The article describes real phishing activity seen across multiple enterprise customers, where attackers used well-known AI brands as lures because employees now expect routine AI-related emails. It includes concrete subject lines, a suspicious impersonation domain, and an example of abusing legitimate Zoom infrastructure to make a fraudulent event invite look credible.
How the attack worked
This was a live phishing campaign observed across multiple enterprise customers that used well-known AI brand names as lures rather than attacking AI systems directly. Three distinct pretexts stood out:
- An invoice/payment email referencing Anthropic, with the subject line "RE: Anthropic Engagement approval & payment," pushing finance and accounts payable staff to approve a large payment tied to a supposed contract.
- A fake Google/Gemini Ads invitation encouraging marketing and advertising recipients to connect or join what looked like an official Gemini Ads environment, pointing to the suspicious domain gemini-advertisers[.]com.
- An "OpenAI Partner Summit 2026" invite aimed at executives and business development staff, sent through Zoom's event notification system rather than an OpenAI address, using
noreply-zoomevents[@]zoom.us.
Why it succeeded
The common thread across all three lures is that employees now expect routine email traffic from AI products, and attackers are counting on that familiarity to lower suspicion. Each pretext borrowed the reputation of a trusted brand (Anthropic, Google/Gemini, OpenAI) while relying on the recipient not checking the actual sending infrastructure closely. In the Zoom case, the use of genuine zoom.us URLs made the registration flow look technically legitimate even though the underlying invitation was fraudulent.
What to watch for
- Unexpected payment or contract approval requests that reference a well-known AI vendor by name.
- Workspace or advertising platform invitations where the sender or reply-to domain does not match the brand being referenced.
- Event or partner invitations where links use a legitimate third-party platform (like Zoom) but the framing and content point to a different, unverified brand.
- Any brand name used as context to justify urgency rather than as a verified sender identity.
How to build resistance
- Verify payment and contract requests referencing AI vendors through a separate, trusted channel before processing them, especially in finance and procurement.
- Check sender and reply-to domains carefully, even when the message references a brand your organization actually works with.
- Remember that legitimate infrastructure, such as zoom.us links, does not guarantee a legitimate message; the content and requester still need scrutiny.
- Treat AI-brand emails as a higher-risk category generally, since attackers are actively exploiting the routine nature of AI-related business communication.
Key findings
- The authors observed a "live phishing campaign" using AI brand names as email lures across multiple enterprise customers.
- Specific lures included an invoice/payment pretext referencing Anthropic, a fake Google/Gemini Ads invitation pointing to a suspicious domain, and an OpenAI event invite sent via legitimate Zoom infrastructure.
- The article’s broader SOC finding is that AI-related SOC alerts were a small share overall (0.43%) but grew rapidly (up 685% Feb–Jun 2026), with only a tiny fraction being confirmed real attacks (0.02%).
Who’s being targeted
- Commonly targeted roles: Finance / Accounts Payable, Procurement, Marketing / Advertising, Executives, Business Development / Partnerships, All employees (email security awareness).
- Affected industries: Multiple industries (enterprise environments using AI tools).
- Attack channels: email, website.
- Impersonated: Anthropic (referenced as the business counterparty), Google / Gemini Ads, OpenAI (with Zoom used as the delivery platform).
Red flags to watch for
- Unexpected payment request using a well-known AI brand to create urgency/legitimacy
- Pressure to process a "large payment" tied to a "supposed contract/invoice"
- Brand name is used as context, not a verified sender identity
- Sender/reply-to not associated with Google
- Suspicious lookalike domain used to drive the user to a site
- Unsolicited workspace invitation asking the recipient to connect/join
- Mismatch between the claimed brand (OpenAI) and the sender domain (Zoom)
- Legitimate platform infrastructure used to make a fraudulent invite look real
- Unexpected partner/event invitation with a registration workflow
Frequently asked questions
What made these phishing emails convincing?
They used well-known AI brand names like Anthropic, Google/Gemini, and OpenAI as lures, since employees now expect routine AI-related emails and are less suspicious of them.
How was Zoom infrastructure involved?
One lure impersonated OpenAI in an invite for a 'Partner Summit 2026' but the message originated from Zoom's event notification address, and the registration flow used legitimate zoom.us URLs to lend the fraudulent invite credibility.
Which teams were targeted?
Finance and accounts payable staff were targeted with a fake Anthropic contract/invoice payment request, marketing and advertising staff with a fake Gemini Ads invitation, and executives or business development staff with the fake OpenAI partner summit invite.
Were these confirmed as real attacks?
The source notes that AI-related SOC alerts grew rapidly but only a small fraction were confirmed real attacks, and this phishing campaign was identified as one of the real ones.
Read the video transcript
You’re getting way more AI emails now, right? Attackers know that, and they’re riding those brands to phish you. One real case: subject line says, 'RE: Anthropic Engagement approval & payment.' Inside, it cites a supposed Anthropic contract to rush a large payment. Anthropic isn’t the sender, it’s just the bait. Another: a 'Google/Gemini Ads' invite pushing you to join a workspace at gemini-advertisers.com, or an OpenAI Zoom event that really just abuses zoom.us to look legit. Familiar brand, unfamiliar domain, that’s your aha moment. So when any AI-brand email asks for money or to join something, pause. One action: close the email and verify the request through a trusted channel you open yourself.