AI-Powered Presentation Tool Gamma Implicated in Multi-Stage Phishing Campaign

April 15, 2025

Attackers exploited the AI-powered presentation tool, Gamma, to create deceptive slides that contained links to a spoofed Microsoft SharePoint login page. The phishing strategy utilized compromised email accounts, Cloudflare Turnstile for bot mitigation, and adversary-in-the-middle (AiTM) techniques to authenticate credentials in real time and capture session cookies. This campaign aimed at bypassing Multi-Factor Authentication (MFA) and compromising user accounts.

Harm prevention is crucial in ensuring safe and secure AI practices. This incident highlights the need for robust governance and proper management of AI tools like Gamma through HISPI Project Cerebellum TAIM (Measure or Manage function). JOIN US to learn more about responsible AI governance and contribute to the advancement of trustworthy AI.

Matched TAIM controls

Suggested mapping from embedding similarity (not a formal assessment). Browse all TAIM controls

Alleged deployer
unknown-threat-actors, unknown-threat-actors-leveraging-gamma, unknown-aitm-phishing-campaign-actors
Alleged developer
gamma
Alleged harmed parties
gamma, microsoft, microsoft-sharepoint-users, recipients-of-phishing-emails-sent-from-compromised-accounts, enterprises-relying-on-microsoft-365-and-identity-services, organizations-whose-employees-interacted-with-gamma-hosted-phishing-content

Source

Data from the AI Incident Database (AIID). Cite this incident: https://incidentdatabase.ai/cite/1068

Data source

Incident data is from the AI Incident Database (AIID).

When citing the database as a whole, please use:

McGregor, S. (2021) Preventing Repeated Real World AI Failures by Cataloging Incidents: The AI Incident Database. In Proceedings of the Thirty-Third Annual Conference on Innovative Applications of Artificial Intelligence (IAAI-21). Virtual Conference.

Pre-print on arXiv · Database snapshots & citation guide

We use weekly snapshots of the AIID for stable reference. For the official suggested citation of a specific incident, use the “Cite this incident” link on each incident page.