Connect with us

Hi, what are you looking for?

HEADLINES

ChatGPT phishing fantasies: Will AI chatbots help fight cyberscam?

A study revealed that although ChatGPT knows a great deal about phishing and can guess the target of a phishing attack, it had high false positive rates of up to 64 percent. Often, it produced imaginary explanations and false evidence to justify its verdicts.

Kaspersky experts have conducted research studying ChatGPT phishing links detection capability. While ChatGPT had previously demonstrated the ability to create phishing emails and write malware, its effectiveness in detecting malicious links was limited. The study revealed that although ChatGPT knows a great deal about phishing and can guess the target of a phishing attack, it had high false positive rates of up to 64 percent. Often, it produced imaginary explanations and false evidence to justify its verdicts.

ChatGPT, an AI-powered language model, has been a topic of discussion in the cybersecurity world due to its potential to create phishing emails and the concerns about its impact on cybersecurity experts’ job security even despite its creators’ warnings that it is too early to apply the novel technology to such high-risk domains. Kaspersky experts decided to conduct an experiment to reveal ChatGPT’s ability to detect phishing links, as well as the cybersecurity knowledge it learned during training. Company’s experts tested gpt-3.5-turbo, the model that powers ChatGPT, on more than 2,000 links that Kaspersky anti-phishing technologies deemed phishing, and mixed it with thousands of safe URLs.


In the experiment, detection rates vary depending on the prompt used. The experiment was based on asking ChatGPT two questions: “Does this link lead to a phishing website?” and “Is this link safe to visit?”. The results showed that ChatGPT had a detection rate of 87.2 percent and a false positive rate of 23.2 percent for the first question. The second question, “Is this link safe to visit?” had a higher detection rate of 93.8 percent, but a higher false positive rate of  64.3 percent. While the detection rate is very high, the false positive rate is too high for any kind of production application. 

Question askedDetection rateFalse positive rate
Does this link lead to a phishing website?87.2%23.2%
Is this link safe to visit?93.8%64.3%


The unsatisfactory results at the detection task were expected, but could ChatGPT help with classifying and investigating attacks? Since attackers typically mention popular brands in their links to deceive users into believing that the URL is legitimate and belongs to a reputable company, the AI language model shows impressive results in the identification of potential phishing targets. For instance, ChatGPT has successfully extracted a target from more than half of the URLs, including major tech portals like Facebook, TikTok, and Google, marketplaces such as Amazon and Steam, and numerous banks from around the globe, among others —without any additional training.

The experiment also showed ChatGPT might have serious problems when it comes to proving its point on the decision whether the link is malicious. Some explanations were correct and based on facts, others revealed known limitations of language models, including hallucinations and misstatements: many explanations were misleading, despite the confident tone.

Advertisement. Scroll to continue reading.
References to WHOIS, which the model doesn’t have access to: Finally, if we perform a WHOIS lookup for the domain name, it was registered very recently (2020-10-14) and the registrant details are hidden.References to content on a website that the model doesn’t have access to either:The website is asking for user credentials on a non-Microsoft website. This is a common tactic for phishing attacks.Misstatements:The domain ‘sxxxxxxp.com’ is not associated with Netflix and the website uses ‘http’ protocol instead of ‘https’ (the website uses https)Revelatory nuggets of cybersecurity information:The domain name for the URL ‘yxxxx3.com’ appears to be registered in North Korea which is a red-flag.

Examples of misleading explanations provided by ChatGPT

“ChatGPT certainly shows promise in assisting human analysts in detecting phishing attacks but let’s not get ahead of us – language models still have their limitations. While they might be on par with an intern-level phishing analyst when it comes to reasoning about phishing attacks and extracting potential targets, they tend to hallucinate and produce random output. So, while they might not revolutionize the cybersecurity landscape just yet, they could still be helpful tools for the community,” comments Vladislav Tushkanov, Lead Data Scientist at Kaspersky.

To learn more about the experiment, visit Securelist.com.

Kaspersky’s ML team is at the forefront of applying machine learning technologies to cybersecurity tasks, constantly updating Kaspersky products with the latest tech and intel. To take advantage of Kaspersky’s expertise in machine learning and stay protected, the company’s experts recommend:

  • For corporate cybersecurity, Kaspersky Managed Detection and Response is an essential tool capable of detecting and preventing intrusions in their initial stages. It utilizes advanced machine-learning models to filter out mundane events and sends only alarming ones to professional human analysts. This service enhances a company’s ability to withstand cyber threats while optimizing the use of existing workforce resources.
  • Providing your staff with basic cybersecurity hygiene training is crucial. Conducting simulated phishing attacks can also help ensure that they know how to distinguish phishing emails.
  • Lastly, using the latest Threat Intelligence information to stay aware of actual TTPs (tactics, techniques, and procedures) used by threat actors is also recommended to enhance cybersecurity.
Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

Maya has already integrated National ID eVerify, the Philippine Statistics Authority’s identity-verification service, into its onboarding process. Since early this year, eligible customers have been...

HEADLINES

In 2025 alone, Converge denied nearly 12 billion entry requests to websites hosting dangerous, inappropriate, and harmful content that attempted to pass through its...

HEADLINES

The announcement represents one of the first major third-party technology integrations following the launch of Sophos Fusion, demonstrating Sophos' commitment to an open ecosystem...

HEADLINES

APAC consumers are more concerned about digital tech usage for crime than consumers globally (35% vs 32%). The awareness is highest in Thailand (39%),...

HEADLINES

“It is the time for Radenta to demonstrate that it is strongly committed to protecting client data,” remarks Nereo Bolante, Co-Director, Radenta Ethics, Compliance, and Governance Team...

HEADLINES

Attackers are operationalizing artificial intelligence (AI) to collapse attack workflows from weeks to days. The report finds that AI’s most immediate impact on cybercrime...

HEADLINES

In July 2026, researchers from the Kaspersky Global Research and Analysis Team (GReAT) team identified a new campaign, dubbed GoSerpent, representing a sophisticated and...

HEADLINES

The prominence of identity attacks in ransomware indicates a shift in method, as attackers increasingly recognize identity as a key component in ransomware delivery....

Advertisement