Microsoft Warns of Phishing Attacks Using ChatGPT and Claude as Bait
The attacks show threat actors are exploiting the AI hype cycle to steal credentials through sophisticated, multi-step phishing lures that bypass email filters and mimic legitimate brand interfaces.
Key Facts
- Microsoft detected a phishing campaign on May 5, 2026, that sent up to 100,000 emails per day impersonating ChatGPT and targeting recipients in South Africa, Switzerland, and Austria.
- The ChatGPT-themed phishing emails demanded payment method updates under threat of account downgrade and used multiple redirects through legitimate services like Rebrandly to evade filters.
- Microsoft found that shared infrastructure between the two campaigns suggests the same threat actors are behind both operations.
Reporting from 1 source: GIGAZINE.
Microsoft has identified a surge in phishing attacks that impersonate AI brands like ChatGPT, Claude, DeepSeek, and Microsoft Copilot. One campaign sent up to 100,000 emails per day targeting South Africa, Switzerland, and Austria, while another targeted over 2,000 organizations in the US, UK, and India with fake terms-of-service violation appeals.
Microsoft analyzed two major phishing campaigns that use AI brand names as social engineering bait. In one campaign detected on May 5, 2026, emails impersonating ChatGPT demanded payment method updates under threat of account downgrade. The emails, sent to 4,500 recipients in South Africa and up to 100,000 per day across Switzerland, Austria, and South Africa, used multiple redirects through legitimate services like Rebrandly to evade filters. Victims were led to a fake ChatGPT page that asked for personal and credit card information after a CAPTCHA-like step.
A separate campaign targeting Claude users sent over 2,000 spoofed emails to organizations in the US, UK, and India between April 20 and 22, 2026. The emails claimed the recipient's account had violated the Acceptable Use Policy and included a PDF attachment with an appeal link. Clicking the link led through a Cloudflare-mimicking authentication screen to a Claude-styled compliance page, then likely to a fake Microsoft sign-in page designed to capture credentials. Microsoft noted that shared infrastructure between the two campaigns suggests the same threat actors are behind both operations.
Synthesized by Yomimono from the 1 cited source below, including Japanese-language reporting where cited, then editorially reviewed before publishing.