Fake AI Chatbot Ad Portals Deployed to Steal Credentials and MFA Codes
Researchers uncover human-operated phishing platform mimicking advertising products for major AI chatbots

Key Takeaways
- A human-operated phishing platform impersonates AI chatbot advertising products to steal credentials and MFA codes.
- Fake portals mimic legitimate interfaces for ChatGPT, Gemini, Claude, Perplexity, Meta Muse, and Manus.
- The campaign offers features like campaign optimization and spend audits as bait to lure victims.
Related Security News

China-Aligned TA419 Conducts AitM Phishing Against U.S. AI Policy Experts
A China-nexus threat actor identified as TA419 (also tracked as FamousSparrow) has been conducting credential phishing campaigns targeting U.S. AI policy experts, think tank researchers, university academics, and legal sector personnel. The campaigns use Microsoft Account-to-Account (AitM) phishing infrastructure to bypass multi-factor authentication and harvest credentials. Threat actors impersonated prominent economists, AI policymakers, and a prominent Anthropic employee to increase the effectiveness of their lures. The activity has been ongoing through at least October 2026. Microsoft recommends enabling phishing-resistant MFA and implementing conditional access policies as primary mitigations.




