Researchers have reported a phishing operation using fake advertising portals branded around prominent AI products, including ChatGPT, Claude, and Gemini. The lures promise advertising or campaign-management features, then direct targets to spoofed authentication flows designed to capture passwords and multi-factor authentication codes.
The reported operation uses browser-in-the-browser techniques, where a fraudulent window is drawn within the real browser and presents a trusted-looking address bar or sign-in destination. This can make ordinary visual checks less reliable, particularly when a target is expecting an account-connection workflow.
Organizations should remind staff to validate the browser’s actual origin before entering credentials, use phishing-resistant authentication where possible, and monitor for newly registered lookalike domains and suspicious OAuth or account-connection prompts. Brand-themed phishing should be treated as an identity-security problem, not merely a marketing issue.
Source: Cyber Security News report on the fake AI advertising portals
