Skip to content
Auto-CTI
Back to today
NEW HIGH B3

Detect and disrupt AI-themed attacks with Microsoft Defender

B Microsoft Security Blog ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

Cyberattackers are weaponizing AI platform impersonation (ChatGPT, Copilot, Claude, DeepSeek) at scale (up to 100,000 emails per day) for phishing, credential harvesting, and malvertising, with increasing automation and Teams-based social engineering.

Description

Campaigns impersonate popular AI platforms through phishing emails leveraging urgency, curiosity, and familiarity (e.g., fake security updates, new model announcements, or productivity plugins). A ChatGPT-themed phishing kit harvested credit card data; a Claude-themed campaign used adversary-in-the-middle (AiTM) techniques to steal credentials and access tokens. In Q2 2026, threat actors expanded into Teams-based social engineering with increasingly automated multi-stage attack chains. The tactics remain classical social engineering, but AI-themed lures amplify effectiveness.

Risk score

20
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
15.00
raw before weight
15.00
industry weight
1.10
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00

Path: operational

ESC