Fake ChatGPT and Gemini sites target ad managers with advanced credential theft
A sophisticated phishing campaign uses spoofed AI platform websites to steal login credentials and MFA codes from ad account managers.

According to BleepingComputer, a new threat campaign targeting advertising account managers is utilizing fake websites disguised as popular AI tools like ChatGPT, Gemini, Claude, and Perplexity.
The attacks rely on browser-in-browser phishing techniques, which skillfully mimic authentic login prompts to capture victims' credentials and multi-factor authentication (MFA) codes.
The primary targets of this campaign are digital marketing professionals who manage sensitive ad accounts and corporate budgets.
Security experts advise users to double-check domain names and rely strictly on official application portals to prevent falling victim to these convincing scams.
This campaign highlights the growing sophistication of social engineering tactics targeting tech professionals globally, emphasizing the need for robust endpoint security.



