Skip to content
Tech News
← Back to articles

Fake ChatGPT and Gemini ad-platform sites steal advertiser logins via browser-in-browser attack

read original get YubiKey 5 Series → more articles
GoKawiil Brief

Security firm Island discovered a phishing campaign using fake ChatGPT, Gemini, Claude and Perplexity sites that target advertising agency staff and media buyers. The sites exploit the recent launch of Meta's Muse AI agent and use browser-in-browser techniques to fake Google login windows, capturing credentials and MFA codes to hijack high-value ad accounts.

Why It Matters

GoKawiil's interpretation of the reporting above, not reported fact.

The stolen accounts can be used to run fraudulent ad campaigns or sold to other criminals, suggesting attackers are specifically chasing accounts with spending power across multiple clients rather than individual users. Island notes the phishing kit adapts to multiple operating systems and uses a human operator to guide victims, indicating the campaign is built for scale and persistence as AI tools become common targets for impersonation.

Key Takeaways
Worth a Look

YubiKey 5 Series — Since this phishing campaign specifically targets login credentials and MFA codes through fake browser windows, a hardware security key like the YubiKey provides phishing-resistant authentication that can't be tricked by fake login pages. It's a practical step for ad account managers and agencies who need to protect high-value advertising accounts from exactly this kind of attack.

See YubiKey 5 Series on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Source: bleepingcomputer.com, 2026-10-06

Published there as: “Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.