Fake ChatGPT, Gemini, Claude, and Perplexity Sites Used to Steal Advertising Accounts and MFA Codes
Campaign targets ad account managers through spoofed AI interfaces and browser-in-browser attacks

Key Takeaways
- Fake websites impersonating ChatGPT, Gemini, Claude, and Perplexity are being used in a targeted campaign against ad account managers.
- The attack employs browser-in-browser techniques to bypass MFA and harvest credentials.
- Compromised advertising accounts could lead to unauthorized access to ad campaigns and marketing assets.
- User vigilance, URL verification, and phishing-resistant MFA are recommended mitigation strategies.
Related Security News

Nikkei Reports Email Account Breaches Used for Phishing Campaigns
Japanese publishing giant Nikkei has disclosed that unknown attackers breached two employee email accounts, utilizing one of the accounts to dispatch thousands of phishing emails. The incident underscores the ongoing risk of email account compromise and its potential use in credential theft and malware distribution campaigns.

Fake AI Chatbot Ad Portals Deployed to Steal Credentials and MFA Codes
Cybersecurity researchers have detailed a human-operated phishing platform that impersonates advertising products for major AI chatbots including OpenAI ChatGPT, Google Gemini, Anthropic Claude, Perplexity, Meta Muse, and Manus. The fake portals claim to offer campaign optimization, spend audits, and business-account connections, but are designed to steal user credentials and multi-factor authentication codes. The campaign, disclosed on October 6, 2026, targets users globally and leverages phishing portals that mimic legitimate AI advertising interfaces.



