Image: By Rawpixel/ Envato
AI’s presence in targeted business email compromise attacks is rising, according to a new Barracuda study.
AI is generating 51% of all spam emails. This isn’t something to worry about — as long as AI-generated spam remains text-based, according to Columbia University associate professor Asaf Cidon.
This finding is in a new Barracuda study, conducted with researchers from Columbia University and the University of Chicago.
Two additional insights from the Barracuda study stand out:
“The results show that currently, attackers are primarily using AI to evade spam filters and to reduce grammatical errors and typos,” Wei Hao, a PhD computer science student at Columbia University and the study’s lead author, told TechRepublic.
Hao’s advisor, Cidon, an associate professor at Columbia University, added that the researchers were pleasantly surprised to find that they could accurately estimate the prevalence of AI being used in spam mail by cybercriminals. “So far, almost all the research done on this topic has been extremely anecdotal and speculative,” Cidon noted.
Right now, no one should be concerned about AI-generated spam — as long as it remains text-based, he said.
The study notes that AI’s presence in targeted business email compromise (BEC) attacks is rising, though still at 14% for now.
However, the rapid adoption of AI by attackers is alarming, Cidon stressed, “especially given the exponentially decreasing cost and increasing efficiency of multimodal models,” and notably, “the recent rise of very cheap and very efficient voice cloning and text-to-voice models.”
Once those models are widely adopted by attackers, Cidon said, “I am afraid we will see much more effective impersonation/BEC-style attacks.”
To differentiate AI-generated messages from human-written content, researchers trained a model on pre-ChatGPT spam data and used it as a benchmark to detect AI-generated emails in a real-world sample. The researchers then applied the model to a large dataset of malicious emails from early 2022 to April 2025, tracking how tone and structure shifted after generative AI became mainstream.
Read our coverage of rising cyberattacks and Check Point’s analysis to learn how threat actors are evolving in the age of AI-powered malware.
Esther Shein is a freelance writer and editor who specializes in writing about AI, cloud, cybersecurity, data, software, and IT leadership. In addition to TechRepublic and eWeek, her work has appeared in CIO.com, CSOOnline, ZDNet, TechTarget, Communications of the ACM, Consumer Goods Technology, Computerworld, The Boston Globe, and Inc. She has also written thought leadership whitepapers, ebooks, case studies, and marketing materials.