Jadwal Sholat

Memuat jadwal sholatโ€ฆ

Computer Science editorial

Open AccessOA2026

Engineered Persuasion: Evaluating Personalized Pretexts in LLM-Generated Spear Phishing

A 180-participant study on how cumulative workplace personalization shapes convincingness, click intention, and defensive action in AI-generated phishing emails
Jerson Francia; Derek Hansen; Benjamin Schooley; Shydra Valynn Murrayยท 2026ยท DOI 10.48550/arXiv.2609.04410

The core problem

Large language models (LLMs) can now insert workplace details into phishing pretexts at low cost, making spear phishing more scalable than ever. However, the authors argue that such details are double-edged: they may either support or undermine a message's credibility. The central research question is whether personalization is simply a matter of adding more details, or whether it depends on the fit between the pretext and the recipient's work context.

The study recruited 180 U.S. working adults to evaluate simulated, AI-generated phishing emails in a disclosed survey. The emails used four cumulative levels of information:

- **Level 1:** workplace context only
- **Level 2:** recipient name and job title
- **Level 3:** job responsibilities
- **Level 4:** coworker/shared-project context

Participants rated each message's convincingness from 0 to 100, chose one stated action (open the link, investigate, delete, or report), and explained why their highest- and lowest-rated messages stood out. The analysis is based on 1,436 valid evaluations.

Innovation

Across 1,436 valid evaluations, convincingness increased by 2.40 points per personalization level in the sensitivity analysis. The odds of expressing click intention increased by 28% per level. Among participants who did not express an intention to click, investigation remained common, reporting declined, and deletion increased.

A post-hoc descriptive analysis found higher ratings and click intention for messages from a named person who referenced a supplied coworker than for messages from a department or entity. This suggests that the source of the message and the specificity of the coworker reference matter beyond the mere presence of personalization.

The following Mermaid diagram summarizes the observed behavioral shifts across personalization levels:

Qualitative coding showed why added deta

Large language models (LLMs) can now insert workplace details into phishing pretexts at low cost, making spear phishing more scalable than ever. However, the authors argue that such details are double-edged: they may either support or undermine a message's credibility. The central research question is whether personalization is simply a matter of adding more details, or whether it depends on the fit between the pretext and the recipient's work context.
The study recruited 180 U.S. working adults to evaluate simulated, AI-generated phishing emails in a disclosed survey. The emails used four cumulative levels of information:

Why it matters

The results highlight that personalization is not simply a matter of adding more details: it depends on whether the pretext fits the recipient's work context. Details that align with a recipient's role and routines enhance credibility, whereas mismatched, vague, or channel-inappropriate details trigger suspicion. This distinction has important implications for workplace cybersecurity training.

The finding that click intention odds rise by 28% per personalization level underscores the risk posed by LLM-generated spear phishing. However, the decline in reporting and increase in deletion among non-clickers suggests that some defensive behaviors may shift rather than disappear. Training should therefore focus not only on recognizing personalization but also on evaluating contextual fit.

The authors propose that organizations can use these insights to design more effective training interventions. For example, employees could be taught to verify whether a message's details match their actual responsibilities and communication norms. The study also calls for further research on how different types of personalization interact with individual and organizational factors.

In summary, the study provides empirical evidence that the effectiveness of personalized phishing depends on contextual congruence, not merely on the amount of personal information included.

Who should read this

CS practitioners and researchers

Opening member contentโ€ฆ