← Back to news
The Hacker News6 Oct 2026 · 2 min read

Phishing Sites Pose as AI Advertising Tools to Steal Login and MFA Data

Researchers have identified a phishing operation that uses fake advertising-management portals branded around popular artificial intelligence products, including ChatGPT, Gemini, Claude, Perplexity, M...

Researchers have identified a phishing operation that uses fake advertising-management portals branded around popular artificial intelligence products, including ChatGPT, Gemini, Claude, Perplexity, Meta Muse, and Manus. The sites claim to provide services such as campaign planning, ad-spend reviews, account optimization, and connections to business advertising accounts.

According to researchers at Island, the portals are intended to collect account passwords and multi-factor authentication codes from advertising professionals. The campaign appears to target agency employees, media buyers, and administrators of advertising manager accounts, which can control campaigns for multiple clients.

Fake browser windows imitate trusted sign-in pages

The sites prominently display a button to connect an account. Selecting it launches a browser-in-the-browser phishing interface: a counterfeit login window rendered within the victim's actual browser tab. The fraudulent window includes an address bar that appears to show legitimate services, such as Google Accounts or an Okta environment, while the real page remains under the attacker's control.

The platform reportedly records login attempts, gathers device fingerprinting information, and allows an operator to determine which MFA prompt or challenge is presented next. Stolen credentials may be used immediately to access the targeted advertising account.

One example, a site presenting itself as an AI advertising manager for Meta Muse, offered connections for Google, Meta, TikTok, and Okta-related workflows. Researchers said the wider infrastructure uses shared Next.js and Socket.IO components, common network endpoints, and similar operational patterns across multiple phishing themes.

Broader infrastructure targets ads and job seekers

The same platform has also been linked to fraudulent Google Ads refund and payment-confirmation pages, as well as recruitment-themed sites impersonating companies including Tesla, Nike, Louis Vuitton, and Adecco. Researchers said earlier versions of the platform's source code were exposed through publicly accessible, misconfigured GitHub repositories.

Advertising accounts can be valuable to criminals because they may have established spending histories and access to company payment methods. Attackers can add their own administrators, reduce the original owner's access, and use compromised accounts to run campaigns or sell access to others.

Defensive measures

  • Use phishing-resistant authentication methods where available.
  • Verify URLs and avoid signing in through embedded pop-up windows.
  • Review administrator changes, linked accounts, and advertising billing activity regularly.
  • Vet new AI integrations before authorizing access to ad platforms or identity providers.
Share this article:TwitterLinkedIn