AI-Generated Phishing Achieves a 54% Click Rate
WatchGuard’s security blog, on what happens to social engineering when generative AI writes the lure.
- Publisher
- WatchGuard Technologies
- Published
- July 24, 2026
- Topic
- AI, cybersecurity, social engineering
- Reading time
- 5–7 minutes
- Cost
- Free — no paywall, no registration
The link above resolves to WatchGuard’s Spanish-language edition of the post, which is the version we could verify directly. English-language coverage of the same piece is indexed on the WatchGuard phishing blog hub.
Why it’s worth your time
Most AI-and-security writing is forecasting. This one is arithmetic. It reports a 54% click rate on AI-generated phishing campaigns — a measured outcome, not a projection about what attackers might eventually manage.
That single number reframes the debate. Generative AI is not primarily inventing new attack classes; it is making an old one dramatically more effective. Phishing did not need reinvention. It needed fluency, volume, and personalisation at near-zero marginal cost, and that is exactly what a language model supplies.
View as table
| Lure type | Click-through rate |
|---|---|
| AI-generated | 54% |
| Conventional (manually written) | 12% |
Source: Microsoft Digital Defense Report 2025, as reported by WatchGuard. See the sourcing note.
Read the second bar first. A 12% baseline was already enough to justify an entire security industry. At 54%, “train users to spot the fake” stops being a control and becomes a hope.
Key insights
1. Scale is the real capability gain
AI lets attackers produce highly convincing phishing emails at volume, collapsing the cost and effort of running a campaign. Fluent grammar, plausible internal context, correct tone for the target’s industry — the artisanal parts of spear phishing are now automated. The economics that once limited high-quality targeting to high-value victims no longer apply.
2. Strong authentication is doing the load-bearing work
As lures improve, the controls that still hold are the ones that do not depend on a human noticing anything: phishing-resistant multifactor authentication, modern MFA rather than SMS codes, and a Zero Trust posture that treats every session as unproven until verified. These degrade gracefully when a user clicks. Awareness training does not.
3. The bottleneck moved from malware to identity
The decisive question is no longer “did our tooling detect the payload?” but “can a stolen credential actually be used?” Organisations that strengthen identity verification and access control are structurally better positioned against AI-enhanced phishing, because they are defending the step the attacker cannot automate away.
Why it matters
For anyone making budget decisions across AI, automation, and security, the strategic read is that AI is accelerating existing techniques far more than it is creating new ones. That has an uncomfortable corollary: the marginal detection tool is a weaker investment than it looks, because it is competing in the one category where the attacker’s cost curve just fell off a cliff.
Spending that compounds instead: identity, least-privilege access, verification of high-consequence requests, and operational processes that survive a successful click. Those controls are indifferent to how good the lure was.
This is the same logic ClearGlass applies to autonomous systems — put the gate at the consequential boundary, not at the point of persuasion. It is why our own operating model routes every material action through explicit approval rather than trusting that the input was legitimate. See AI Agents Are the New Insider Threat and The Case for Adaptive Trust for the architectural version of the argument.
Model the blast radius
The argument above is only useful if it changes a number you own. This model takes the click rate as a given and asks the question the article ends on: when the click happens, how far does it get? Change the inputs and watch which lever actually moves the outcome — it is not the click rate.
Assumptions — argue with these
- This is arithmetic over your inputs, not telemetry. Nothing here is measured, sampled, or phoned home. The page holds no data and sends none; the scenario link encodes only the four values you set.
- Click rate defaults to the reported 54% for AI-assisted lures, with the 12% conventional baseline one button away. Both trace to the Microsoft Digital Defense Report 2025.
- Credential-submission rate defaults to 30% of clickers. Published figures for AI-assisted campaigns run around a third; substitute your own phishing-simulation results, which are the only numbers that describe your staff.
- Posture factors (90% / 50% / 2%) are editorial estimates of how often a captured credential still yields account access under each posture — real-time relay defeats one-time codes, fatigue defeats push approval, and a hardware-bound key defeats both. Replace them with your own incident data before anyone spends money on the output.
- Residual exposure is takeover-capable accounts as a share of all recipients. Thresholds: under 0.5% contained, under 5% elevated, above that critical. They are editorial bands, not a standard.
Move the click-rate slider from 12% to 54% and the first tile more than quadruples — that is the article’s finding. Now leave it at 54% and change the posture instead. The last two tiles collapse by more than an order of magnitude, and the click rate never moved. That asymmetry is the whole argument: you cannot buy the first number down, and you can buy the last two down.
Check the provenance before you quote it
The 54% figure did not originate with WatchGuard. The post cites the Microsoft Digital Defense Report 2025, which reported a 54% click-through rate on AI-assisted phishing against 12% for manually written messages — the 4.5× multiplier quoted widely since. Independent academic work on automated spear-phishing campaigns validated on human subjects reports click-through in the same range.
If you plan to put this number in a board deck, cite the primary report rather than the secondary coverage, and state the comparison group. A click rate without its baseline is a headline, not evidence. That is a house rule here: provenance outranks persuasive output.
One takeaway
The competitive advantage is no longer detecting every phishing email. It is ensuring that a successful phishing attempt cannot easily become a successful compromise.
Assume the click. Design so the click is survivable. Identity-centric security is becoming the foundation of effective cyber defense in the AI era — not because detection stopped mattering, but because it stopped being sufficient.
Five moves this quarter
If the article persuades you, these are the changes that follow from it. None require a new detection product.
- Retire phishable factors. Move admins and finance off SMS and push-approval MFA onto passkeys or hardware keys first. Those two groups are where a 54% click rate converts into a material loss.
- Cap what a valid session can do. Least privilege by default, short-lived credentials, and step-up verification on privilege escalation — so a working credential is not a standing licence.
- Put a second channel on money and access. Out-of-band verification for payment changes, vendor bank details, and account-recovery requests. Written fluency is exactly what AI supplies, so stop treating a well-written request as a signal.
- Instrument post-click, not just pre-click. Measure time-to-detect anomalous session behaviour and time-to-revoke a credential. Those are the numbers that move your loss curve now.
- Re-brief your people honestly. Tell them the lures are now indistinguishable and that reporting a click fast matters more than never clicking. Shame is the main reason incidents surface late.
Long reads are collected weekly on the ClearGlass Insights desk. Curation criteria: measurable, primary-source-checkable, and useful to someone making a decision this month. Press Ctrl / ⌘ + K to jump to any brief.
Assume the click. Then make it survivable.
ClearGlass builds governed systems where a working credential is not a standing licence: scoped identities, approval gates at consequential boundaries, and an append-only ledger for every material action.