Security News > 2023 > January > AI-generated phishing emails just got much more convincing

GPT-3 language models are being abused to do much more than write college essays, according to WithSecure researchers.
Perhaps unsurprisingly, GPT-3 proved to be helpful at crafting a convincing email thread to use in a phishing campaign and social media posts, complete with hashtags, to harass a made-up CEO of a robotics company.
In another test, the report authors asked GPT-3 to generate fake news stories because, as they wrote, "One of the most obvious uses for a large language model would be the creation of fake news." The researchers prompted GPT-3 to write an article blaming the US for the Nordstream 2 pipeline attack in 2022.
With long-form content, as other researchers have pointed out, GPT-3 sometimes breaks a sentence halfway through, suggesting that human editors will still be needed to craft or at least proofread text, malicious or otherwise - for now.
In addition to using GPT-3 to help generate definitions, the authors also asked the AI to review their research.
"While the report does an excellent job of highlighting the potential dangers posed by GPT-3, it fails to propose any solutions to address these threats," the GPT-3 generated review said.
News URL
https://go.theregister.com/feed/www.theregister.com/2023/01/11/gpt3_phishing_emails/
Related news
- Microsoft: Hackers steal emails in device code phishing attacks (source)
- Beware: PayPal "New Address" feature abused to send phishing emails (source)
- YouTube warns of AI-generated video of its CEO used in phishing attacks (source)
- Microsoft Warns of ClickFix Phishing Campaign Targeting Hospitality Sector via Fake Booking[.]com Emails (source)
- Coinbase phishing email tricks users with fake wallet migration (source)
- Why it's time for phishing prevention to move beyond email (source)
- Microsoft’s new AI agents take on phishing, patching, alert fatigue (source)
- After Detecting 30B Phishing Attempts, Microsoft Adds Even More AI to Its Security Copilot (source)
- New Morphing Meerkat Phishing Kit Mimics 114 Brands Using Victims’ DNS Email Records (source)