AI Brand Phishing: ChatGPT, Copilot and Claude as Lures

Your employees now have accounts with AI services they did not have two years ago, and attackers have noticed. A mail claiming 'your ChatGPT Plus payment failed' or 'your Claude account violated our usage policy' lands differently than yet another fake bank alert, because millions of workers genuinely hold those subscriptions and genuinely fear losing access mid-project. Microsoft Threat Intelligence has now documented this lure family in detail, and it belongs on every security team's radar.
Microsoft Documents the New Lure Family
In a June 8, 2026 report titled AI brands as bait, Microsoft Threat Intelligence describes active campaigns impersonating ChatGPT, Microsoft Copilot, DeepSeek, and Anthropic's Claude. The logic is classic brand phishing applied to a brand category that barely existed in most workplaces until recently. Where attackers once leaned exclusively on banks, parcel carriers, and Microsoft 365, they now add the AI tools employees use daily and, crucially, pay for personally or through the company card.
The scale is not experimental. Microsoft observed a single AI-brand campaign delivering as many as 100,000 emails in one day, with threat actors rotating between AI brand lures the way they have long rotated between banks and delivery services. When one brand's lure gets burned, the next is a template swap away.
The Fake Payment Failure: ChatGPT Plus as Bait
On May 5, 2026, a campaign of roughly 4,500 emails, 97 percent of them targeting South Africa, told recipients their ChatGPT Plus payment needed updating. Victims who clicked were routed through multi-step redirects that abused legitimate services, a common technique for defeating URL reputation checks, before landing on a page that harvested card and personal data.
The payment-failure premise is effective precisely because it mirrors reality. Subscription cards expire, renewals fail, and the legitimate services really do send dunning emails. An employee who relies on an AI assistant for daily work has a concrete, immediate reason to fix a billing problem fast, and urgency is the phisher's oldest ally.
The Fake Policy Violation: Claude Users Under Pressure
Between April 20 and 22, 2026, a campaign impersonating Anthropic hit more than 2,000 organizations, 62 percent in the United States, 18 percent in the United Kingdom, and 9 percent in India. The lure claimed the recipient's account had violated the 'Account Usage Policy' and offered a PDF 'appeal' attachment. The flow led to adversary-in-the-middle credential harvesting, the technique that captures session tokens and defeats basic MFA.
This variant weaponizes a different emotion: professional anxiety. An accusation of policy violation implies the employee did something wrong, perhaps pasted sensitive data into a chatbot against company rules, and the offer of an appeal channels that anxiety into immediate compliance. Employees who feel guilty click faster and scrutinize less.
45 Minutes From Announcement to Malware
The third pattern targets enthusiasm rather than fear. On April 24, 2026, a fake 'DeepSeek V4' GitHub repository appeared within 45 minutes of the official product announcement, ranked among the top four results in installer searches, and delivered Vidar Stealer, an infostealer that harvests passwords, cookies, and session data. Vidar is not a proof of concept: the browser credentials and session tokens it collects feed directly into the criminal credential economy, so a single enthusiastic install can expose every account on the machine, corporate logins included.
Forty-five minutes is faster than most security teams can even circulate an advisory. Early adopters inside your company, often the most technically confident people, are exactly the ones racing to install a hot new model the hour it ships. Their confidence works against them: they know how to find and install software quickly, and speed is the vulnerability this lure exploits.
Adding AI-Brand Lures to Your Training Program
This lure family deserves explicit coverage in awareness programs, because generic phishing training does not automatically transfer to a novel brand context. An employee who would never fall for a fake bank alert may still trust a subscription notice from a tool they used an hour ago. And as Microsoft's analysis shows with the ChatGPT Plus campaign's redirects through legitimate services, even disciplined link-hovering can be defeated when the first hop looks respectable. The response has to be layered: realistic practice, simple verification rules, and controlled software channels. Practical steps:
- Add AI-brand templates to your phishing simulation library. Payment-failure, policy-violation, and new-model-download scenarios mirror the three real patterns Microsoft documented. empowsec customers can build these as custom scenarios alongside the classic bank and Microsoft 365 lures, and use risk scoring to see which teams bite.
- Establish the verification rule. Billing and account problems get checked inside the app or on the vendor's website typed by hand, never through email links or attachments.
- Give guilt an official channel. Tell employees that policy-violation notices claiming to come from AI vendors should go straight to IT, and that reporting one is never punished, so anxiety cannot be leveraged against them.
- Control the software supply. New AI tools and models should arrive through an approved internal process, not through whichever repository ranks highest in the first hour of a launch.
- Brief your early adopters. The DeepSeek case shows attackers move within the hour of a release; the colleagues most excited about AI need this story specifically.
Key Takeaways
- Attackers follow habits, and AI is now a habit. Microsoft documents active phishing impersonating ChatGPT, Copilot, Claude, and DeepSeek, with a single campaign delivering as many as 100,000 emails in one day.
- Three emotional levers, one family: billing urgency (fake ChatGPT payment failures), professional anxiety (fake Claude policy violations), and enthusiasm (fake DeepSeek releases delivering Vidar Stealer).
- MFA is not a safety net here. The Anthropic-themed campaign used adversary-in-the-middle harvesting that captures authenticated sessions.
- Speed is part of the attack. A malicious repository ranked top-4 in search results within 45 minutes of a product announcement.
- Update your simulations now. Security awareness training that never mentions AI-brand lures leaves a fresh, fast-growing gap untested.
Every new tool your workforce adopts becomes a costume for attackers within months. The organizations that adapt their training as fast as their employees adopt new brands will be the ones that keep the click rate down.


