AI Incident Database - Incident 1068
Source evidence cited by public records. This page shows where the source is used, its trust tier, and when it was last checked in the seed.
Records using this source
- unknown-threat-actors
entity | 18 Mar 2026 | 70%
unknown-threat-actors - organisation named in the AI Incident Database harm index.
- enterprises-relying-on-microsoft-365-and-identity-services
entity | 21 May 2025 | 70%
enterprises-relying-on-microsoft-365-and-identity-services - organisation named in the AI Incident Database harm index.
- gamma
entity | 21 May 2025 | 70%
gamma - organisation named in the AI Incident Database harm index.
- microsoft-sharepoint-users
entity | 21 May 2025 | 70%
microsoft-sharepoint-users - organisation named in the AI Incident Database harm index.
- organizations-whose-employees-interacted-with-gamma-hosted-phishing-content
entity | 21 May 2025 | 70%
organizations-whose-employees-interacted-with-gamma-hosted-phishing-content - organisation named in the AI Incident Database harm index.
- recipients-of-phishing-emails-sent-from-compromised-accounts
entity | 21 May 2025 | 70%
recipients-of-phishing-emails-sent-from-compromised-accounts - organisation named in the AI Incident Database harm index.
- unknown-aitm-phishing-campaign-actors
entity | 21 May 2025 | 70%
unknown-aitm-phishing-campaign-actors - organisation named in the AI Incident Database harm index.
- unknown-threat-actors-leveraging-gamma
entity | 21 May 2025 | 70%
unknown-threat-actors-leveraging-gamma - organisation named in the AI Incident Database harm index.
- AI-Powered Presentation Tool Gamma Implicated in Multi-Stage Phishing Campaign
event | 21 May 2025 | 82%
Attackers reportedly exploited Gamma, an AI-powered presentation tool, to create convincing presentation pages that hosted links to a spoofed Microsoft SharePoint login portal. The phishing flow allegedly used compromised email accounts, Cloudflare Turnstile for bot evasion, and adversary-in-the-middle (AiTM) tactics to validate credentials in real time and capture session cookies. The campaign aimed to bypass MFA and compromise accounts.