AI-Powered Presentation Tool Gamma Implicated in Multi-Stage Phishing Campaign
Attackers reportedly exploited Gamma, an AI-powered presentation tool, to create convincing presentation pages that hosted links to a spoofed Microsoft SharePoint login portal. The phishing flow allegedly used compromised email accounts, Cloudflare Turnstile for bot evasion, and adversary-in-the-middle (AiTM) tactics to validate credentials in real time and capture session cookies. The campaign aimed to bypass MFA and compromise accounts.
- Date it happened
- 2025-04-15
- Organisation involved
- Unknown threat actors, Unknown threat actors leveraging Gamma, Unknown AiTM phishing campaign actors
- Product, system or model
- Gamma, Cloudflare Turnstile, Microsoft SharePoint, AiTM phishing frameworks, Email account holders
This incident was imported from AI Incident Database and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.
This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.