Interestana
Home/News/Fake AI Sites Steal Ad Accounts, MFA Codes
BleepingComputer••3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Fake AI Sites Steal Ad Accounts, MFA Codes

A sophisticated phishing campaign is targeting advertising account managers by deploying deceptive websites that impersonate popular AI chatbots, including ChatGPT, Gemini, Claude, and Perplexity. These fake sites are designed to lure unsuspecting users into entering their login credentials and multi-factor authentication (MFA) codes, thereby compromising their advertising accounts. The attack method utilizes a technique known as browser-in-browser (BiB) attacks, which creates a seemingly legitimate pop-up window within the user's current browser session, making it appear as if they are interacting with a genuine login portal.

Researchers at the cybersecurity firm HUMAN Security identified this campaign, noting that the attackers specifically target individuals managing advertising accounts. The BiB attack works by embedding a fake browser window within the legitimate one, often styled to perfectly mimic the appearance of the real AI service's login page. When a user attempts to log in through this fake window, their entered username, password, and any subsequently requested MFA codes are captured by the attackers. This allows the threat actors to gain unauthorized access to the victim's ad accounts, potentially leading to significant financial losses, reputational damage, and the misuse of advertising budgets.

The campaign highlights a growing trend of threat actors leveraging the popularity and widespread adoption of AI tools to craft more convincing and effective phishing schemes. By impersonating well-known AI platforms, attackers can exploit user trust and familiarity with these services. The stolen credentials and MFA codes can then be used to take over ad accounts on platforms like Google Ads or Meta Ads, enabling the attackers to run fraudulent campaigns, redirect ad spend, or steal sensitive campaign data. The sophistication of the BiB attack, which bypasses some traditional security measures designed to detect fake domains, makes it particularly challenging to identify and prevent.

This incident underscores the critical importance of robust cybersecurity practices for individuals and organizations, especially those managing online advertising. Users are advised to exercise extreme caution when logging into sensitive accounts, always verifying the URL and looking for signs of spoofing. Implementing strong, unique passwords and utilizing hardware security keys for MFA, where possible, can provide an additional layer of defense against credential theft. The continuous evolution of phishing techniques necessitates ongoing vigilance and education within the cybersecurity community and among end-users to mitigate the risks posed by such advanced threats.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next