Close Menu
    X (Twitter) LinkedIn
    CapitalAI DailyCapitalAI Daily
    X (Twitter) LinkedIn
    • Markets & Investments
    • Big Tech & AI
    • Fraud & Scams
    • Hacks
    • Banks
    • Crypto
    Sunday, October 5
    CapitalAI DailyCapitalAI Daily
    Home»Fraud & Scams»Microsoft Warns Scammers Using AI To Hide Phishing Attacks That Steal US Corporate Login Credentials

    Microsoft Warns Scammers Using AI To Hide Phishing Attacks That Steal US Corporate Login Credentials

    By Henry KanapiSeptember 27, 20252 Mins Read
    Share
    Twitter LinkedIn

    Microsoft says cybercriminals are now using artificial intelligence to hide their phishing scams, and US businesses are already being targeted.

    The company’s security team spotted and blocked an email campaign that tried to steal login details.

    The team says the attackers likely used an AI model to generate the code, adding complexity that made it harder for legacy defenses to catch.

    It starts with fake emails that look like file-sharing notices. Each message had an attachment that seemed to be a six-page PDF. But the file was actually an SVG, a graphics file that can hold hidden code. When opened, it redirected the victim to a fake security page meant to trick them into typing their username and password.

    “When opened, the SVG file redirected the user to a webpage that prompted them to complete a CAPTCHA for security verification, a common social engineering tactic used to build trust and delay suspicion. Although our visibility for this incident was limited to the initial landing page due to the activity being detected and blocked, the campaign would have very likely presented a fake sign-in page after the CAPTCHA to harvest credentials.”

    The code had giveaway signs of being machine-written. Variables had long, clunky names, and comments were filled with generic business phrases like “Advanced business intelligence data processor.” To anyone peeking inside, it looked like boring business software, not a phishing attack.

    The attackers even hid instructions inside common business words such as “revenue” and “operations.” The script later turned those words back into malicious commands that sent users to the fake site and tracked their browsers.

    Microsoft says the operation was small, but it mainly targeted US companies. The emails were disguised so that the sender and recipient addresses matched, with real targets tucked into the blind copy field. The trick is often used to dodge basic filters.

    A typical phishing campaign is designed to steal usernames and passwords that can be resold on underground markets, used to break into corporate accounts, or even combined with other stolen data for fraud. In many cases, a single compromised login can open the door to sensitive emails, financial systems, or private customer records, which criminals can exploit for direct theft or blackmail.

    Disclaimer: Opinions expressed at CapitalAI Daily are not investment advice. Investors should do their own due diligence before making any decisions involving securities, cryptocurrencies, or digital assets. Your transfers and trades are at your own risk, and any losses you may incur are your responsibility. CapitalAI Daily does not recommend the buying or selling of any assets, nor is CapitalAI Daily an investment advisor. See our Editorial Standards and Terms of Use.

    AI Microsoft phishing Scams
    Previous ArticleJPMorgan Says AI Infrastructure Boom Is ‘No House of Cards,’ Backed by Real Cash Flows and Not Hype
    Next Article Whales Load Up $1.977 Billion in Ethereum (ETH) and Bitcoin (BTC) Amid Crypto Market Dip: Lookonchain

    Read More

    Deutsche Bank Warns AI Trade Flashing ‘Red Light’ Signals, Sees Investors Buying This Asset As Safe-Haven Hedge

    October 5, 2025

    Bank of America: Nvidia AI Boom Hitting a Hidden Bottleneck Most Investors Miss

    October 4, 2025

    Yale Finds No Proof AI Is Killing Jobs, Calls Labor Market Panic Premature

    October 4, 2025

    Google Gemini Traffic Surges 111% in a Year As ChatGPT Loses Ground, According to Similarweb

    October 4, 2025

    Goldman Sachs Pouring $6 Billion Into AI and Tech in 2025, Embraces Tools Like Cognition’s Devin

    October 4, 2025

    More Than Half of Adults Fail To Spot AI Scams, Leaving Accounts and Enterprises at Risk: Yubico Research

    October 4, 2025
    X (Twitter) LinkedIn
    • About
    • Author
    • Editorial Standards
    • Contact Us
    • Privacy Policy
    • Terms of Service
    • Opt-out preferences
    © 2025 CapitalAI Daily. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
    View preferences
    {title} {title} {title}