Fake AI Ad Tool Phishing: How Attackers Steal Ad Accounts and MFA Codes

AI-powered advertising tools are becoming popular with businesses, agencies and freelancers looking for easier ways to manage campaigns. But attackers are now using fake AI advertising portals that imitate well-known services such as ChatGPT, Gemini and Claude to trick users into handing over their login details.

In a recently reported phishing campaign, victims are directed to websites that promise advertising optimisation or campaign audits. A “Connect” button opens a convincing fake login window using a technique called browser-in-the-browser. The window can display a trusted-looking address while actually being controlled by the phishing website. Passwords entered into the page can be captured, and attackers may attempt to use them immediately.

The campaign is particularly concerning because even MFA codes can be stolen when users enter them into a fake login page. For Indian businesses, advertising agencies, start-ups and freelancers managing Google, Meta or other business accounts, an account takeover could result in unauthorised advertising spend, changes to account settings, loss of campaign data and reputational damage. There is no indication that the reported campaign specifically targeted Indian users, but the lure is relevant to this audience.

Fake Claude Code Installer Spreads Fileless .NET Infostealer via SEO PoisoningFake Claude Code Installer Spreads Fileless .NET Infostealer via SEO Poisoning

Users should avoid signing in through unfamiliar pop-ups or links and instead open the official service directly in a new browser tab. Where available, passkeys or security keys provide stronger protection against phishing than passwords and one-time codes. Businesses should also restrict administrator access, regularly review account users and billing settings, and enable alerts for unusual activity. If credentials have already been entered on a suspicious page, change the password, revoke unknown sessions and contact the affected platform immediately.

Phishing attacks rely on making fraudulent websites look trustworthy. Net Protector’s Total Security includes anti-phishing protection for home users, while Corporate Web Control can help businesses control access to harmful websites. These protections can add another layer of defence, but users should still verify websites before entering passwords or MFA codes.