AI-powered threats: A Systematic Review of Generative Artificial Intelligence in Phishing Emails and Phishing URL

Authors

  • Ahmed R. AlKarawi Department of Computer science, College of Science, Mustansiriyah University, Baghdad, Iraq Author
  • Zied Othman Ahmed Department of Computer science, College of Science, Mustansiriyah University, Baghdad, Iraq Author

DOI:

https://doi.org/10.63964/s5d8m457

Keywords:

Phishing; Phishing detection; Social engineering; Generative AI; URL phishing; Email phishing.

Abstract

Recent breakthroughs in generative artificial intelligence (Gen-AI) and large language models (LLMs) have improved productivity across many domains but also increased the level of phishing attack realism and targeting. This systematic review examines recent studies on (i) the application of LLMs and other Gen-AI technologies to phishing email composition and phishing URL creation or obfuscation, (ii) phishing email and URL detection, and (iii) human factors in phishing vulnerability. The review considered studies published between 2020 and 2025 and compared their performance using accuracy, recall, precision and F1-score metrics. The reviewed indicates that Machine Learning (ML), Deep Learning (DL), and ensemble learning have been widely used in phishing detection. For email phishing detection, BERT transformer models have shown the highest performance in all studies reviewed. For URL phishing detection, hybrid models that combine structural and lexical information have shown the best performance. The review also emphasizes the role of human factors, such as familiarity of the sender and the fear of missing out (FoMO), in influencing phishing vulnerability. Overall, the findings support combining high-performing detection models with user-centered warnings and training to improve real-world phishing resilience.

Downloads

Published

2026-08-16