Threats & Adversaries · Credential Theft

Fake ChatGPT Sites Steal Ad Accounts

BleepingComputer reports a campaign using fake ChatGPT, Gemini, Claude, and Perplexity sites to target ad account managers and steal both passwords and multi-factor authentication (MFA) codes. The lure is a browser-in-browser phish: the victim sees a login window that looks like a real browser inside the site itself.

Because the page is fake but interactive, the attacker can collect the password and the one-time code in the same sign-in flow and turn them into a working login, not just a leaked credential. That matters for ad teams because a hijacked advertising account can mean control of campaign settings, billing, and business messaging.

The exposure sits in browser-based MFA flows: if users trust the page surface more than the domain, the same trick can carry into other SaaS and cloud logins. For organizations that manage ads in those accounts, the loss is the account session and the assets behind it, not only the AI-brand impersonation.

2 sources · 4h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-10-06

Every edition of this story: Fake ChatGPT Sites Steal Ad Accounts

More from today