Skip to content
Study report, HSLU and Cyberdise, 2025

~60% less risky clicking after AI spearphishing exercises

539 employees in four groups, measured from November 2024 to June 2025. Training improved attitudes, but the biggest change in what people actually did came from realistic exercises. The three-page report is free, with no form to fill in.

Top of the study report Leveraging AI-enabled spearphishing to enhance cybersecurity, with the study directors, the partners and the abstract
The three phases of the study: a baseline with two phishing exercises and a questionnaire, one intervention per group (control group, training, conventional phishing, AI OSINT phishing), and a follow-up exercise to measure again
Innosuisse research project 73275.1

Leveraging AI-enabled spearphishing to enhance cybersecurity

Led by Dr. Carlo Pugnetti of the Lucerne University of Applied Sciences and Arts (HSLU) and Palo Stacho of Cyberdise, with GLB Group as a study partner. Baseline in November and December 2024, one intervention per group in May 2025, and a final exercise in May and June 2025 to measure the change.

  • Can AI spearphishing work in Europe, where less personal data is public?
  • Which changes behavior more, training or realistic attacks?
  • What does each approach do to attitude, and what to behavior?

Download the report, 0.5 MB

What changed behavior

Biggest drop: AI spearphishingAll three interventions lowered risky clicking, and AI spearphishing lowered it most, about 60% against its own baseline, with the difference between the groups significant at p = 0.03.
Only training moved attitudesIt was the only intervention that significantly improved how people see cyber risk, so the report's conclusion is to run both.
8.9%of the AI spearphishing group visited the phishing site in the final exercise, down from 22.6%
10.9%of the conventional phishing group
12.1%of the training group
20.4%of the control group, the same as at baseline

Source: AISP study

From the study into the product

The exercises in the study were built from public information about each person. That work first appeared in Cyberdise in V2.7 as OSINT reconnaissance and is now part of Behavioral Defense Engineering, together with a generator that writes a phishing message for each recipient. The report also found that one well-run campaign no longer showed an effect on attitude after five months, so Cyberdise runs practice as a continuous loop.

See how personalized campaigns work

The OSINT data of one recipient in Cyberdise, with public facts grouped into links, names, skills such as risk analysis, and hobbies such as skiing

Related research

The earlier HSLU paperPugnetti and others, Risks, 2024: the paper that separates risk attitude from risk behavior, the distinction this study builds on.Read it at the journal
The HSLU project pageThe Lucerne University of Applied Sciences and Arts describes the research project on its own site.Go to hslu.ch
Who ran the study?
The Institute of Financial Services Zug at HSLU and Cyberdise, as Innosuisse research project 73275.1, with GLB Group as a study partner. The study directors were Dr. Carlo Pugnetti (HSLU) and Palo Stacho (Cyberdise).
Is the study peer reviewed?
Not yet. The full paper has been submitted for publication. The report you can download here summarizes the project and its results.
What does ~60% refer to?
In the AI spearphishing group, the share of people who visited the phishing site fell from 22.6% at baseline to 8.9% in the final exercise, a relative drop of about 60%. The control group stayed at 20.4%.
Does this mean awareness training is useless?
No. Training lowered risky clicking too, and it was the only intervention that significantly improved attitudes. The study argues for training and realistic exercises together.
Do I have to fill in a form to get the report?
No. The download is open.

Run the exercises from the study with your own people.

In 30 minutes we show you how Cyberdise writes a personal exercise for each recipient and follows up on every click and every report.