Blog Main Image
September 15, 2026

AI Brands as Bait: When Phishing Looks Like ChatGPT

A billing notice from an AI assistant now belongs in the same mental bucket as a fake invoice or a missed delivery card. Microsoft Threat Intelligence has been tracking a run of campaigns that borrow the branding of ChatGPT, Microsoft Copilot, DeepSeek and Anthropic's Claude, then use that borrowed familiarity to sell people a story they are already half expecting. Your subscription needs attention. There is a new model to try. Here is the plugin everyone has been talking about. One ChatGPT themed campaign reached as many as 100,000 emails in a single day.

What Microsoft has been tracking

In research published on 8 June 2026, Microsoft described a growing set of campaigns that impersonate the branding of popular AI platforms. The activity spans phishing email, malvertising (malicious adverts that push people towards harmful sites or downloads) and search engine manipulation, and it ends in credential theft, financial fraud or malware infection.

One point deserves emphasis before anyone reaches for a headline. Microsoft is explicit that these campaigns do not represent a compromise of the AI services being referenced. Nothing has been breached at OpenAI, Microsoft, DeepSeek or Anthropic. Attackers are borrowing a brand, which is a far older trick than the brand itself.

The numbers give a sense of scale. On 5 May 2026 Microsoft detected a ChatGPT themed phishing attack that led users to pages collecting credit card details along with names and addresses. That burst was 4,500 emails, 97 per cent of them aimed at South Africa. It formed part of a wider campaign that delivered as much as 100,000 emails on a single day to targets in Switzerland, Austria and South Africa, across industries including higher education and professional services.

Why an AI brand makes such useful bait

Phishing works when a message arrives in a gap where the recipient has no settled habit, and AI subscriptions sit squarely in that gap. Think about how these tools entered your workplace. Someone signed up personally and expensed it. A team lead bought seats on a card. IT rolled out a licence for a group already using the free tier. Ownership is genuinely fuzzy, and the billing relationship is new enough that nobody has years of muscle memory for what a real message from the provider looks like. When a payment notice lands, the honest answer for many staff is that they are not sure who normally deals with it. That uncertainty is what the attacker is buying.

The emotional levers are the familiar ones: urgency because access might stop, curiosity because a new model is genuinely interesting, and a logo people see every day. Only the wrapper has changed.

Timeline diagram showing a DeepSeek V4 preview, a fraudulent GitHub organisation appearing 45 minutes later, a 4,500 email ChatGPT themed wave on 5 May 2026, a peak day of up to 100,000 emails, and the tactic being brokered to multiple actors
The gap between an AI announcement and its first fake is now measured in minutes.

Attackers move faster than the announcement cycle

The speed is the part that should reshape how security teams think about awareness content. In April 2026 Microsoft observed a campaign exploiting interest in the newly released DeepSeek V4 by impersonating it through a fraudulent GitHub repository and organisation. The fake GitHub organisation appeared within 45 minutes of the V4 preview.

Forty five minutes is shorter than most internal approval chains, and certainly shorter than the time it takes to write, review and publish a staff bulletin. Awareness material pinned to the specific brands of last quarter will always be running behind. What travels better is the underlying shape of the attack: a message that arrives unprompted, carries a well known logo, creates a reason to act now, and asks you to sign in, pay or install.

The lure is only the opening move

Microsoft's follow up post on 10 September 2026 set out what the research team has recently observed, and the variety is the point:

  • A ChatGPT themed phishing kit built to harvest credit card data.
  • A Claude themed campaign that harvested credentials and access tokens using adversary in the middle techniques.
  • Malvertising for a fake AI Windows plugin that delivered the Vidar information stealer.
  • Fraudulent DeepSeek installers distributed through GitHub.

Microsoft also notes that an initial access broker it tracks as Storm-3075 used AI themed malvertising to distribute payloads for several downstream actors. When a technique becomes a service one criminal group sells to others, it has stopped being a clever experiment and become part of the standard toolkit.

The adversary in the middle element deserves explaining properly, because it is where confident assumptions about multi-factor authentication come unstuck. The victim is sent to a page that quietly relays their session to the genuine service. The sign-in really does succeed, and the MFA prompt really is from the provider, so approving it is the correct answer to the question being asked. What the attacker captures is the session token issued afterwards, and a valid token can be reused without any further prompt. MFA still blocks a great deal of routine credential abuse and should stay switched on everywhere. It simply does not settle this question on its own, which is why phishing-resistant methods and device-based conditional access earn their place.

Microsoft also published a case study showing how quickly one of these chains runs. A document sharing lure persuaded a user to begin a legitimate Microsoft device code sign-in flow, sidestepping traditional credential theft entirely. Microsoft says it contained the account within four minutes, before the attacker could establish persistence, create inbox rules or attempt payroll fraud. For context on volume, Microsoft states that its attack disruption capability contains more than 81,000 compromised user accounts and disrupts more than 45,000 adversary in the middle attacks each month.

What this means for the people in your organisation

None of this is a story about staff being gullible. A finance assistant who receives a plausible renewal notice for a tool their colleagues genuinely use is being asked to make a judgement quickly, with incomplete information, on a subject nobody has briefed them about. Give people the missing information and the same judgement becomes easy. Practical steps that hold up well against AI themed lures:

  • Publish who owns AI subscriptions. A single line in the intranet naming the team that handles AI tool billing removes the ambiguity the lure depends on.
  • Separate the message from the action. Renewals, payment updates and licence changes should be checked by navigating to the provider directly or asking the named owner, never through a link in the message.
  • Control software installation. Fake installers and browser plugins only pay off where people can install unapproved software. Application control and a clear route to request tools do more here than any warning email.
  • Move towards phishing-resistant sign-in. Passkeys and hardware security keys, combined with conditional access that requires a managed device, remove most of the value of a stolen session token. Restrict device code authentication where you do not need it, and alert on its use where you do.
  • Make reporting the fastest option available. If flagging a suspicious message takes one click and gets a quick answer, you hear about the campaign from the first recipient rather than the fortieth. A reporting and triage workflow turns each report into useful signal.
  • Test with lures that look like this week. A realistic simulation built around a subscription notice tells you far more than a generic parcel delivery template.

The bottom line

AI brands are the current bait because they carry trust and curiosity at once, and because the working relationship most people have with them is only a few months old. The technique underneath has not changed. Someone borrows a name you recognise, gives you a reason to hurry, and asks you to sign in, pay or install. Organisations that name the owners, control installation, harden sign-in and make reporting effortless will find the next themed lure lands as an irritation rather than an incident. The brand on the next one will be different. The shape will not be.

Phishing Tackle offers the tools businesses need to strengthen their human risk strategies, with multi-platform testing, real-time behavioural insights, and actionable data to keep your organisation ahead of modern cyber threats.

Contact us today to learn how Phishing Tackle can help safeguard your organisation from the growing array of cyber risks.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Scroll To Top Arrow