NEWS

Fake ChatGPT, Gemini, and Claude Sites Steal Advertising Accounts and MFA Codes

A browser-in-the-browser phishing campaign impersonates AI tools to hijack ad account managers' logins and real-time MFA codes.

Dylan H.

News Desk

October 7, 2026
3 min read
Fake ChatGPT, Gemini, and Claude Sites Steal Advertising Accounts and MFA Codes

AI-Branded Lures Target the People Who Control Ad Budgets

A phishing operation is impersonating ChatGPT, Gemini, Claude, and Perplexity to target advertising account managers, media buyers, and ad administrators — roles that typically hold spending authority across multiple client accounts. The campaign combines convincing AI-tool branding with a technically sophisticated browser-in-the-browser (BitB) attack to harvest both credentials and multi-factor authentication codes in real time.


How the Browser-in-the-Browser Attack Works

Victims land on a site impersonating a popular AI platform and are prompted to "Connect" their Google account to unlock some feature. Clicking it opens what looks like a legitimate Google OAuth pop-up — complete with a realistic address bar showing accounts.google.com. In reality, that "pop-up" is an iframe rendered inside the page itself, with the phishing site locally rebuilding the Google login interface to collect credentials directly.

Once a victim enters their password, a live human operator takes over the session and can:

  • Request the password again if the first attempt looks wrong
  • Prompt the victim for an SMS or authenticator app code
  • Display a fake Okta push notification or Google approval prompt
  • Reject submitted codes, stall victims on a waiting screen, or terminate the session at will

This human-in-the-loop design lets operators relay stolen MFA codes to the real login page within the code's validity window — defeating time-based one-time passwords and app-based push approvals that would otherwise stop simple credential phishing.


Who's Being Targeted

TargetWhy
Agency staffManage ad accounts across many clients
Media buyersControl active ad spend and budgets
Ad administratorsHold elevated permissions on platform accounts

Compromised accounts give attackers the ability to launch fraudulent ad campaigns against the victim's budget or resell the stolen access to other cybercriminals — both lucrative outcomes given the spending authority these roles typically carry.


Infrastructure and Scope

Researchers traced the campaign's infrastructure — built on Next.js and Socket.IO — back to March 2026 through exposed GitHub repositories, and have identified dozens of URLs themed around ads, refunds, and recruitment lures.


The Attack's Weakness

Browser-in-the-browser attacks have a structural limitation that defenders can use for detection: the fake pop-up is an iframe confined to the browser window. Unlike a genuine OAuth pop-up, it cannot be dragged outside the browser's boundaries or resized independently — if a "Google sign-in window" won't move past the edge of your browser tab, that's a strong signal it's fake.


  1. Train ad-ops and agency staff specifically on the browser-in-the-browser tell: try dragging any login pop-up outside the browser window before entering credentials
  2. Enforce phishing-resistant MFA (FIDO2/WebAuthn hardware keys) on advertising platform accounts — these cannot be relayed by a human operator the way SMS or TOTP codes can
  3. Restrict and monitor ad account permissions, limiting spend authority to the minimum needed per role
  4. Block known campaign infrastructure at the network/DNS layer where threat intelligence feeds have indexed it
  5. Report suspicious "Connect your account" prompts on any site claiming to be ChatGPT, Gemini, Claude, or Perplexity — none of these platforms require linking a Google ad account to use their core chat features