Microsoft Warns of Phishing and Malware Campaigns Using AI Brands as Lures

Microsoft Threat Intelligence said threat actors have used the branding of ChatGPT, Microsoft Copilot, Claude and other AI services in phishing, malvertising and search-driven campaigns. Its June report says the activity exploits familiar names as lures rather than showing that the referenced AI services were compromised, making domain and sender verification a practical security concern for teams adopting AI tools.
Microsoft Threat Intelligence has documented phishing, malvertising and search-engine-optimization campaigns that borrow the names and visual identity of popular AI services, including ChatGPT, Microsoft Copilot and Anthropic's Claude. The company’s June report says the campaigns use the brands as social-engineering lures; it does not describe a compromise of the referenced services.
What Microsoft observed
Microsoft described several distinct campaigns. A ChatGPT-themed phishing operation used messages about a supposed subscription-payment update to direct recipients through a chain of redirects to pages seeking personal and payment-card information. The company said it detected one wave on May 5 that sent 4,500 emails, largely to recipients in South Africa.
Microsoft also described an Anthropic-branded campaign observed from April 20 to 22. The messages used account-enforcement language and a PDF attachment designed to steer recipients toward a credential-harvesting flow. Microsoft said the activity targeted more than 2,000 organizations, with most targets in the United States, the United Kingdom and India.
The report also covers AI-themed malvertising and fake software repositories. Those lures capitalized on searches for AI tools and model releases, while the payloads sought to install information-stealing malware or route victims to other malicious infrastructure.
Why the distinction matters
The reported risk is brand impersonation, not evidence that ChatGPT, Claude or Copilot itself was breached. That distinction matters for incident triage: a suspicious payment notice, installer or account-warning message should be evaluated by its sender, domain, attachment and destination rather than by the familiarity of the logo it displays.
For organizations rolling out AI tools, the report is a reminder that new product names can quickly become useful phishing bait. Microsoft’s guidance emphasizes established controls such as phishing protection, endpoint detection and user reporting, alongside verification of unexpected account or software prompts through known official channels.
Key Points
- 1Microsoft says the campaigns impersonate AI brands as lures and do not show that the referenced services were compromised.
- 2A ChatGPT-themed payment lure and an Anthropic-branded account-enforcement lure were among the campaigns Microsoft described.
- 3AI-tool adoption creates a recognizable brand surface that security teams should include in phishing and software-installation awareness efforts.
Scoring Rationale
A first-party threat-intelligence report documents active social-engineering patterns that affect organizations and individuals using widely recognized AI services.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems


