---
title: ChatGPT, Claude, and DeepSeek exploited in new wave of phishing attacks
description: Microsoft has uncovered a wave of phishing campaigns impersonating ChatGPT, Claude, and DeepSeek to steal card details and account credentials. Read now!
slug: chatgpt-claude-deepseek-bi-loi-dung-trong-lan-song-phishing-moi
type: news
locale: en-US
author: Martha Tran
date: "2026-09-14T09:33:35.892Z"
lastmod: "2026-09-14T09:33:35.799Z"
thumbnail: "https://static.vncdn.vn/vnetwork.vn/pub/websites/uploads/1/94/chatgpt-claude-deepseek-bi-loi-dung-trong-lan-song-phishing-moi-thumb.png"
sabo: "Artificial intelligence platforms such as ChatGPT, Claude, and DeepSeek have become a favorite target for cybercriminals to impersonate. According to a recent report from Microsoft Threat Intelligence published in June 2026, a wave of phishing campaigns has exploited the popularity of these AI brands to deceive users. From fake emails requesting payment updates, to fake login pages that steal authentication tokens, to fake GitHub repositories spreading malware, every method targets the same weak point: users’ trust in the technology brands leading the current trend. The article below analyzes three representative campaigns in detail and outlines effective ways to defend against them."
---

<h2><strong>1. How are ChatGPT, Claude, and DeepSeek being exploited in this wave of phishing attacks?</strong></h2><p>Artificial intelligence platforms such as ChatGPT, Claude, and DeepSeek have become favorite targets for impersonation in&nbsp;<a href="https://www.vnetwork.vn/en-US/news/phishing-la-gi-3-hinh-thuc-tan-cong-phishing/">phishing</a> campaigns. In this latest wave, the impersonated entities are no longer the familiar banks or e-commerce platforms, but the AI brands making the biggest waves today: OpenAI’s ChatGPT, Anthropic’s Claude, and DeepSeek.</p><p>It should be made clear that this is not a case of the AI platforms themselves being breached. OpenAI, Anthropic, and DeepSeek have not had their systems taken over by hackers. Attackers simply build interfaces, domains, and logos that look authentic enough to exploit users’ trust, a technique commonly known as brand impersonation phishing.</p><p>It is not hard to see why AI brands make such attractive bait. The media buzz surrounding AI means any notification related to ChatGPT, Claude, or DeepSeek easily grabs attention, while the fear of missing out on new technology experiences makes users act more hastily than usual. In fact, the gap between how quickly a technology spreads and how quickly users’ security awareness catches up is always the first place cybercriminals exploit, and AI currently sits right in that gap. This is not an isolated phenomenon either, according to the&nbsp;<a href="https://apwg.org/trendsreports">Phishing Activity Trends report from the Anti-Phishing Working Group (APWG)</a>, a nonprofit organization that tracks global phishing trends, the number of brands targeted in phishing campaigns keeps rising steadily each quarter, showing that cybercriminals are increasingly diversifying their impersonation targets rather than focusing on a fixed set of brands.</p><figure class="image"><img style="aspect-ratio:1672/941;" src="https://static.vncdn.vn/vnetwork.vn/pub/websites/uploads/1/94/vi-sao-chatgpt-claude-va-deepseek-bi-loi-dung-trong-lan-song-tan-cong-phishing.png" alt="vi-sao-chatgpt-claude-va-deepseek-bi-loi-dung-trong-lan-song-tan-cong-phishing.png" width="1672" height="941"><figcaption><i>Why are ChatGPT, Claude, and DeepSeek being exploited in this wave of phishing attacks?</i></figcaption></figure><h2><strong>2. Impersonating ChatGPT to steal credit card information</strong></h2><p>The first campaign, recorded by Microsoft in May 2026, targeted ChatGPT Plus users. Tens of thousands of emails were sent claiming a payment method issue and asking users to update their card information to avoid service interruption. The targets were concentrated in South Africa, Switzerland, and Austria.</p><p>Technically, the email leads users through a multi layer redirect chain that passes through legitimate domains that have been hijacked or abused to evade traditional email filters. Before reaching the actual data harvesting page, users are also asked to pass a fake CAPTCHA step. This small detail is exactly what convinces victims the site is safe enough to enter personal information.</p><p>In short, this campaign has three easily identifiable traits:</p><ul><li>The email content always revolves around a payment error or an urgent request to update card details</li><li>The link passes through multiple intermediary domains before reaching the data harvesting page</li><li>A fake CAPTCHA step creates a false sense of security before the victim enters their name, address, card number, and CVV code</li></ul><p>What stands out in this campaign is that the attacker did not need to breach OpenAI’s systems at all. Building an interface that looks convincing enough was sufficient to fool most victims. This shows that modern phishing succeeds more through psychology than pure technical skill, and this type of domain impersonation technique is also known as email&nbsp;<a href="https://www.vnetwork.vn/en-US/news/spoofing-la-gi/">spoofing</a>, a common tactic in large scale fraud campaigns.</p><figure class="image"><img style="aspect-ratio:1672/941;" src="https://static.vncdn.vn/vnetwork.vn/pub/websites/uploads/1/94/email-gia-mao-chatgpt-de-danh-cap-thong-tin-the-tin-dung.png" alt="email-gia-mao-chatgpt-de-danh-cap-thong-tin-the-tin-dung.png" width="1672" height="941"><figcaption><i>A fake ChatGPT email used to steal credit card information</i></figcaption></figure><h2><strong>3. Fake Claude campaign targets authentication tokens and enterprise accounts</strong></h2><p>Unlike the ChatGPT impersonation campaign, which targeted individual users, the Claude impersonation campaign discovered by Microsoft in April 2026 targeted enterprise accounts directly. The email poses as Anthropic, citing a usage policy violation, and includes a PDF attachment designed to create a sense of urgency that pushes the recipient to act immediately.</p><p>The attack chain for this campaign unfolds as follows:</p><ul><li>An email impersonating Anthropic warns of a policy violation and includes a PDF attachment</li><li>The PDF leads to a fake CAPTCHA verification step</li><li>The CAPTCHA step then leads to a fake “Account Appeal Notice” page that mimics the Claude interface</li><li>The fake page uses an Adversary in the Middle (AiTM) technique to steal authentication tokens in real time</li></ul><p>Because this token is what keeps an authenticated session alive, the attacker can bypass multi factor authentication (MFA) entirely without ever knowing the original password. The industries targeted were mainly IT and finance in the United States, the United Kingdom, and India.</p><p>According to the&nbsp;<a href="https://www.verizon.com/business/resources/reports/dbir/">Verizon Data Breach Investigations Report (DBIR)</a>, a well respected annual report on global data breaches, session token theft techniques are becoming increasingly common precisely because they can bypass the extra authentication layers many organizations still consider strong enough defenses. The fact that AiTM directly targets the IT and finance sectors, which are generally seen as more security aware than average, shows that individual vigilance alone is not enough without an additional technical layer of protection at the infrastructure level. This is also why campaigns of this kind are often classified as&nbsp;<a href="https://www.vnetwork.vn/en-US/news/spear-phishing-la-gi/">spear phishing</a>, given how specifically targeted they are.</p><figure class="image"><img style="aspect-ratio:1672/941;" src="https://static.vncdn.vn/vnetwork.vn/pub/websites/uploads/1/94/gia-mao-claude-nham-vao-tai-khoan-doanh-nghiep.png" alt="gia-mao-claude-nham-vao-tai-khoan-doanh-nghiep.png" width="1672" height="941"><figcaption><i>Fake Claude campaign targets enterprise accounts</i></figcaption></figure><h2><strong>4. Impersonating DeepSeek V4 with malware distributed via GitHub</strong></h2><p>The third campaign happened right as DeepSeek announced its V4 release. Within just 45 minutes of the launch announcement, attackers had already set up a fake GitHub repository, complete with the official logo and even real benchmark figures to create an air of absolute credibility.</p><p>The attackers did not stop at building a fake page. They also used search engine optimization tactics to push the fake repository to a high ranking on Google, Bing, and even AI powered search tools. Users who trusted the site and downloaded what looked like the official installer were, in fact, installing&nbsp;<a href="https://www.vnetwork.vn/en-US/news/malware-la-gi/">malware</a> called Vidar Stealer, which is designed to steal login credentials, session cookies, and other sensitive data stored in the browser.</p><p>Notably, this is not an isolated campaign but part of a wider rotating ecosystem of AI impersonation, including:</p><ul><li>Fake repositories and websites impersonating the newly launched DeepSeek V4</li><li>Tools posing as ChatGPT and Claude Code</li><li>Fake download pages for Gemini and Manus AI</li></ul><p>All of these share the same malware distribution infrastructure. The fact that a campaign can be stood up in under an hour shows that manual defenses, which only react after an incident is detected, are almost always a step behind the speed of cybercriminals, making it essential for organizations to shift toward proactive rather than reactive detection.</p><figure class="image"><img style="aspect-ratio:1672/941;" src="https://static.vncdn.vn/vnetwork.vn/pub/websites/uploads/1/94/mao-danh-deepseek-v4-va-ma-doc-phat-tan-qua-github.png" alt="mao-danh-deepseek-v4-va-ma-doc-phat-tan-qua-github.png" width="1672" height="941"><figcaption><i>Impersonating DeepSeek V4 with malware distributed via GitHub</i></figcaption></figure><h2><strong>5. Common traits and warning signs of AI impersonation campaigns</strong></h2><p>Although they targeted three different brands with different goals, all three campaigns share several recurring technical traits that can help users spot them early.</p><figure class="table" style="width:100%;"><table class="ck-table-resized"><colgroup><col style="width:17.21%;"><col style="width:28.3%;"><col style="width:27.31%;"><col style="width:27.18%;"></colgroup><tbody><tr><td><strong>Factor</strong></td><td><strong>ChatGPT</strong></td><td><strong>Claude</strong></td><td><strong>DeepSeek</strong></td></tr><tr><td>Bait type</td><td>Payment email</td><td>Policy violation warning email</td><td>Fake GitHub repository</td></tr><tr><td>Main technique</td><td>Redirect chain, fake CAPTCHA</td><td>AiTM token theft</td><td>Information stealing malware</td></tr><tr><td>Stolen target</td><td>Credit card information</td><td>Account authentication tokens</td><td>Login credentials, cookies</td></tr><tr><td>Target audience</td><td>Individual users</td><td>IT and finance enterprises</td><td>Developers, technical users</td></tr></tbody></table></figure><p>Looking at the comparison table above, the four most noticeable common signs include:</p><ul><li>Creating a false sense of urgency to pressure victims into acting immediately</li><li>Using multi layer redirect chains through legitimate domains to evade email filters</li><li>Inserting a fake CAPTCHA step to increase the sense of safety before collecting information</li><li>Luring users into downloading software or entering information from unofficial sources</li></ul><p>According to data published by APWG and Verizon DBIR, the average time it takes a user to click a phishing link is significantly shorter than the time it takes them to recognize and report the incident. This shows that the core problem is not that users are unaware of the warning signs, but that the few seconds they take to decide are far too fast compared to the time needed to notice something is wrong, a challenge that is more about designing better warning mechanisms than simply running awareness training.</p><h2><strong>6. How do AI impersonation phishing campaigns affect businesses?</strong></h2><p>For businesses, the consequences of AI impersonation campaigns do not stop at a single employee being tricked into entering the wrong information. They can spread into several layers of damage.</p><h3><strong>6.1. Direct financial losses</strong></h3><p>According to the&nbsp;<a href="https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf">FBI IC3’s Internet Crime Report 2025</a>, losses from business email compromise (BEC) fraud surpassed 3 billion USD in 2025, continuing to rise from the previous year. Notably, this was also the first year the report recorded a separate category of AI related complaints, with losses reaching hundreds of millions of USD, showing that fraud campaigns involving AI, including brand impersonation as analyzed above, are becoming a significant financial loss category rather than a theoretical risk.</p><h3><strong>6.2. Operational disruption and loss of system access</strong></h3><p>When an enterprise account is hijacked through the AiTM technique described in the Claude case, employees can immediately lose access to the AI tool they rely on for daily work. For teams that have deeply integrated AI into their workflow, even a few hours of disruption is enough to affect project timelines and overall productivity.</p><h3><strong>6.3. Cascading risk from a single compromised account</strong></h3><p>A stolen authentication token does not stop at the compromised AI account. If that account is shared with or linked to other internal systems, the attacker can use it as a stepping stone to move deeper into the enterprise infrastructure, turning what seemed like a minor incident into a much larger intrusion.</p><h3><strong>6.4. Reputational risk and legal obligations</strong></h3><p>If customer data is exposed in the process, the business also faces data breach notification obligations under the&nbsp;<a href="https://www.vnetwork.vn/en-US/news/luat-so-91-2025-qh15/">Personal Data Protection Law</a> along with related regulations under the&nbsp;<a href="https://www.vnetwork.vn/en-US/news/nghi-dinh-53-2022-nd-cp/">Cybersecurity Law</a>, on top of the risk of losing customer and partner trust. In practice, the biggest damage is usually not the money lost at the moment of the incident, but the operational downtime and the cost of rebuilding trust afterward, costs that are hard to measure immediately but last far longer.</p><figure class="image"><img style="aspect-ratio:1672/941;" src="https://static.vncdn.vn/vnetwork.vn/pub/websites/uploads/1/94/tac-dong-cua-chien-dich-phishing-gia-mao-ai-den-doanh-nghiep.png" alt="tac-dong-cua-chien-dich-phishing-gia-mao-ai-den-doanh-nghiep.png" width="1672" height="941"><figcaption><i>The impact of AI impersonation phishing campaigns on businesses</i></figcaption></figure><h2><strong>7. How to defend against AI brand impersonation phishing attacks</strong></h2><p>Effective defense requires combining individual level actions with technical measures at the enterprise level.</p><h3><strong>7.1. Always type the URL yourself, never click links in unfamiliar emails</strong></h3><p>Instead of clicking directly on a link sent to them, users should open their browser and type in the official address of ChatGPT, Claude, or DeepSeek themselves to check account notifications. This simple habit completely eliminates the risk of being led through a malicious redirect chain.</p><h3><strong>7.2. Never enter payment information or passwords through a link sent to you</strong></h3><p>No reputable AI platform will ask you to update your credit card details or confirm your password through a link in an email. If you receive such a request, the safest approach is to ignore the link and log in directly through the official homepage to check your account.</p><h3><strong>7.3. Enable two factor authentication and verify directly for any urgent request</strong></h3><p>Two factor authentication (2FA) helps reduce risk even if a password has been exposed, though it is not fully immune to AiTM techniques. When you receive an urgent warning such as an account lock or a policy violation, verify it directly through an official support channel instead of immediately following the instructions in the email.</p><h3><strong>7.4. Only download AI tools and software from official homepages or channels</strong></h3><p>Avoid downloading AI tools from advertising links, social media posts of unclear origin, or GitHub repositories that do not belong to the official development organization, even when the interface and benchmark figures look credible.</p><h3><strong>7.5. Businesses should implement SPF, DKIM, and DMARC email authentication</strong></h3><p>The three protocols&nbsp;<a href="https://www.vnetwork.vn/en-US/news/spf-la-gi/">SPF</a>,&nbsp;<a href="https://www.vnetwork.vn/en-US/news/dkim-la-gi/">DKIM</a>, and&nbsp;<a href="https://www.vnetwork.vn/en-US/news/dmarc-bao-ve-Email-chong-tan-cong-co-chu-dich/">DMARC</a> help verify that an outgoing email truly originates from a legitimate domain, blocking most domain spoofing emails before they ever reach a recipient’s inbox. This is also the foundational technical step that any business should implement first.</p><h3><strong>7.6. Businesses need proactive monitoring and regular awareness training</strong></h3><p>Beyond technical controls, businesses need to maintain continuous anomaly monitoring across email flows and run regular cybersecurity awareness training for employees, with particular attention to new scam tactics tied to popular AI brands. The most effective approach is not to generically tell employees to “be more careful,” but to minimize the number of situations where an employee has to make a correct or incorrect judgment call in just a few seconds, by pushing technical filtering earlier in the email infrastructure layer.</p><h2><strong>8. EG-Platform - A proactive line of defense against AI brand impersonation phishing</strong></h2><p>As AI brand impersonation phishing campaigns grow more sophisticated and harder to spot with the naked eye or traditional spam filters, businesses need a proactive defense layer at the email infrastructure level rather than relying solely on individual employee vigilance.</p><p>VNETWORK’s&nbsp;<a href="https://eg.vnetwork.vn/en-US/">EG-Platform</a> is an email security platform that applies AI and machine learning to provide comprehensive protection for both incoming and outgoing email. The solution helps prevent phishing, social engineering, and targeted email attacks. Notably, EG-Platform is an email security platform that fully meets the&nbsp;<a href="https://www.vnetwork.vn/en-US/news/bo-quy-tac-bao-mat-Email-toan-cau-cua-itu/">ITU-T X.1236</a> standard set by the International Telecommunication Union.</p><p>EG-Platform operates on a three layer protection model:</p><ul><li><strong>SpamGUARD: </strong>uses machine learning and Bayesian filtering to score the risk of each email while checking SPF, DKIM, and DMARC authentication standards to detect domain spoofing, helping to filter and block spam, phishing emails, and malware laden emails early</li><li><strong>ReceiveGUARD: </strong>protects incoming email by inspecting content, attachments, and URLs in a sandbox environment, analyzing IPs, headers, and unusual behavior to identify fake emails, disabling suspicious links before users can access them</li><li><strong>SendGUARD: </strong>controls outgoing email, preventing compromised internal accounts from spreading phishing or leaking data, with filtering by IP, country, and sensitive content to help minimize the spread of an incident</li></ul><figure class="image"><img style="aspect-ratio:1910/1073;" src="https://static.vncdn.vn/vnetwork.vn/pub/websites/uploads/1/94/mo-hinh-3-bo-loc-cua-eg-platform-en.png" alt="mo-hinh-3-bo-loc-cua-eg-platform-en.png" width="1910" height="1073"><figcaption><i>EG-Platform’s three layer filtering model</i></figcaption></figure><p>Thanks to this three layer model, EG-Platform can detect sophisticated phishing campaigns early, before they cause damage, including redirect chains and fake login pages like those analyzed in the ChatGPT and Claude impersonation campaigns above, while also meeting international email security standards, making it suitable for businesses with high requirements for information security and regulatory compliance.</p><h2><strong>9. Conclusion</strong></h2><p>AI brands will almost certainly remain a favorite lure for cybercriminals going forward. This is not a passing trend but an inevitable consequence of AI’s adoption speed far outpacing most users’ security awareness. The three ChatGPT, Claude, and DeepSeek impersonation campaigns analyzed in this article are just the representative examples that have been detected, and many similar variants targeting other AI brands are likely still quietly underway.</p><p>For businesses, proactively equipping a strong enough email security layer at the infrastructure level is a necessary step so that data safety does not depend on the split second vigilance of individual employees. Contact the VNETWORK team today for advice on an EG-Platform solution suited to your business’s scale and email security needs.</p><h2><strong>FAQ - Frequently asked questions</strong></h2><h3><strong>1. How can you tell a genuine email from ChatGPT, Claude, or DeepSeek apart from a fake one?</strong></h3><p>Official emails from these AI platforms never ask you to update card details or confirm a password through a link in the email. The safest approach is to carefully check the sender’s domain and always log in directly through the official homepage rather than clicking the link sent to you.</p><h3><strong>2. What should you do if you have already clicked a fake AI phishing link?</strong></h3><p>Change the password immediately on the affected account and on any other account that shares that password, enable two factor authentication if you have not already, and check your login history and linked devices for signs of unusual access.</p><h3><strong>3. How is AiTM different from ordinary password stealing phishing?</strong></h3><p>Traditional phishing only steals passwords, whereas the Adversary in the Middle technique steals the authenticated session token directly. This lets the attacker keep access even when the account has multi factor authentication enabled, because the token functions as a valid, already logged in session.</p><h3><strong>4. Which measure should businesses prioritize first to defend against this type of attack?</strong></h3><p>The foundational step to implement first is email authentication through the SPF, DKIM, and DMARC protocols, since this technical layer blocks most domain spoofing emails before they ever reach employees.</p><h3><strong>5. How does EG-Platform protect businesses from AI impersonation phishing?</strong></h3><p>EG-Platform combines three layers, SpamGUARD, ReceiveGUARD, and SendGUARD, applying AI and machine learning to score risk and check domain authentication standards, while sandboxing analyzes URLs and attachments before an email ever reaches the user, helping to detect sophisticated AI brand impersonation phishing campaigns early.</p>
