Phishing Campaign Masquerades as ChatGPT, Claude and Gemini Ads to Hijack Advertisers’ Accounts
A newly identified phishing operation is targeting advertising professionals by posing as popular AI advertising products such as ChatGPT, Claude and Gemini. The scheme relies on a "browser‑in‑the‑browser" trick that displays a counterfeit login window within a legitimate‑looking page, allowing attackers to capture usernames, passwords and even manipulate multi‑factor authentication (MFA) prompts.
The browser‑in‑the‑browser method creates an illusion of a secure, embedded browser provided by the advertised service. Victims are led to believe they are authorising a connection between their ad account and an AI‑driven tool, when in fact the window is a fully controlled replica that records every credential entered.
Security researchers monitoring the campaign reported seeing hundreds of distinct phishing pages that replicate the visual design of genuine ad‑platform integration flows. Each page includes branding, logos and language consistent with the official ChatGPT, Claude and Gemini advertising interfaces, making the deception especially convincing for users who routinely link third‑party tools to their ad accounts.
Successful compromises give attackers direct access to advertising dashboards, where they can reallocate budgets, extract performance data, or even launch further malicious campaigns. By subverting MFA, the actors bypass one of the strongest defenses that many advertisers rely on, increasing the likelihood of long‑term account control and potential financial loss.
Researchers, first highlighted by the GBHackers community, have issued warnings to marketers and platform providers. They advise users to verify URLs carefully, avoid clicking links in unsolicited messages, and prefer hardware‑based MFA tokens that are resistant to screen‑based interception. Reporting suspicious pages to the affected platforms and to security‑focused groups can help accelerate takedown efforts.
Analysts expect the technique to evolve as AI‑related services gain wider adoption in the advertising ecosystem. Continued vigilance, combined with stronger verification mechanisms from the AI and ad‑tech providers, will be essential to curb the abuse of these trusted brands for phishing purposes.
Comments (0)
Be the first to comment.
Join the discussion