Fake AI login phishing campaign targeting ad account managers
Campaign
Summary
Hide ▲
Show ▼
A phishing campaign is using fake ChatGPT, Gemini, Claude, and Perplexity sites to steal login credentials and MFA codes, putting ad account managers and downstream client accounts at risk of fraudulent ad spend and resale. The operation uses browser-in-the-browser login pages that imitate accounts.google.com and other sign-in flows. Researchers traced the broader activity to related lures and infrastructure that date back to March.
Related Happenings
UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign
Campaign
H score16
First: 20.08.2026 22:59
Last: 20.08.2026 22:59
Sources 1
About this happening:
A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and Euro...
UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign
CampaignAbout this happening: A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and Euro...
RecruitTrap recruitment-themed phishing campaign
Campaign
H score25
First: 14.08.2026 13:57
Last: 14.08.2026 13:57
Sources 1
About this happening:
The RecruitTrap campaign used fake recruiter outreach and BitB login pages to steal Google and Facebook credentials and relay MFA prompts in real time. It span...
RecruitTrap recruitment-themed phishing campaign
CampaignAbout this happening: The RecruitTrap campaign used fake recruiter outreach and BitB login pages to steal Google and Facebook credentials and relay MFA prompts in real time. It span...
LogoKit real-time per-victim phishing campaign
Campaign
H score35
First: 29.07.2026 19:00
Last: 29.07.2026 19:00
Sources 1
About this happening:
The LogoKit phishing-as-a-service campaign now builds a unique login page per victim in real time, making credential theft harder to detect and block. It uses live scree...
LogoKit real-time per-victim phishing campaign
CampaignAbout this happening: The LogoKit phishing-as-a-service campaign now builds a unique login page per victim in real time, making credential theft harder to detect and block. It uses live scree...
Q2 2026 brand phishing expands to ChatGPT impersonation
Trend
H score35
First: 24.07.2026 14:15
Last: 24.07.2026 14:15
Sources 1
About this happening:
Phishing impersonation of technology brands rose in Q2 2026, with ChatGPT entering the top 10 of most impersonated brands for the first time and signaling growing atta...
Q2 2026 brand phishing expands to ChatGPT impersonation
TrendAbout this happening: Phishing impersonation of technology brands rose in Q2 2026, with ChatGPT entering the top 10 of most impersonated brands for the first time and signaling growing atta...
GPPStorm Google Partners enrollment phishing campaign
Campaign
H score33
First: 13.07.2026 16:03
Last: 13.07.2026 16:03
Sources 1
About this happening:
GPPStorm is a phishing campaign that uses bogus Google Partners and Google Premier Partner enrollment workflows to push recipients to a fake Google sign-in page and st...
GPPStorm Google Partners enrollment phishing campaign
CampaignAbout this happening: GPPStorm is a phishing campaign that uses bogus Google Partners and Google Premier Partner enrollment workflows to push recipients to a fake Google sign-in page and st...
Timeline
-
06.10.2026 18:16 2 articles · 0h ago
Fake ChatGPT, Gemini, Claude, and Perplexity pages steal ad account credentials and MFA codes
Initial DisclosureResearchers identified a phishing campaign targeting ad account managers, agency staff, media buyers, and administrators with fake ChatGPT, Gemini, Claude, and Perplexity login pages that use browser-in-the-browser flows to steal credentials and MFA codes. The fake pages prompt victims to connect accounts through an embedded Google window showing accounts.google.com, while a human operator can request passwords, SMS or authenticator codes, Okta push approvals, Google prompts, or QR-code scans. The same operation also appears to leverage the recent launch of the Muse AI agent, use fake recruitment and refund lures, and rely on shared Next.js and Socket.IO infrastructure with Vercel, Railway, and Render components; investigators traced related activity back as far as March and saw hundreds of victim submissions in the Telegram control channel.
Show sources
- Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes — www.bleepingcomputer.com — 06.10.2026 18:16
- Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes — www.bleepingcomputer.com — 06.10.2026 18:16