Fake ChatGPT Gemini sites are being used in an active phishing campaign targeting advertising professionals, media buyers, and account administrators with access to valuable Google, Meta, TikTok, and Okta accounts.
The campaign uses realistic AI-branded advertising products that claim to help users manage campaigns, optimize ad spend, or connect business accounts. But clicking the apparent “Connect” button launches a carefully designed fake login window that can capture passwords and multi-factor authentication codes.
Security researchers at Island found that the operation impersonates several well-known AI brands, including ChatGPT, Gemini, Claude, Perplexity, Manus, and Meta’s newly launched Muse platform.
The attackers are using a technique known as Browser-in-the-Browser phishing, or BitB, to make the fake login flow appear far more convincing than a traditional phishing page.
For broader protection against credential theft, phishing, and business account compromise, see our Small Business Cybersecurity Defense Hub.
Key takeaway: These fake AI tools are not simply stealing passwords. Human operators can interact with victims in real time, request MFA codes, trigger approval prompts, and potentially take control of advertising accounts linked to multiple clients.
How the Fake ChatGPT and Gemini Phishing Campaign Works
The campaign is designed around a simple action: convincing a target to connect an advertising or business account to what appears to be a useful AI service.
The fake products are tailored specifically to advertising professionals.
Researchers observed pages offering services such as:
- AI-powered advertising campaign optimization
- Google Ads account management
- Campaign spending audits
- Weekly advertising briefs
- Business account integrations
- Paid media planning
Because these services appear directly relevant to marketers and ad managers, the request to connect an account may look legitimate.

The “Connect” Button Is the Trap
When a victim clicks the Connect button, the phishing site does not actually open a genuine Google authentication window.
Instead, it draws a second browser interface inside the existing webpage.
The fake window can include:
- A realistic browser title bar
- A lock icon
- An address bar showing
accounts.google.com - Google-style login forms
- Dark-mode styling
- Mobile-specific browser interfaces
This technique is known as Browser-in-the-Browser phishing.
The victim may believe a genuine Google login window has opened, even though the real browser is still connected to the attacker’s phishing domain.
What Is Browser-in-the-Browser Phishing?
Browser-in-the-Browser attacks simulate a legitimate authentication popup inside a malicious webpage.
Unlike a normal phishing page that simply copies a login screen, BitB attacks recreate the appearance of a separate browser window.
This allows attackers to display trusted-looking URLs such as:
accounts.google.com- Meta login pages
- TikTok authentication portals
- Okta tenant login pages
The URL displayed inside the fake popup is not the real browser address bar.
Island researchers noted one simple test: a genuine popup can normally be moved beyond the boundaries of the original browser window. A fake BitB window remains trapped inside the phishing page.
Attackers Can Steal MFA Codes Too
Multi-factor authentication does not automatically stop this particular phishing flow.
According to Island’s research, a human operator can control what the victim sees after entering their credentials.
The phishing platform allows operators to request:
- Additional password attempts
- SMS verification codes
- Authenticator app codes
- Google approval prompts
- QR verification
- Tap-number verification
- Okta push approvals
- Okta authenticator codes
The attacker can even reject a valid-looking code and ask the victim to submit another one.
This gives the operator time to use the stolen credentials against the legitimate service while the victim remains on the phishing page.
Human Operators Control the Attack in Real Time
The operation is more advanced than a static credential-harvesting page.
Researchers found that the backend uses a state-based system that allows attackers to monitor victims and decide what authentication step should appear next.
The platform can store multiple password attempts and collect device information such as IP address, approximate location, screen characteristics, and browser-related details.
Commands are transmitted using Socket.IO, allowing the operator to interact with the victim’s session in real time.
This human-controlled design makes the phishing flow adaptable.
If the victim receives an authenticator challenge, the attacker can request the authenticator code. If Google shows an approval request instead, the operator can switch the fake page to a matching prompt.
Fake AI Brands Include ChatGPT, Gemini, Claude and Perplexity
The attackers created different AI-themed advertising products depending on the brand being impersonated.
Island researchers observed fake platforms associated with:
- ChatGPT
- Google Gemini
- Anthropic Claude
- Perplexity
- Manus
- Meta Muse
Each site used slightly different marketing language while routing victims into essentially the same credential-stealing infrastructure.
For example, a fake ChatGPT product promoted an advertising briefing service, while Gemini-themed pages claimed to support manager accounts and linked clients.
Attackers Quickly Exploited Meta’s Muse Launch
Meta officially introduced its Muse personal AI agent on September 8, 2026.
Just eight days later, researchers observed a fake product called Muse Ads claiming to provide an AI advertising manager for paid media workflows.
The fake service encouraged visitors to connect their advertising accounts.
The speed with which the phishing operation adopted a newly launched AI brand is significant.
Cybercriminals increasingly capitalize on new products while awareness is still low and users may not yet know what official integrations actually exist.
Why Advertising Accounts Are Valuable Targets
Advertising accounts are particularly attractive to cybercriminals because they often have access to stored payment methods and approved advertising budgets.
An agency employee may also manage multiple client accounts from a single identity.
Compromising one account could therefore give attackers access to:
- Advertising budgets
- Stored billing methods
- Multiple client campaigns
- Business manager accounts
- Audience data
- Linked users and administrators
Attackers can use stolen accounts to run fraudulent advertising campaigns or resell access to other cybercriminals.
Account Recovery Can Be More Difficult Than Card Replacement
Researchers warn that simply removing a payment card may not resolve the incident.
After taking over an advertising account, attackers may add their own administrator accounts, alter recovery information, or reduce the legitimate owner’s permissions.
Recovering a compromised agency or advertising manager account can take significantly longer than blocking a payment method.
During that period, unauthorized campaigns may continue to operate.
The Same Phishing Infrastructure Was Used for Other Lures
Island’s investigation found that the AI advertising sites were only one part of a broader operation.
The same infrastructure was also associated with:
- Fake recruitment sites
- Refund pages
- Payment confirmation pages
- Business verification pages
Researchers linked the campaigns through shared backend infrastructure, API endpoints, frontend technology, and control mechanisms.
Many of the observed pages used Vercel-hosted frontends combined with Railway or Render backend services.
Misconfigured GitHub Repositories Exposed Older Attack Code
The researchers were able to investigate the phishing infrastructure in greater detail because operators accidentally exposed older source code in public GitHub repositories.
The leaked code revealed similarities between AI-themed phishing sites and older recruitment campaigns.
This allowed researchers to trace parts of the operation further back and understand how the same phishing framework was being reused across different themes.
Researchers Saw Hundreds of Victim Submissions
Island reported observing hundreds of victim submissions reaching the platform’s Telegram-linked control infrastructure.
However, that number should not be interpreted as the number of confirmed compromised accounts.
A submission may represent an interaction with the phishing platform rather than a successful account takeover.
The campaign was still active at the time the research was published.
How to Spot a Browser-in-the-Browser Attack
A convincing fake login window can be difficult to identify visually, but there are several warning signs.
- Check the real browser’s address bar rather than the URL displayed inside a popup.
- Try moving the authentication window outside the main browser window.
- Be cautious when an unfamiliar AI tool requests access to advertising accounts.
- Verify new integrations through the vendor’s official website.
- Avoid logging in through unexpected links sent by email or messaging platforms.
If the apparent popup cannot move outside the original page, it may simply be part of the phishing website.
Phishing-Resistant Authentication Provides Better Protection
Traditional SMS or authenticator codes can still be stolen if a victim manually enters them into a phishing page.
Security teams should consider phishing-resistant authentication methods such as passkeys and hardware-backed security keys for sensitive accounts.
Google states that passkeys and security keys provide stronger protection against phishing because authentication is tied to the legitimate website rather than reusable codes.
What Advertising Teams Should Do
Organizations managing advertising accounts should treat requests from newly launched AI tools with extra caution.
Recommended steps include:
- Verify AI integrations through official vendor websites.
- Use passkeys or hardware security keys where available.
- Limit administrator access to advertising accounts.
- Review newly added managers and partners regularly.
- Monitor unexpected campaign and spending changes.
- Remove unknown administrators immediately.
- Review recovery email addresses and phone numbers after suspected compromise.
- Do not approve unexpected MFA prompts.
What to Do If You Entered Credentials on a Fake AI Site
If you believe you entered credentials or MFA codes into one of these fake sites, act quickly.
- Change the affected account password from a trusted device.
- Sign out or revoke existing sessions.
- Review MFA and passkey settings.
- Remove unknown devices and recovery methods.
- Review advertising account administrators and partners.
- Check recent campaign activity and spending.
- Notify connected clients if their accounts may have been accessible.
Frequently Asked Questions
Are ChatGPT and Gemini themselves stealing advertising accounts?
No. The campaign uses fake websites and products that impersonate legitimate AI brands. The real ChatGPT, Gemini, Claude, Perplexity, and Muse services are not described as being responsible for the phishing operation.
What are fake ChatGPT Gemini sites?
They are phishing sites designed to look like AI advertising products associated with trusted brands such as ChatGPT and Gemini.
What information can attackers steal?
The phishing platform can collect passwords, MFA codes, device information, and potentially access advertising or business accounts connected to the stolen identity.
Can MFA stop this attack?
Traditional one-time MFA codes may still be stolen if the victim enters them into the fake authentication window. Phishing-resistant methods such as passkeys or hardware security keys provide stronger protection.
What is Browser-in-the-Browser phishing?
Browser-in-the-Browser phishing creates a fake login popup inside a malicious webpage, making it appear as though the victim is signing in through a trusted service.
Which AI brands were impersonated?
Researchers observed phishing pages impersonating ChatGPT, Gemini, Claude, Perplexity, Manus, and Meta Muse.
Who is being targeted?
The campaign primarily targets advertising agency employees, media buyers, account managers, and administrators who may have access to multiple advertising accounts.
Final Takeaway
The fake ChatGPT Gemini sites campaign demonstrates how cybercriminals are using the rapid growth of AI products to make phishing attacks more believable.
Rather than sending victims directly to an obvious fake login page, the attackers create realistic AI advertising platforms and wait until users voluntarily connect valuable accounts.
The combination of Browser-in-the-Browser phishing, real-time human operators, and MFA interception makes the campaign especially dangerous for advertising professionals and agencies managing multiple client accounts.
The safest approach is to verify every new AI integration through the vendor’s official website and use phishing-resistant authentication wherever possible.
Stay Updated on Cybersecurity Threats
Cybercriminals are increasingly impersonating trusted AI platforms, cloud services, and business tools to steal credentials and gain access to high-value accounts.
Follow CyberUpdates365 for verified cybersecurity news, phishing research, AI-related threats, vulnerability analysis, and practical security guidance.
Official and Primary Sources
Island Security Research:
Behind the Connect Button: The Fake AI Ads Campaign
Meta Muse Announcement:
Meta’s official Muse announcement
Google Account Security:
Google guidance for protecting accounts from phishing




