Security1 publisher2 min readPublished
A fake ChatGPT Plus billing alert pushed up to 100,000 emails in a single day
Microsoft Threat Intelligence documents ChatGPT, Copilot, DeepSeek and Claude lures spanning phishing kits, adversary-in-the-middle credential theft, malvertising and fake GitHub installers. A broker it tracks as Storm-3075 resells the access it wins.
The Watch · Security desk

What happened
- Microsoft Threat Intelligence published research on a growing set of campaigns impersonating AI platforms, naming ChatGPT, Microsoft Copilot, DeepSeek and Claude as the borrowed brands.
- A separate Claude-themed campaign harvested credentials and access tokens using adversary-in-the-middle techniques, according to Microsoft's research team.
- Microsoft says an initial access broker it tracks as Storm-3075 used AI-themed malvertising to distribute payloads for multiple downstream actors.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Mail-flow inspection covers half of what Microsoft documented, because an ad click in a browser and a download from a code host never enter the message path Safe Links and Safe Attachments watch.
- precedent Once a broker packages the AI-brand lure and sells the resulting access, the theme survives the product cycle that inspired it and shows up under actors with unrelated objectives.
- cost The remediation Microsoft describes is configuration state: detonation happens only where policies are already turned on, so the work lands on whoever owns the tenant's policy baseline.
- decision Awareness content that teaches staff to distrust AI-vendor mail has to reckon with Copilot sitting in the impersonated set, which rules out treating the brand itself as the signal.
Half of the four named campaigns never touch mail flow. The fake AI Windows plugin was advertised through malvertising and delivered the Vidar stealer [6]. The fraudulent DeepSeek installers were distributed through GitHub [7]. Microsoft's own description of Safe Links puts its coverage at URL scanning and detonation during mail flow, plus time-of-click verification when a user clicks a link in email, Microsoft Teams or supported Microsoft 365 apps [10]. A user who clicks a search ad in a browser, or pulls a binary from a code host, is outside all of that [14].
The payoffs also split. The ChatGPT-themed kit was built to harvest credit card data [4]. The other three end in identity material or code on the endpoint: the Claude-themed campaign harvested credentials and access tokens through adversary-in-the-middle [5], the plugin ad dropped Vidar [6], and the DeepSeek installers were executables [7]. Three of the four named campaigns produce credentials and access tokens, not card numbers [15].
The 100,000 figure is Microsoft's, and it is bounded: up to 100,000 emails in one day, in a campaign that asked users to update ChatGPT Plus payment information and took personal and credit card data [2]. Microsoft's post, dated September 10, 2026, gives no campaign duration, no victim count, and no domains or hashes in the text [17]. It states plainly that none of this involves a compromise of the AI services being referenced [3]. Nothing here requires action inside an OpenAI, Anthropic or DeepSeek account.
The broker model persists after any one campaign ends. Microsoft says an initial access broker it tracks as Storm-3075 used AI-themed malvertising to distribute payloads for multiple downstream actors [8]. The lure itself becomes inventory that Storm-3075 resells. The crew building the funnel is not the crew using the access, and the campaigns Microsoft describes layer multi-stage redirection chains and disposable infrastructure, so the domains and the payloads rotate independently [9].
For defenders the controls Microsoft points at are already in the tenant. Anti-phishing policies cover user and domain impersonation, first-contact messages and mailbox intelligence signals [12]. Safe Attachments detonates attachments in a virtual environment before delivery, and Microsoft's wording is conditional: when policies are configured [11]. The bill is a configuration review, plus the ad-click path that mail controls do not see.
Filtering by brand name is the reflex to resist. Three of the four impersonated brands are third-party services; the fourth is Microsoft Copilot [16]. A rule that treats AI-vendor notification mail as inherently suspect would also flag mail the tenant generates for itself [1].
What to watch
- Whether Microsoft publishes domains, hashes or a campaign date range for the Storm-3075 AI-themed malvertising, which the September 10 post does not include.
- Whether GitHub removes the fake DeepSeek installer repositories and the distribution moves to another code host.
- Whether the Claude-themed AiTM tokens turn up being replayed against the AI services themselves rather than corporate mail.