Attackers Are Wrapping Old Phishing Tricks in AI Branding. It's Working.
Microsoft and Google both dropped advisories this week documenting how threat actors are dressing up familiar credential theft and malware campaigns as ChatGPT, Copilot, and DeepSeek experiences. The technique is not new. The success rate is.

Neither advisory describes a novel exploit class. That's the point.
Microsoft Threat Intelligence and Google's Fraud & Scams team published separate but converging findings: attackers are taking phishing, impersonation, and malware delivery — all thoroughly catalogued TTPs — and re-skinning them with AI product branding. ChatGPT subscription renewal emails. Fake DeepSeek V4 repositories pushing Vidar Stealer. QR-code lures routed through legitimate cloud productivity infrastructure. Calendar invites that abuse Google Workspace to land in inboxes with full trust signals intact.
In practice, the threat model hasn't changed so much as the costume has.
Microsoft's advisory states that AI-themed campaigns rely on "longstanding tactics" — urgency-driven messaging, multi-stage redirect chains, abuse of trusted SaaS surfaces. The difference is that employees now interact with AI tools as a routine part of their workday, which means a spoofed Copilot notification or a fake Claude billing alert arrives with plausible context. The failure mode here is familiarity. Users expect AI tools to ask them to log in, approve a subscription, or run a script. Attackers know this.
Google's figures put some scale on the problem: global fraud losses approaching $580 billion in 2025, with adversary-in-the-middle attacks specifically designed to mirror legitimate login flows so cleanly that FIDO2-resistant MFA is the only consistent technical control that holds.
Analysts framed this as a structural shift, not a campaign spike. IDC's Sakshi Grover noted that 58% of enterprises in a recent survey flagged AI-enhanced phishing and deepfakes as their top AI-driven threat. Everest Group's Prabhjyot Kaur drew a sharper line: "Shadow IT was a visibility problem. Shadow AI is a trust exploitation problem." The vector isn't an unsanctioned app employees installed — it's a browser extension or embedded SaaS copilot they adopted because their manager told them to.
Gartner's Apeksha Kaushik put it plainly: adversaries are targeting the human layer by manipulating trust and routine behaviors, and blocking one deepfake or impersonation attempt is a tactical win inside a losing strategic position if the surrounding environment keeps rewarding that behavior.
One thing the post-mortem will say: the organization had phishing training, but it wasn't updated to cover AI-branded lures.
The operational lift here isn't another awareness module. It's treating AI tool adoption — every new Copilot integration, every browser extension with OAuth access to corporate mail — as a threat surface that requires the same onboarding scrutiny as a new SaaS vendor.
Operational takeaway: If your acceptable-use policy for AI tools was written before your employees started using them, it's already behind the attack.



