Historical intelligence backfill. This assessment covers reporting originally published on 2026-06-08 and was added to the RWP archive on 2026-09-07.

Daily Top · IT

ChatGPT Plus billing mail was a carder page — AI brands are the new Microsoft logo

Microsoft 8 June 2026 — ChatGPT, Copilot, Claude, DeepSeek impersonation. Not a compromise of those services. 4,500 ChatGPT-themed mails to South Africa on 5 May; Claude AiTM 20–22 April across 2,000 orgs.

RWP Ventures · 2026-09-07 · event 2026-05-05 · 1 min read · priority 7.6

Bottom line up front

CONFIRMED Microsoft Threat Intelligence, 8 June 2026 — campaigns impersonating ChatGPT, Microsoft Copilot, DeepSeek, and Anthropic Claude. Microsoft states these are not compromises of the named services. ChatGPT-themed 5 May: sender display "ChatGPT", Plus payment-update lure, 4,500 mails to South Africa; same infra up to ~100,000 in a day to CH/AT/ZA; landing pages collected name, address, then PAN. Claude-themed 20–22 April: 2,000+ orgs US/UK/India, ToS-violation lure, AiTM for Microsoft tokens. DeepSeek: fake GitHub org within 45 minutes of a V4 preview, stolen branding + benchmarks for SEO. Check Point Q2 later put ChatGPT in the top-10 impersonated brands (Microsoft still #1 at 23 percent). Credential/card theft and malware: CONFIRMED as campaign goals. OT: none.

Historical backfill of 8 June 2026 reporting; added 7 September 2026.

What happened

The AI boom gave criminals a second set of logos users will click without reading the From: line.

Why it mattered

Users who would catch a fake Microsoft 365 mail will still click "your Claude account is in violation." SOC rules that only watch Microsoft/Google brands miss it.

Who / what was affected

Consumers and orgs in the named geos. Token theft is the enterprise path.

Technical context

Lookalike domains, CRM/shortener hops, AiTM kits, malvertising, SEO GitHub. Storm-3075 named in some recaps as an IAB using AI lures — treat as REPORTED overlap.

Exploitation / threat status at the time

CONFIRMED Microsoft campaign telemetry.

REPORTED DeepSeek 45-minute GitHub spoof as Microsoft/Paubox describe it.

What defenders should have done

  1. Brand-impersonation detections for OpenAI/Anthropic/DeepSeek.
  2. User training that includes AI billing mail.
  3. AiTM defenses already in the Tycoon2FA playbook.

RWP assessment

Confidence: High. This is lure-as-a-service, not "AI malware."

Defensive actions

  1. Expand impersonation intel beyond Microsoft/Google/Apple.
  2. Block newly registered AI-brand domains.
  3. Keep Q2 email landscape post as the volume layer.

Sources

  1. Microsoft Security — AI brands as bait
  2. Paubox — Attackers impersonate ChatGPT, Claude, and DeepSeek
  3. Check Point Q2 2026 Brand Phishing Report (ChatGPT enters top 10) — Check Point Q2 2026 Brand Phishing Report (ChatGPT enters top 10)