AI-Generated Phishing Communications for Personalized Security Training

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing phishing simulation methods rely on static, manually designed content, limiting adaptability and flexibility, and require significant administrative effort to generate varied phishing communications.

Innovation Solution

Employing a generative artificial intelligence algorithm to automatically generate personalized phishing communications based on user data, using templates filled with user-specific information and adaptable parameters, reducing administrative burden.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If predetermined static text is used for phishing communication content, then the communication can be manually designed and sent, but the adaptability and flexibility are limited and significant administrative effort is required

Engineering Contradiction:
Improveadaptability of phishing communication contentVSAvoidadministrative effort for generating communications
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system enables self-service by allowing phishing communication content to be automatically generated based on user profiles and campaign parameters without requiring manual drafting. The generation module automatically creates personalized messages by combining template structures with user-specific data, eliminating the need for administrators to manually craft each communication while maintaining high adaptability to different user contexts

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system applies parameter changes by dynamically adjusting communication content based on user attributes such as job role, department, and behavioral data. Rather than using fixed static text, the system modifies message parameters including sender identity, subject line, body content, and timing to match the target user's profile, thereby achieving high versatility without proportional increases in administrative complexity

Inventive Principle:
Principle #35Parameter changes

2Productivity

If manually designed predetermined text is used, then the content can be controlled, but the number of types of phishing communications that can be issued is limited and generation is laborious

Engineering Contradiction:
Improvenumber of phishing communication types issuedVSAvoidtime for generating communication content
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system implements preliminary action by pre-defining communication templates and structures that can be rapidly instantiated with user-specific data. Templates include pre-configured elements such as sender profiles, message formats, and contextual variables, allowing the system to generate diverse communication types quickly without manual design effort for each new campaign

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system achieves universality through a single communication generation module that can produce multiple types of phishing communications across different formats (email, instant message, SMS) and contexts. The template-based approach with parameter substitution allows the same system to generate various communication types by changing input parameters rather than requiring separate manual design processes for each type

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12537847B2Cyber security phishing campaign
Publication Date: 2026.01.27 OUTTHINK LTD
  • US12537847B2 patent drawing
  • US12537847B2 patent drawing
  • US12537847B2 patent drawing

AI summary

Embodiments describe herein relate to the automatic generation of personalised phishing communications for a target user within an organization. The content of a phishing communication is generated based on a generative artificial intelligence algorithm. In certain embodiments, data associated with the target user is as a part of a prompt to the generative artificial intelligence algorithm, enabling personalised content to be created. In further embodiments, we describe the use of templates associated with various parameters to be used as part of the prompt, which allows the content of the phishing communication to be customised according to the training requirements of a target user with minimal administrative input.