AI-powered threats: A Systematic Review of Generative Artificial Intelligence in Phishing Emails and Phishing URL
DOI:
https://doi.org/10.63964/s5d8m457Keywords:
Phishing; Phishing detection; Social engineering; Generative AI; URL phishing; Email phishing.Abstract
Recent breakthroughs in generative artificial intelligence (Gen-AI) and large language models (LLMs) have improved productivity across many domains but also increased the level of phishing attack realism and targeting. This systematic review examines recent studies on (i) the application of LLMs and other Gen-AI technologies to phishing email composition and phishing URL creation or obfuscation, (ii) phishing email and URL detection, and (iii) human factors in phishing vulnerability. The review considered studies published between 2020 and 2025 and compared their performance using accuracy, recall, precision and F1-score metrics. The reviewed indicates that Machine Learning (ML), Deep Learning (DL), and ensemble learning have been widely used in phishing detection. For email phishing detection, BERT transformer models have shown the highest performance in all studies reviewed. For URL phishing detection, hybrid models that combine structural and lexical information have shown the best performance. The review also emphasizes the role of human factors, such as familiarity of the sender and the fear of missing out (FoMO), in influencing phishing vulnerability. Overall, the findings support combining high-performing detection models with user-centered warnings and training to improve real-world phishing resilience.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Journal of Al-Turath University College

This work is licensed under a Creative Commons Attribution 4.0 International License.
