AI is now responsible for more than half (51%) of all malicious and spam emails, research from Barracuda found, in a collaborative study with Colombia University and the University of Chicago.
Analysing a dataset of spam emails detected from February 2022 to April 2025, trained detectors from Barracuda determined if malicious or spam emails were made using AI.
From November 2022 to early 2024, the researchers identified a continual increase in the number of spam emails that were generated using AI.
November 2022, of course, was the month that ChatGPT was launched, bringing advanced AI technology to the public’s finger tips, for better or for worse.
Following this, March 2024 saw AI-generated spam emails shoot up, then undulate since July 2024. By April 2025, more than half of all unsolicited emails were AI-generated, the research found.
Business email compromise, however, saw a different, much less dramatic pattern following the advent of ChatGPT.
These emails saw a spike in AI-generation in July 2023, but only just above a tenth. By April 2025, AI was responsible for just 14% of all business email compromise attempts detected by Barracuda.
This trend makes sense within context – while AI may be highly effective in churning out spam, targeted attacks requiring impersonation or more tactical social engineering will require finesse that may still require a human touch.
Recommended reading
- Is ChatGPT Driving the Rise in Malicious Emails?
- Report: Half of Domains Still Lack Adequate Email Protection
- Renewed Warnings As Social Media and Email Fraud Skyrockets
However, the research found that AI-generated emails have less grammatical or spelling errors, and were more formal and sophisticated compared to those written by humans.
This often makes AI-generated emails more difficult to spot than traditional spam or phishing emails, as tell-tale signs traditionally included bad grammar and spelling. They can also help the AI emails bypass detection systems often offered by security vendors and email platforms.
AI is also being used as testing grounds to see which wording variations are more effective in evading detection and garnering clicks from targets.
However, researchers found that AI emails tended to stress the same level of urgency as those written by humans, meaning that, while AI may improve plausibility, tactics have remained largely unchained.





