READ. SCROLL. LISTEN.

Unbiased headlines. Facts, not spin.

Every story is an unbiased news briefing written from 114+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Fake ChatGPT, Gemini and Claude Ad Portals Are Stealing Login Credentials and MFA Codes, Island Researchers Find

Fake ChatGPT, Gemini and Claude Ad Portals Are Stealing Login Credentials and MFA Codes, Island Researchers Find
Browser security firm Island says a human-operated phishing operation has been running fake AI advertising portals since mid-September, using browser-in-the-browser tricks to steal ad account logins and MFA codes in real time. A separate, unrelated campaign tracked by Proofpoint has Chinese state-linked hackers impersonating real AI policy experts to phish U.S. think tank researchers since July. Different targets, same basic playbook: ride the AI hype, fake the browser window, steal the login.

Fake 'AI Ad Manager' Sites Are Hijacking Logins in Real Time

A phishing operation is impersonating advertising products from ChatGPT, Google Gemini, Anthropic Claude, Perplexity, Meta Muse, and Manus to steal ad account credentials and multi-factor authentication codes, according to a report from browser security firm Island shared with The Hacker News.

Researchers Oleg Zaytsev and Ofek Ronen say every fake product is built around one button: Connect. Click it, and the page opens a browser window drawn inside your real browser. The fake address bar shows accounts.google.com or a legitimate-looking Okta tenant. Your actual browser never leaves the phishing domain.

The browser-in-the-browser technique was first documented by security researcher mr.d0x in March 2022 and previously used against Steam accounts, according to Bleeping Computer. It works because the fake pop-up looks exactly like a real login window, complete with the URL users expect to see.

How the Scam Runs

One of the sites identified, museads.ai, appeared on September 16, 2026, roughly a week after Meta launched its Muse AI agent, Island's researchers found. It billed itself as 'Your AI ads manager for paid media workflows,' promising to connect advertisers' Google, Meta, TikTok, and Okta accounts.

Every brand gets a tailored pitch, the researchers said. ChatGPT promises a Monday Google Ads brief. Gemini dangles manager-account and linked-client support. Claude gets its own advertising portal. Perplexity offers campaign planning and spend audits. Manus promises a private Meta integration.

Once a victim hits Connect, the platform logs every password attempt, fingerprints the device, and sends that data to the attacker's endpoint over a Socket.IO connection, according to Island. A human operator then decides in real time which MFA challenge to throw at the victim next: an SMS code, an authenticator prompt, an Okta push request, or a QR code. Operators can reject a submitted code and hold the victim in a waiting screen while they try to log in with the stolen password themselves, Bleeping Computer reported.

The targets are deliberate. Island says the campaign goes after agency staff, media buyers, and account administrators who manage spend across multiple client accounts, people whose credentials can unlock large ad budgets that attackers either burn on fraudulent campaigns or resell to other criminals.

Part of a Larger Operation

Island traced the ad-portal sites to a broader phishing infrastructure that also runs fake Google Ads refund claims, payment confirmation pages, and recruitment scams. All of it shares a Next.js and Socket.IO software stack, common API endpoints, and a mix of Vercel frontends with Railway or Render backends, the researchers found.

The operation's history goes back further than the recent AI branding. Misconfigured public GitHub repositories exposed older source code, letting researchers trace the activity back to March 2026, according to Bleeping Computer. A Telegram channel used to control the campaign had logged hundreds of victim submissions, though Bleeping Computer noted that figure doesn't necessarily mean hundreds of accounts were fully drained. The number of submissions that resulted in a completed account takeover versus a rejected or abandoned login attempt remains unclear.

A Separate Threat: Chinese Hackers Impersonating AI Policy Experts

A different and unrelated campaign, tracked by Proofpoint and reported by IT Pro on October 2, shows Chinese state-linked hackers going after a different target entirely: people who shape AI policy, not people who buy ads.

A group Proofpoint tracks as TA419 has, since July, impersonated real individuals including Lynne Parker, a former member of the White House Office of Science and Technology Policy leadership team, economist Heidi Crebo-Rediker, and a senior Anthropic employee, according to IT Pro. The lures targeted AI policy analysts at U.S. think tanks, universities, and legal firms, in one case inviting a recipient to join an 'AI Policy Advisory Committee' and in another seeking feedback on the military integration of Claude.

Victims who engaged were funneled through a multi-stage redirect chain into an Adversary-in-the-Middle credential phishing attack using a customized version of an open-source BitB tool called Frameless BitB, IT Pro reported. That version fakes a Microsoft login pop-up over a page styled to look like a OneDrive document-sharing site, then relays the login to real Microsoft infrastructure, harvesting Microsoft 365 passwords, MFA codes, and session cookies in the process.

Both campaigns use the browser-in-the-browser spoofing technique, but come from different researchers, different infrastructure, and different target lists. Island's findings concern commercial ad-fraud operators going after ad account managers. Proofpoint's findings concern a China-linked espionage group going after policy researchers.

What Actually Stops This

Island notes there's no patch for a social engineering attack like this. The defense is procedural: verify sign-in URLs manually rather than trusting a pop-up's address bar, and use hardware-based or passkey-style MFA, which binds authentication to the real website's origin and can't be tricked by a fake browser window the way SMS or push-based codes can.

No law enforcement action against either campaign has been announced in these reports, and neither Island nor Proofpoint named the operators behind the infrastructure. For agency staff and ad account managers, the practical takeaway is straightforward: if an email invites you to connect your ad account to a shiny new AI tool you've never heard your platform rep mention, that invitation is the attack.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
The Hacker NewsFake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes
unknown
Bleeping ComputerFake ChatGPT, Gemini Sites steal advertising accounts, MFA codes
unknown
InfoSec TodayFake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes
unknown
GitHub[HackerNews] Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes · Issue #74777 · SecOpsNews/news
unknown
IT ProChinese hackers impersonate leading AI figures to harvest credentials
unknown
prsol.ccFake ChatGPT, Gemini Sites steal advertising accounts, MFA codes
unknown
Radar (OffSeq)Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes