By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Fake AI Chatbot Ad Portals Steal Credentials, MFA

Cybersecurity researchers have detailed a sophisticated, human-operated phishing platform designed to impersonate advertising portals for prominent artificial intelligence (AI) chatbots. This platform targets users seeking to manage or optimize advertising campaigns for services such as Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. The fake portals are crafted to appear as legitimate tools offering features like campaign optimization, spend audits, and business account connections, with the sole objective of capturing sensitive user information. The operation was uncovered by researchers who observed the platform's intricate setup and its methods for deceiving potential victims.
The phishing platform employs a multi-stage attack vector. Initially, victims are lured to fake advertising portals through various means, likely including malicious advertisements or direct phishing emails. Once on the counterfeit site, users are prompted to log in with their existing credentials for the respective AI chatbot services. The platform is engineered to capture not only usernames and passwords but also time-based one-time passwords (TOTP) generated by multi-factor authentication (MFA) applications. This capability is particularly concerning as it bypasses a critical security layer designed to prevent unauthorized access even if credentials are compromised. The attackers leverage the trust users place in these AI tools and their associated advertising ecosystems to execute their fraudulent activities.
The researchers highlighted that the platform's operators actively manage and update the phishing sites, indicating a persistent and organized threat actor. The impersonated services are among the most widely used AI chatbots, suggesting a broad target base. By mimicking the legitimate interfaces and functionalities of these advertising platforms, the attackers aim to maximize the chances of success. The stolen credentials and MFA codes can then be used to gain full access to user accounts, potentially leading to financial fraud, data theft, or the misuse of AI services for malicious purposes. The existence of such platforms underscores the growing need for enhanced vigilance and security awareness among users of AI technologies and their associated business tools.
This discovery by cybersecurity researchers serves as a stark reminder of the evolving threat landscape in the AI sector. As AI chatbots become increasingly integrated into business operations and marketing strategies, the platforms that support them become attractive targets for cybercriminals. The human-operated nature of this phishing platform suggests a level of sophistication beyond automated attacks, allowing for real-time adaptation and evasion of detection systems. The researchers have not yet publicly disclosed the specific names of the threat actors or the full extent of the compromised accounts, but the detailed technical analysis provides a clear picture of the operational methods. The implications for businesses relying on these AI services are significant, necessitating a review of their security protocols and employee training to mitigate the risks associated with credential harvesting and MFA bypass techniques.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.