{
  "id": 12582671,
  "title": "Fake AI advertising portals harvest logins and MFA codes",
  "url": "https://urgent.news/2026/10/07/fake-ai-advertising-portals-harvest-logins-and-mfa-codes",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-07T07:06:13.000Z",
  "source": {
    "name": "Arabian Post",
    "slug": "arabian-post",
    "url": "https://thearabianpost.com/fake-ai-advertising-portals-harvest-logins-and-mfa-codes/"
  },
  "original_language": "en",
  "account": "Security experts have discovered a human-operated phishing system designed to imitate AI advertising platforms such as ChatGPT, Claude, Gemini, and other similar products. The malicious operation, uncovered by researchers Oleg Zaytsev and Ofek Ronen of browser security firm Island, was disclosed on October 6. The platform targeted advertising professionals with false browser windows, aiming to steal account credentials and multifactor authentication codes. During their investigation, the researchers noted hundreds of submissions to the platform and confirmed that activity was ongoing at the time of their findings. Unlike basic credential harvesting methods, this campaign presented users with a convincing business service before requesting access, including fakes of OpenAI’s ChatGPT, Google’s Gemini, Anthropic’s Claude, Perplexity, Manus, and Meta’s Muse. Clicking the provided \"Connect\" button led to a Browser-in-the-Browser (BitB) interface, a counterfeit browser window embedded within a legitimate browser tab. This interface adapted to different operating systems and devices, mimicking details like Safari's URL display, Chrome custom tabs, and dark mode to evade user suspicion. The system operated as a human-controlled mechanism, fingerprinting devices and retaining multiple password attempts. Operators could reject incorrect passwords, request re-entry, and track the authentication process, allowing them to adapt the phishing sequence to the victim's responses. The attack demonstrated significant potential, as conventional multifactor authentication, relying on reusable one-time codes, could be bypassed when the victim submitted the code directly to the attacker while attempting to gain access to the legitimate service. While the lures utilized AI-themed branding, the infrastructure was also linked to refund, billing, and recruitment schemes, indicating a broader attack tactic. The researchers traced the same technology to various misconfigured public GitHub repositories, revealing common password-retry patterns, Telegram-linked control channels, and backend infrastructure used across multiple pages.",
  "summary": "Cybersecurity researchers have uncovered a human-operated phishing platform that impersonates advertising products linked to ChatGPT, Claude, Gemini and other artificial intelligence brands, using convincing fake browser windows to steal account credentials and multifactor authentication codes. Researchers Oleg Zaytsev and Ofek Ronen at browser security company Island disclosed the operation on…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}