GMAsia
    🇸🇬Singapore·AI News·7 Oct 2026·via International Business Times

    Fake ChatGPT and Gemini Sites Used in AI Phishing Attack to Steal Ad Accounts and MFA Codes

    Cybercriminals are using fake AI platforms like ChatGPT, Gemini, and Claude to steal advertising account credentials and multi-factor authentication (MFA) codes. Researchers from Island identified a phishing campaign employing convincing fake websites and browser-in-the-browser (BitB) techniques to target advertising agency employees and media buyers.

    Nexa's Summary

    The phishing operation focuses on business accounts managing advertising budgets, which, once compromised, can be used for fraudulent campaigns or sold. Attackers create fraudulent websites that mimic legitimate AI advertising assistants, encouraging victims to connect their advertising accounts. The lure involves services such as campaign optimization and spending audits.

    A key element of the attack is the browser-in-the-browser (BitB) technique. When a victim attempts to connect their account, a counterfeit Google or Okta login window appears within the existing phishing page. This fake window is designed to look authentic, complete with familiar branding and a trusted-looking address bar, while the actual browser remains on the malicious site.

    Beyond initial password capture, the attackers leverage human operators to control the multi-factor authentication process. They can fingerprint devices, request repeated password entries, and trigger various MFA challenges like SMS codes, authenticator prompts, or QR-code authentication. This allows the attackers to adapt to the victim's responses and maintain the phishing session until successful.

    Share this article

    Go deeper
    Original reporting by International Business TimesWe don't republish, read the full story â†’

    Related reading

    6 stories