Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes
- ID
- 32527
- Status
- summarized
- Published
- 07 Oct 2026, 2:38 AM
- Fetched
- 07 Oct 2026, 5:59 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/10/fake-chatgpt-gemini-and-claude-ad.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 6.0
- Created
- 07 Oct 2026, 6:00 AM
- Tags
- Audience
- developerssaas_startup_foundersai_agent_users
What happened
Researchers at Island disclosed a human-operated phishing platform that impersonates ad products for ChatGPT, Gemini, Claude, Perplexity, Meta Muse, and Manus, using a browser-in-the-browser (BitB) fake window whose address bar shows legitimate origins like accounts.google.com or an Okta tenant. One site, museads.ai, appeared on September 16, 2026 — about a week after Meta launched Muse — and its "Connect" button fingerprints the device, logs every password attempt, and lets the operator choose which MFA challenge the victim sees; stolen credentials are used to sign in in real time, with data sent to /api/send/ip over Socket.IO. Each brand gets a tailored pitch (ChatGPT promising a Monday Google Ads brief, Gemini promising manager-account and linked-client support), targeting Google, Meta, TikTok, and Okta workflows.
Why it matters
If anyone on your team connects ad accounts or SSO through a link from a sales pitch or DM, the usual 'check the URL' defence fails here because the address bar is drawn inside the page. Concretely: stop approving Okta or Google sign-ins you did not start yourself, since the operator picks which MFA prompt you see, and treat any 'connect your ad account' tool pitched under an AI brand name as unverified unless you reached the real console by bookmark or typed URL. Watch Okta/Google sign-in logs for MFA challenges no one initiated.
Discussion angle
BitB breaks the address-bar habit most teams still teach — what replaces it for verifying a login prompt, and how fast should you expect attackers to clone a new AI product's branding (museads.ai landed roughly a week after Meta's Muse launch)?