Fake AI Ad Portals Steal User Credentials and MFA Codes
A human-operated phishing campaign is targeting advertising account managers by impersonating artificial intelligence ad management portals to capture user credentials and multi-factor authentication codes.
FTMQ Security, written by our newsroom0 views

A human-operated phishing platform is impersonating ad management tools for major artificial intelligence products to steal credentials and multi-factor authentication codes, The Hacker News and BleepingComputer reported. The campaign specifically targets advertising account managers using fake portals that impersonate tools for OpenAI ChatGPT, Google Gemini, Anthropic Claude, Perplexity, Meta Muse, and Manus. [1][2]
According to The Hacker News and BleepingComputer, the fraudulent websites use browser-in-the-browser login windows to capture incoming multi-factor authentication codes and account passwords. The fake portals promise campaign optimization, spend audits, and business account connections, but rely on a connect action that displays a fake browser window drawn inside the actual browser. Island researchers Oleg Zaytsev and Ofek Ronen reported that each fake product was built around this single malicious connection action. [1][2]
BleepingComputer reported that the phishing campaign also exploited the public launch of Meta Muse, an artificial intelligence assistant created for personal tasks. ChatGPT is a generative artificial intelligence chatbot developed by OpenAI that uses large language models to produce text and image responses. [2][5]
Multi-factor authentication requires users to present two or more distinct pieces of evidence before access is granted, which helps protect personal and financial data if a password is compromised. Security teams should inform system administrators and advertising managers about browser-in-the-browser attacks to prevent unauthorized credential capture. [1][2][6]
In short
- A human-operated phishing platform is impersonating artificial intelligence portals to steal credentials.
- The attack uses browser-in-the-browser windows to capture login details and multi-factor authentication codes.
- The campaign targets ad account managers using fake sites for ChatGPT, Gemini, Claude, and Perplexity.
Sources
Every paragraph above points to the numbered items it rests on. Read the originals here.
- [1]Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA CodesThe Hacker News, 1d ago (the report this story comes from)
- [2]Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codesBleepingComputer, 1d ago
- [3]Midnight Blizzard Abuses Hotel Wi-Fi Captive Portals to Deliver Malware and Steal CredentialsCyberSecurityNews, 1d ago
Background
- [4]Artificial intelligence on Wikipedia
- [5]ChatGPT on Wikipedia
- [6]Multi-factor authentication on Wikipedia
Our newsroom writes these reports with the help of software, from the 6 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.
Related from FTMQ Security
Earlier reports of ours on the same people and subjects.
- China Aligned TA419 Targets US AI Experts With Phishing AttacksTop Stories, 3d ago
More in Top Stories
- Attackers hijack top level domains to obtain unauthorized Google security certificates7m ago
- Discord security bot Double Counter breached exposing user email addresses7m ago
- FBI warns ongoing FortiBleed attacks target Fortinet VPNs and lock out administrators7m ago
- MonsterCloud owner charged over secret ransomware payments7m ago
- Ransomware group BYOD claims data breach exposing Trump Mobile subscriber records7m ago
- FBI removes Accenture contractor following Oracle PeopleSoft data breach1d ago
Get the day in one email
Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments
Loading
Join the conversation
Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.
Already on the list? Enter the same address and we will send a sign-in link.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.