➤Summary
Fake AI phishing sites are targeting advertising account managers by impersonating familiar products from ChatGPT, Gemini, Claude and Perplexity. The campaign uses AI-themed advertising portals and fake sign-in windows to capture credentials and multi-factor authentication codes in real time. For security and brand-protection teams, the incident shows how quickly trusted AI names can be repurposed into phishing infrastructure.
What Happened in the Fake AI Phishing Campaign?
On October 6, 2026, Island security researchers disclosed a human-operated phishing platform disguised as a portfolio of AI advertising products. The campaign used brand-specific lures that promised functions such as campaign optimization, spend audits, Google Ads briefs and business-account connections.
According to Island’s investigation of the fake AI ads campaign, the operators had already impersonated Gemini, Claude, ChatGPT and Perplexity before adding a fake Muse Ads product shortly after Meta introduced Muse. Researchers said the activity was still ongoing when their report was published and that the platform had received hundreds of victim submissions. That figure should not be interpreted as a confirmed number of successfully compromised accounts.
The pages do not begin with an obvious password prompt. They present themselves as useful business products for marketers and advertisers, making the request to “connect” an account appear routine.
Why Advertising Accounts Are Valuable Targets
Agency staff, media buyers and advertising administrators often manage accounts with access to several client environments. A single manager identity may control campaigns, budgets, payment methods and permissions across multiple organizations.
That creates a multiplier effect. If an attacker gains access to one advertising manager account, the risk can extend to client campaigns and billing relationships. Attackers may attempt fraudulent ad spending, change account administrators or resell access.
BleepingComputer’s coverage of the fake ChatGPT and Gemini phishing sites reported that the campaign specifically targeted professionals whose advertising accounts could reach multiple client accounts and that the phishing flows were designed to collect both login credentials and MFA codes.
How Browser-in-the-Browser Phishing Makes the Login Look Real
The campaign uses Browser-in-the-Browser, or BitB. Instead of opening a genuine Google or Okta authentication window, the phishing site draws a fake browser window inside the real browser tab.
The fake window can display a realistic address bar, familiar logos and a trusted-looking sign-in URL. To the victim, it may appear that Google or another identity provider has opened a normal authentication popup. In reality, the user is still interacting with the attacker-controlled page.
SpoofGuard has previously examined this technique in its guide to UI spoofing and Browser-in-the-Browser threats. The defensive lesson is simple: visual browser chrome inside a webpage should not be treated as proof that the authentication flow is legitimate.
A practical check is to inspect the real browser origin rather than the address bar drawn inside the page. Genuine browser windows behave independently from the webpage, while a simulated popup remains part of it.
Why MFA Did Not Automatically Stop the Attack
MFA substantially reduces account-takeover risk, but not every MFA method is equally resistant to phishing.
Human-in-the-loop phishing can keep a victim engaged while an attacker attempts to authenticate to the legitimate service. Instead of simply collecting a static username and password for later use, the attacker may try to obtain a verification step while the victim is still interacting with the fake interface.
That distinction matters because SMS codes, authenticator codes and approval prompts can still be socially engineered under certain conditions.
Phishing-resistant authentication changes this equation. Passkeys and hardware-backed methods that bind authentication to the legitimate origin reduce the value of one-time codes captured by a fake page.
AI Brand Impersonation Is the Social-Engineering Layer
The AI companies being impersonated were not reported as breached in this campaign. Their brands were being abused to create trust.
A fake ChatGPT, Gemini, Claude or Perplexity site is evidence of impersonation, not evidence that OpenAI, Google, Anthropic or Perplexity suffered a compromise.
The campaign also shows why fast-moving technology categories are attractive to phishers. Users expect new beta programs, integrations and advertising tools to appear quickly. A fraudulent product can therefore look plausible before users have established what the legitimate vendor actually offers.
SpoofGuard has discussed a related pattern in its article on phishing detection for fake AI APIs, where attackers exploit expectations around emerging AI services.
What Brand-Protection Teams Should Monitor
A lookalike domain is not automatically a phishing domain. Security teams need evidence that distinguishes harmless similarity from active abuse.
Useful signals include:
- domains combining a trusted AI brand with advertising, beta, business or account-related terms;
- newly activated websites that reproduce brand logos or login interfaces;
- SSL certificate issuance for suspicious brand-related domains;
- new DNS, MX or hosting changes on previously inactive domains;
- pages asking users to connect Google, Meta, TikTok or enterprise identity accounts;
- advertising or email campaigns directing users to unverified AI products;
- cloned sign-in flows, credential forms or unexpected identity-provider prompts.
SpoofGuard’s domain threat intelligence technology describes monitoring across domain registrations, Certificate Transparency logs, DNS changes, website content and infrastructure signals. These signals can help teams prioritize suspicious domains for validation rather than treating every similar name as malicious.
How Organizations Should Respond to a Suspected Phishing Domain
When a suspicious domain is identified, the first step is evidence collection, not immediate attribution.
Teams should record the domain, timestamps, screenshots, redirect behavior, DNS records, certificate information, registrar details and observed brand assets. If credential collection is visible, preserve enough evidence to support blocking, abuse reporting and takedown requests without interacting with the site more than necessary.
If an employee entered credentials, incident response should begin immediately. Relevant actions may include resetting passwords, revoking active sessions, reviewing MFA methods, checking advertising account administrators and examining recent campaigns, billing changes and account permissions.
For a manager account, investigators should review every downstream client environment the compromised identity could access. The absence of fraudulent spend does not prove that no access occurred.
SpoofGuard’s phishing detection and takedown use cases show how domain monitoring, infrastructure context, screenshots and evidence can be combined into a repeatable investigation and enforcement workflow.
Frequently Asked Questions
Were ChatGPT, Gemini, Claude or Perplexity hacked?
The available reporting does not indicate that these AI providers were breached as part of this campaign. Attackers created fake products and websites that impersonated their brands. Brand impersonation and a breach of the impersonated company are different events.
Can Browser-in-the-Browser phishing bypass MFA?
It can capture some phishable MFA factors when a victim submits them to a fake interface while an attacker attempts a real login. This does not mean every MFA system can be bypassed. Origin-bound passkeys and hardware-backed phishing-resistant authentication provide stronger protection against this type of interception.
Is every lookalike AI domain malicious?
No. Domain similarity alone is not proof of malicious activity. A domain becomes more concerning when additional evidence appears, such as cloned branding, credential forms, suspicious redirects, unusual DNS behavior or confirmed phishing content.
What should an agency do if an ad account was phished?
Revoke suspicious sessions, reset affected credentials, review MFA enrollment, verify administrators and recovery settings, and inspect campaigns and billing activity. Agencies should also check every client account accessible through the compromised identity because one manager account can create downstream exposure.
Detect AI Brand Impersonation Earlier
Fake AI products show how quickly attackers can turn trusted brands into convincing phishing lures. Continuous domain and infrastructure monitoring can help security teams identify suspicious lookalike sites, validate whether phishing content is active, collect evidence and coordinate response. If you want to assess how your own brand is being impersonated online, start your 7-day SpoofGuard free trial
