Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →DeepPhish showed that an AI model could generate phishing URLs that bypassed one tested detector more often—but it did not show that the URLs stole credentials or defrauded victims. The 2018 Cyxtera-affiliated study measured detector evasion, while a separate report later described defenders retraining their system to reduce the attack’s effectiveness.
What was DeepPhish?
DeepPhish was a 2018 research experiment, not a consumer product or a live phishing campaign. Researchers affiliated with Cyber Threat Analytics at Cyxtera Technologies—Alejandro Correa Bahnsen, Ivan Torroledo, Luis David Camacho, and Sergio Villegas—investigated whether machine learning could produce new phishing URLs that were harder for a proactive detection system to block.
The team analyzed 1,146,441 phishing URLs collected from PhishTank in 2017. It identified threat actors through shared URL patterns and hosting domains, then trained a Long Short-Term Memory (LSTM) neural network on effective URLs. The model learned character-sequence patterns and generated synthetic URLs intended to evade the researchers’ detector. The primary paper, “DeepPhish: Simulating Malicious AI”, describes the method and experiment.
As Dark Reading reported on October 26, 2018, Cyxtera’s Alejandro Correa summarized the motivation: “We wanted to figure out what is the best way, from an attacker’s perspective, to bypass these detection algorithms.”
#1 Best Overall
Could AI make phishing URLs harder to detect?
In this experiment, generated URLs bypassed the tested detector at higher rates than the comparison results for two modeled threat actors. The paper’s “effectiveness” measure is the share of URLs that the proactive detection system did not block.
| Modeled threat actor | Before DeepPhish | After DeepPhish |
|---|---|---|
| Threat Actor 1 | 0.69% of URLs bypassed the detector | 20.9% of URLs bypassed the detector |
| Threat Actor 2 | 4.91% of URLs bypassed the detector | 36.28% of URLs bypassed the detector |
These are detector-bypass results from the paper’s experiment, not click-through rates, credential-theft rates, or estimates of successful fraud. They show that URL generation could challenge the particular detector used in the study; they do not establish performance against every email gateway, browser, security service, or present-day AI system.
Did DeepPhish steal credentials?
No credential acquisition was measured. The paper says its data limitations prevented the researchers from determining whether an attacker obtained credentials. The work tested URL generation and detector evasion, not what happened after a person received or visited a URL.
That distinction matters: a URL passing a detector is one step in a possible attack, not proof that a person clicked it, entered information, or suffered a loss.
Rank #3
Did defenders find a way to stop it?
SecurityWeek reported on December 7, 2018, that a blue team retrained its anti-phishing system and reduced DeepPhish’s effectiveness. That is a separately reported defensive response, not a result described in the primary paper. SecurityWeek’s coverage provides the account of that response.
The combined lesson is limited but useful: attacker-side generation and defender-side retraining can affect a detector’s performance. The study does not prove that AI invariably gives either attackers or defenders the advantage.
Rank #4
Was the study about spear-phishing?
No. The experiment focused on phishing URLs and the detector’s response to them. SecurityWeek said the project did not study spear-phishing because available labeled examples were too few and imbalanced for standard machine-learning methods. That scope explanation belongs to the coverage and the prior work it cites, not to a claim that the experiment evaluated targeted campaigns.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the findings do—and do not—establish
- Established: An LSTM trained on patterns in previously effective phishing URLs generated synthetic URLs that bypassed the researchers’ detector at higher rates for two modeled actors.
- Not established: Whether those URLs reached victims, induced clicks, captured credentials, or caused financial harm.
- Not generalizable from this experiment alone: How all current phishing defenses or AI models perform, or whether the result would hold across other detectors and attack settings.
A different 2022 USENIX Security paper also titled “DeepPhish” studies user trust in artificially generated social-media profiles. It is a separate project, not the 2018 Cyxtera URL-generation study discussed here.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

