IBM researchers said a ChatGPT-generated phishing email was almost as effective in fooling people compared to a man-made version.

  • MysticKetchup@lemmy.world
    link
    fedilink
    English
    arrow-up
    127
    ·
    1 year ago

    IBM researchers said a ChatGPT-generated phishing email was almost as effective in fooling people compared to a man-made version.

    So it’s less effective than a regular phishing email?

    • snooggums@kbin.social
      link
      fedilink
      arrow-up
      40
      ·
      1 year ago

      Yes, but being about the same means ChatGPT could be used to create massive amounts or personalized phishing emails at a low cost in a very short time by automation. Basically doing what they do now, but even faster.

        • snooggums@kbin.social
          link
          fedilink
          arrow-up
          7
          ·
          1 year ago

          No, those ‘mistakes’ are part of the phishing tactic. It weeds out those that are paying too much attention to the details.

        • El Barto@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 year ago

          Better spelling and punctuation is a bug, not a feature.

          Bad spelling = people who miss those may be easy to fool.

      • afraid_of_zombies@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 year ago

        I wonder how that would work. The last one I did some checking into had a bitcoin address and it (I really don’t understand Bitcoin well) looked like the person moved the fake money from account to account over and over again.

    • FoundTheVegan@kbin.social
      link
      fedilink
      arrow-up
      23
      ·
      1 year ago

      And crafting a carefully targeted phishing email took a human team around 16 hours, they wrote, while ChatGPT took just minutes

      This is significant because any person with the desire to scam can use ChatGPT from the comfort of their own home over lunch instead of hiring professionals for a few days.

      • dack@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        ·
        1 year ago

        No, it’s significant because attackers can pump out way more emails while also making them customized to their targets and constantly changing to help avoid detectors.