Cybercriminals are using fake websites that impersonate AI advertising tools such as ChatGPT, Google Gemini, Anthropic Claude, Perplexity, and others to steal login details and multi-factor authentication (MFA) codes from ad account managers. Researchers describe the campaign as a “human-operated phishing platform” that focuses on taking over advertiser accounts, including those that may already be provisioned with payment information.
Reports say the pages are presented as portals for marketing functions like campaign optimization, spending audits, and connecting business accounts. Instead of delivering those services, the sites capture usernames and passwords and then harvest MFA codes, including through browser-in-browser techniques that mimic the authentication flow. The stolen access can allow attackers to control advertising accounts and potentially carry out fraudulent activity using the compromised credentials.
Outlets emphasize that the targeting is specifically aimed at advertisers and those who manage ad accounts, rather than general consumers. While the brands being spoofed vary across the coverage, all accounts describe the same core tactic: impersonation of legitimate AI ad products combined with credential and MFA interception to bypass standard login protections.