This week’s long read · Cyber defense

AI-Generated Phishing Achieves a 54% Click Rate

A curated read for the week: measured impact instead of speculation. More than half of recipients clicked — and the useful conclusion is not about email filters. It is about identity.

Curated by Desmond Otieno Odhiambo8 minute readSource: WatchGuard Technologies
The long read

AI-Generated Phishing Achieves a 54% Click Rate

WatchGuard’s security blog, on what happens to social engineering when generative AI writes the lure.

Publisher
WatchGuard Technologies
Published
July 24, 2026
Topic
AI, cybersecurity, social engineering
Reading time
5–7 minutes
Cost
Free — no paywall, no registration
Read it at WatchGuard

The link above resolves to WatchGuard’s Spanish-language edition of the post, which is the version we could verify directly. English-language coverage of the same piece is indexed on the WatchGuard phishing blog hub.

Why it’s worth your time

Most AI-and-security writing is forecasting. This one is arithmetic. It reports a 54% click rate on AI-generated phishing campaigns — a measured outcome, not a projection about what attackers might eventually manage.

That single number reframes the debate. Generative AI is not primarily inventing new attack classes; it is making an old one dramatically more effective. Phishing did not need reinvention. It needed fluency, volume, and personalisation at near-zero marginal cost, and that is exactly what a language model supplies.

Click-through rate by lure typeShare of recipients who clicked. AI-assisted lures outperform manually written ones by 4.5×.
View as table
Click-through rate by lure type
Lure typeClick-through rate
AI-generated54%
Conventional (manually written)12%

Source: Microsoft Digital Defense Report 2025, as reported by WatchGuard. See the sourcing note.

Read the second bar first. A 12% baseline was already enough to justify an entire security industry. At 54%, “train users to spot the fake” stops being a control and becomes a hope.

Key insights

1. Scale is the real capability gain

AI lets attackers produce highly convincing phishing emails at volume, collapsing the cost and effort of running a campaign. Fluent grammar, plausible internal context, correct tone for the target’s industry — the artisanal parts of spear phishing are now automated. The economics that once limited high-quality targeting to high-value victims no longer apply.

2. Strong authentication is doing the load-bearing work

As lures improve, the controls that still hold are the ones that do not depend on a human noticing anything: phishing-resistant multifactor authentication, modern MFA rather than SMS codes, and a Zero Trust posture that treats every session as unproven until verified. These degrade gracefully when a user clicks. Awareness training does not.

3. The bottleneck moved from malware to identity

The decisive question is no longer “did our tooling detect the payload?” but “can a stolen credential actually be used?” Organisations that strengthen identity verification and access control are structurally better positioned against AI-enhanced phishing, because they are defending the step the attacker cannot automate away.

Why it matters

For anyone making budget decisions across AI, automation, and security, the strategic read is that AI is accelerating existing techniques far more than it is creating new ones. That has an uncomfortable corollary: the marginal detection tool is a weaker investment than it looks, because it is competing in the one category where the attacker’s cost curve just fell off a cliff.

Spending that compounds instead: identity, least-privilege access, verification of high-consequence requests, and operational processes that survive a successful click. Those controls are indifferent to how good the lure was.

This is the same logic ClearGlass applies to autonomous systems — put the gate at the consequential boundary, not at the point of persuasion. It is why our own operating model routes every material action through explicit approval rather than trusting that the input was legitimate. See AI Agents Are the New Insider Threat and The Case for Adaptive Trust for the architectural version of the argument.

Model the blast radius

The argument above is only useful if it changes a number you own. This model takes the click rate as a given and asks the question the article ends on: when the click happens, how far does it get? Change the inputs and watch which lever actually moves the outcome — it is not the click rate.

Blast-radius modelDeterministic · your inputs only

Clicked the lure540 
Submitted credentials162 
Accounts a stolen credential opens3 
Residual exposure0.3%of all recipients
Residual exposureContained
Assumptions — argue with these
  • This is arithmetic over your inputs, not telemetry. Nothing here is measured, sampled, or phoned home. The page holds no data and sends none; the scenario link encodes only the four values you set.
  • Click rate defaults to the reported 54% for AI-assisted lures, with the 12% conventional baseline one button away. Both trace to the Microsoft Digital Defense Report 2025.
  • Credential-submission rate defaults to 30% of clickers. Published figures for AI-assisted campaigns run around a third; substitute your own phishing-simulation results, which are the only numbers that describe your staff.
  • Posture factors (90% / 50% / 2%) are editorial estimates of how often a captured credential still yields account access under each posture — real-time relay defeats one-time codes, fatigue defeats push approval, and a hardware-bound key defeats both. Replace them with your own incident data before anyone spends money on the output.
  • Residual exposure is takeover-capable accounts as a share of all recipients. Thresholds: under 0.5% contained, under 5% elevated, above that critical. They are editorial bands, not a standard.

Move the click-rate slider from 12% to 54% and the first tile more than quadruples — that is the article’s finding. Now leave it at 54% and change the posture instead. The last two tiles collapse by more than an order of magnitude, and the click rate never moved. That asymmetry is the whole argument: you cannot buy the first number down, and you can buy the last two down.

Check the provenance before you quote it

Sourcing note

The 54% figure did not originate with WatchGuard. The post cites the Microsoft Digital Defense Report 2025, which reported a 54% click-through rate on AI-assisted phishing against 12% for manually written messages — the 4.5× multiplier quoted widely since. Independent academic work on automated spear-phishing campaigns validated on human subjects reports click-through in the same range.

If you plan to put this number in a board deck, cite the primary report rather than the secondary coverage, and state the comparison group. A click rate without its baseline is a headline, not evidence. That is a house rule here: provenance outranks persuasive output.

One takeaway

The line to keep

The competitive advantage is no longer detecting every phishing email. It is ensuring that a successful phishing attempt cannot easily become a successful compromise.

Assume the click. Design so the click is survivable. Identity-centric security is becoming the foundation of effective cyber defense in the AI era — not because detection stopped mattering, but because it stopped being sufficient.

Five moves this quarter

If the article persuades you, these are the changes that follow from it. None require a new detection product.

Long reads are collected weekly on the ClearGlass Insights desk. Curation criteria: measurable, primary-source-checkable, and useful to someone making a decision this month. Press Ctrl /  + K to jump to any brief.

ClearGlass Inc. · Identity-centric defense

Assume the click. Then make it survivable.

ClearGlass builds governed systems where a working credential is not a standing licence: scoped identities, approval gates at consequential boundaries, and an append-only ledger for every material action.

#AIphishing #SocialEngineering #IdentitySecurity #PhishingResistantMFA #ZeroTrust