Find notable cyber news and cases, enriched with sources, timelines, and signals.

Fake AI login phishing campaign targeting ad account managers

Campaign
First reported
Last updated
Happening score
H score 36
1 unique sources, 1 articles

Summary

Hide ▲

A phishing campaign is using fake ChatGPT, Gemini, Claude, and Perplexity sites to steal login credentials and MFA codes, putting ad account managers and downstream client accounts at risk of fraudulent ad spend and resale. The operation uses browser-in-the-browser login pages that imitate accounts.google.com and other sign-in flows. Researchers traced the broader activity to related lures and infrastructure that date back to March.

Related Happenings

UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign

Campaign
H score16 First: 20.08.2026 22:59 Last: 20.08.2026 22:59 Sources 1

About this happening: A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and Euro...

RecruitTrap recruitment-themed phishing campaign

Campaign
H score25 First: 14.08.2026 13:57 Last: 14.08.2026 13:57 Sources 1

About this happening: The RecruitTrap campaign used fake recruiter outreach and BitB login pages to steal Google and Facebook credentials and relay MFA prompts in real time. It span...

LogoKit real-time per-victim phishing campaign

Campaign
H score35 First: 29.07.2026 19:00 Last: 29.07.2026 19:00 Sources 1

About this happening: The LogoKit phishing-as-a-service campaign now builds a unique login page per victim in real time, making credential theft harder to detect and block. It uses live scree...

Q2 2026 brand phishing expands to ChatGPT impersonation

Trend
H score35 First: 24.07.2026 14:15 Last: 24.07.2026 14:15 Sources 1

About this happening: Phishing impersonation of technology brands rose in Q2 2026, with ChatGPT entering the top 10 of most impersonated brands for the first time and signaling growing atta...

GPPStorm Google Partners enrollment phishing campaign

Campaign
H score33 First: 13.07.2026 16:03 Last: 13.07.2026 16:03 Sources 1

About this happening: GPPStorm is a phishing campaign that uses bogus Google Partners and Google Premier Partner enrollment workflows to push recipients to a fake Google sign-in page and st...

Timeline

  1. 06.10.2026 18:16 2 articles · 0h ago

    Fake ChatGPT, Gemini, Claude, and Perplexity pages steal ad account credentials and MFA codes

    Initial Disclosure

    Researchers identified a phishing campaign targeting ad account managers, agency staff, media buyers, and administrators with fake ChatGPT, Gemini, Claude, and Perplexity login pages that use browser-in-the-browser flows to steal credentials and MFA codes. The fake pages prompt victims to connect accounts through an embedded Google window showing accounts.google.com, while a human operator can request passwords, SMS or authenticator codes, Okta push approvals, Google prompts, or QR-code scans. The same operation also appears to leverage the recent launch of the Muse AI agent, use fake recruitment and refund lures, and rely on shared Next.js and Socket.IO infrastructure with Vercel, Railway, and Render components; investigators traced related activity back as far as March and saw hundreds of victim submissions in the Telegram control channel.

    Show sources