$ techbeacon▋
Phishing

Human‑run Phishing Scheme Hijacks AI Chatbot Ad Accounts and MFA Codes

Human‑run Phishing Scheme Hijacks AI Chatbot Ad Accounts and MFA Codes

Cybersecurity analysts have uncovered a sophisticated, human‑operated phishing platform that masquerades as advertising portals for popular artificial‑intelligence chatbots, siphoning user credentials and multi‑factor authentication (MFA) codes.

The operation presents counterfeit sites that promise advertisers the ability to promote AI services such as Google Gemini, Anthropic Claude, OpenAI's ChatGPT, Perplexity, Meta Muse and Manus. When a prospective user clicks a link, they are taken to a replica login page that closely mirrors the legitimate service's interface.

After entering a username and password, victims encounter a secondary prompt that appears to request the one‑time verification code generated by their MFA device. The code is captured in real time, granting the attackers full access to the victim's account despite the presence of two‑factor protection.

Researchers say the scheme leverages the current surge of interest in generative AI, exploiting the eagerness of marketers and developers to secure ad placements for these high‑profile tools. By mimicking official branding and using realistic URLs, the fraudsters increase the likelihood that users will trust the page and submit sensitive information.

The campaign appears to be run by a small team that manually processes each login attempt, allowing them to adapt quickly to security measures and to harvest a broader range of credentials than automated bots typically achieve. Early indicators suggest that the operation has already compromised dozens of accounts, though the full scope remains unclear.

Security experts advise users to verify web addresses carefully, employ password managers that can flag suspicious domains, and consider phishing‑resistant authentication methods such as hardware security keys. Organizations that host AI chatbot services are also urged to monitor for abnormal login patterns and to educate customers about the risk of AI‑themed phishing attacks.

As the adoption of AI chatbots continues to expand across industries, analysts expect similar deception tactics to proliferate, making vigilance and robust security hygiene essential for both individual users and enterprises.

Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related