Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes
thehackernews.com Oct 6, 2026

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

AI-summarised brief · reviewed before publication

Cybersecurity researchers exposed a sophisticated phishing operation that masquerades as AI‑driven advertising platforms for ChatGPT, Gemini, Claude, and others. The scheme uses a browser‑in‑browser trick to display spoofed login pages that appear to belong to legitimate domains, capturing usernames, passwords, and MFA codes. Operators then use the stolen credentials to access Google, Meta, TikTok, and Okta accounts in real time, often targeting agency staff and media buyers. The attackers also host related phishing sites for high‑profile brands and expose source code on public GitHub repositories.

💡 Why It Matters

  • · The attack demonstrates how AI branding can be weaponized to bypass MFA, turning ad accounts into lucrative commodities for cybercriminals.
  • · It underscores the urgent need for phishing‑resistant authentication and vigilant monitoring of ad‑account changes.