A sophisticated phishing campaign has emerged, leveraging fake websites that mimic popular AI platforms like ChatGPT, Gemini, and Claude. These fraudulent sites aim to steal advertising accounts and multi-factor authentication codes from unsuspecting users. The attackers employ a browser-in-browser attack technique, which creates convincing login prompts that deceive users into divulging their credentials.
The impact of this campaign is significant, particularly for businesses and individuals relying on online advertising platforms. Compromised accounts can result in unauthorized access, leading to financial losses and reputational damage. The phishing sites are designed to look legitimate, increasing the likelihood of success. With the growing reliance on AI-driven tools, users must remain vigilant against such threats.
To mitigate risks, users should be cautious when accessing AI tools, especially through links in unsolicited emails or messages. Verification of URLs and ensuring secure connections can help prevent falling victim to these attacks. Companies should educate their employees on recognizing phishing attempts and encourage the use of password managers to handle credentials securely. Advanced security measures, such as monitoring for unusual account activities, can also play a crucial role in early detection and response.

