev 2y agoI hate the InfoSec generated phishing tests. They all pass DKIM, SPF, etc. Some of them are very convincing. I got dinged for clicking on a convincing one that I was curious about and was 50/50 on it being legit (login from a different IP). After that, I added an auto delete rule for all the emails that have headers for our phish testing as a service provider.
- lupire 2y agoDid you report phishing before you clicked? If not, you deserve to be dinged.
- troupe 2y agoI think the idea is that it is a numbers game. If you have a way to inexpensively generate a much higher click-through rate than doing it manually, your success rate will go up with a lower investment.
- Hilift 2y agoThe average SMB company has people that act very differently with their personal email due to they need to protect their checking account that has $400 in it. But have no such measurement or reluctance with work email. They are "clickers". There are also "repeat clickers", "serial clickers", and "frequent clickers". The only thing this study is doing is automating a small part of the profiling and preparation. There was yet another study titled "Why Employees (Still) Click on Phishing Links" by NIH. (2020) https://pmc.ncbi.nlm.nih.gov/articles/PMC7005690/ https://pmc.ncbi.nlm.nih.gov/articles/PMC7005690/ Given the pathology, clicking is the visible and obvious symptom.