The logos of ChatGPT, Gemini, Claude, Perplexity and Meta, all brands the fake ad portals copied. Illustrative. Image: OpenAI, Google, Anthropic, Perplexity and Meta logos via Simple Icons (CC0)

A phishing gang is dressing up as the new wave of AI advertising tools to steal the logins of the people who run ad accounts. Security firm Island published a report on Tuesday describing a “human-operated phishing platform” that poses as ad products for ChatGPT, Claude, Gemini, Perplexity and Manus, and most recently Meta’s Muse.

Island says it saw hundreds of victims submit details to the platform, and that it was still running when the report went out.

A fake Muse Ads site eight days after Muse

Meta launched its Muse AI agent on September 8. By September 16, a site at museads.ai was offering “Muse Ads”, billed as “Your AI ads manager for paid media workflows”. Island found the page ran on the same code as fake ad products the group had already built for the other AI brands.

Each fake product gets its own pitch, written in advertising jargon so it feels routine to the people it targets. The ChatGPT version promises a Monday Google Ads briefing, the Gemini one promises support for manager accounts, and Claude gets its own advertising portal. The report lists dozens of lookalike domains, from advertising-chatgpt.com and chatgpt-monday-brief.com to claude-ads-portal.com, anthropic-ads.com and gemini-ads.ai, plus fakes for Mistral and Cursor. It plays on real launches: OpenAI is expanding ads in ChatGPT, so advertisers half expect invitations to new AI ad tools.

The Connect button is the trap

Every page leads to one button: Connect. Clicking it opens what looks like a Google or Okta sign-in window, complete with a padlock and an address bar reading accounts.google.com. It is a picture of a browser drawn inside the web page, a trick known as browser-in-the-browser, while the real browser stays on the phishing site.

Island’s researchers summed it up:

Behind the interface, the platform kept every password attempt, fingerprinted the device, and let an operator pick which MFA challenge the victim saw next.

Oleg Zaytsev and Ofek Ronen, Island

A real person watches each victim live. The operator can reject a password and ask for it again (the platform stores up to three attempts), then choose whether to ask for a text message code, an authenticator code, a Google approval prompt or an Okta push, while trying the stolen login at the same time. It works for Google, Meta, TikTok and Okta accounts.

Why ad accounts are worth stealing

The lures are aimed at agency staff, media buyers and the people who manage several clients’ ad accounts. An ad account has a payment card and an approved budget attached, and one manager login can reach many clients. Island, citing earlier research by Mimecast, says thieves either spend the budget on their own ads or sell the account, with older accounts with a clean history fetching two to four times the price of new ones on Telegram.

Removing a card takes hours, Island says, but getting the account back can take weeks or months, because attackers add their own administrators and demote the owner.

The same platform also runs fake Google Ads refund pages and fake job sites for Tesla, Louis Vuitton, Nike and Adecco. One server linked them all, appearing in 73 scans across 25 domains between May and June. The group also left older versions of its code in public GitHub repositories, which is how Island could see how it works.

How to avoid it

Island’s advice is to treat any invitation to connect an account to a new AI tool as a request for access, and to check it on the company’s own website. A fake window can draw an address bar, but it can’t change the real one at the top of the browser. Passkeys and hardware security keys stop this kind of attack, because there is no reusable password or code to steal. Anyone who may have been caught should check every ad account they can reach for new managers and spending nobody approved.

Island sells a secure enterprise browser, so it has a commercial interest in browser-based attacks. None of the AI companies whose brands were copied has commented on the report. Stolen AI logins are already traded cheaply on the dark web.

Why it matters

Every AI company is now launching ads, agents and “connect your account” features, and scammers are copying them within days. A launch is exactly when a fake product looks most convincing, so the safest rule is never to sign in through a link in an invitation, however official it looks.

Sources: Island, Meta.

Latest More Labs news

More More Labs news