MICROSOFT warns that AI branding is being used as a lure to make phishing, malvertising and credential theft more believable. Threat intelligence from Microsoft Threat Intelligence identifies campaigns impersonating ChatGPT, Microsoft Copilot, DeepSeek and Claude, including a ChatGPT-themed phishing kit that sought credit card data and a Claude-themed campaign using adversary-in-the-middle techniques.
The campaigns harness fake updates or policy notices, lookalike domains and multi-stage redirection to move from email to malicious links, downloads or credential collection, exploiting user curiosity around AI advances. A notable example noted in the report mentions a ChatGPT-themed phishing effort that sent up to 100,000 emails in a day. The analysis emphasises that these are not breaches of AI services, but classic manipulation of trust around a timely topic.
Defender’s defence starts before users engage with lures, using anti-phishing policies to detect spoofing and impersonation, plus Safe Links for URL scanning and time-of-click verification, and Safe Attachments to detonate suspicious attachments in a virtual environment. When attackers move beyond email, Defender correlates signals across email, endpoints, identities and SaaS apps to present an attack story and enable disruption.
The post-delivery capabilities help remove malicious content, and attack disruption can contain compromised assets to halt lateral movement. A recent case study showed disruption within four minutes of initial activity in a business email compromise tied to an OAuth device code phishing flow, preventing persistence, inbox rules or payroll fraud. Microsoft notes Defender disrupts more than 45,000 AiTM attacks monthly and protects around 81,000 compromised user accounts monthly.