The Impact of Emerging Phishing Threats: Assessing Quishing and LLM-generated Phishing Emails against Organizations
Marie Weinz, Nicola Zannone, Luca Allodi, Giovanni Apruzzese

TL;DR
This study evaluates the effectiveness of emerging phishing tactics like quishing and LLM-generated emails, revealing their high success rates and the need for improved detection and awareness strategies in organizations.
Contribution
It provides empirical data on the real-world impact of quishing and LLM-assisted phishing, highlighting their threat level and assessing employee awareness correlations.
Findings
Quishing emails are as effective as traditional phishing.
LLM-generated phishing emails have high open and click rates.
Employee awareness correlates with organizational resilience.
Abstract
Modern organizations are persistently targeted by phishing emails. Despite advances in detection systems and widespread employee training, attackers continue to innovate, posing ongoing threats. Two emerging vectors stand out in the current landscape: QR-code baits and LLM-enabled pretexting. Yet, little is known about the effectiveness of current defenses against these attacks, particularly when it comes to real-world impact on employees. This gap leaves uncertainty around to what extent related countermeasures are justified or needed. Our work addresses this issue. We conduct three phishing simulations across organizations of varying sizes -- from small-medium businesses to a multinational enterprise. In total, we send over 71k emails targeting employees, including: a "traditional" phishing email with a click-through button; a nearly-identical "quishing" email with a QR code…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
