Threat actors are not just taking advantage of AI to spruce up their social engineering tactics or phishing emails – they are increasingly using well-known AI brands in their attacks.
Cyber-criminals have been using AI’s fandamonium against users, leveraging AI brands as a lure to unsuspecting victims seeking out popular AI chatbots and services.
This is according to Microsoft’s Threat Intelligence group, which tracked the rise cyber campaigns impersonating popular AI platforms like ChatGPT, Anthropic’s Claude, DeepSeek, and Microsoft’s own Copilot.
While the campaigns do not mean that these servicces were compromised, they did lead to phishing, malvertising, and SEO-driven attacks, which resulted in credential threft, fraud, or malware infection.
The team at Microsoft identified various incidents where threat actors utilised fake-AI services as lures, even observing an initial access broker using AI-themed malvertising in payload delivery operations.
“While traditional lures like invoices, payment notifications, or delivery alerts remain effective and continue to be widely used, AI-themed lures reflect a shift in social engineering that is likely to persist as a long-term tactic used by threat actors, from cyber-criminal groups to nation states,” the threat intelligence group’s blog said.
Microsoft viewed a ChatGPT-themed phishing attack that using malicious URLS to direct users to phishing pages for credit card and personal information collection. The email-based attack used ChatGPT in the sender display name, with the subject reading: “To ensure your ChatGPT Plus continues to work – please update your payment method”.
Targeted users were urged to update their payment method as soon as possible, with the email using a prominent ChatGPT logo. The “update payment button” redirected users to one landing page first with a fake CAPTCHA, then a page to confirm personal details, before finally a page to input credit card information.
Microsoft also saw a Claude-themed attack campaign, with phishing emails requiring updated to Claude accounts. The emails impersonated Anthropic’s service teams convicing targets that an account violation needed to be addressed, directing users to a PDF meant to look like an actual Claude document.
Recommended reading
- AI-powered Phishing Attacks Hitting Inboxes Every 19 Seconds
- ICO Sets Out Five Steps to Tackle AI Cyber Threats
- GCHQ Announces New National AI Cyber Shield
A fake Cloudflare landing page likely acted as a way to impede automated analysis for security, with further landing pages resulting in a no-longer available page that the Micorosft team identified as a fake Microsoft sign-in page.
While Microsoft identified other attacks using AI-themed lures, these expemplify two typical tactics that targeted different information – credit cards and account credentials.
The Micorosft Threat Intelligence made some suggestions for mitigating the threat of cyber-criminals using AI brands as lures, including enforcing multifactor authentication (MFA) and using athentication methods such as passkeys.





