Fake AI Ad Portals Target Business Accounts, Steal Credentials and MFA Codes
Advertisers eager to promote their brands through AI chatbots are being funneled into a sophisticated phishing operation that impersonates advertising programs for some of the biggest names in artificial intelligence. According to research published by The Hacker News, the campaign relies on a "human-operated phishing platform" that mimics ad products for Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus.
The fake portals advertise services such as campaign optimization, advertising spend audits, and business-account connections. In reality, every feature is designed to do one thing: convince a victim to hand over login credentials and multi-factor authentication (MFA) codes.
A Convincing Business Pitch
The operation is notable for how closely it mirrors legitimate advertising workflows. Rather than relying on generic login pages, the attackers built portals that promise to help businesses get more value out of their ad budgets. Campaign optimization and spend audits are exactly the kinds of services that marketing teams actively search for, which makes the bait unusually effective.
The phishing pages also offer to "connect" business accounts, a feature that mirrors real onboarding flows used by advertising platforms. Victims who believe they are linking their corporate accounts are instead entering their credentials directly into attacker-controlled infrastructure.
Because the platform is human-operated, attackers can adapt in real time. A live operator can respond to questions, adjust the fake interface, or walk a victim through an MFA prompt, which raises the success rate far above that of automated phishing kits.
Why MFA Codes Are the Real Prize
Stealing a password is no longer enough to compromise a well-defended account. The attackers behind this campaign appear to understand that, which is why their portals are built to capture MFA codes alongside usernames and passwords.
By harvesting both factors in a single session, the operators can attempt to log in immediately, before a time-based one-time password expires. In some cases, a human operator can even relay a push notification or prompt the victim to approve a login in real time.
This approach turns MFA from a hard stop into a speed bump. Organizations that rely solely on SMS or app-based one-time codes remain vulnerable to this style of real-time relay attack.
The Growing AI Advertising Attack Surface
AI chatbots have become a new frontier for digital advertising, and attackers are following the money. As businesses rush to experiment with ads inside ChatGPT, Gemini, Claude, and similar platforms, they are encountering unfamiliar interfaces, unclear account structures, and a shortage of established best practices. That confusion creates ideal conditions for phishing.
Several factors make this campaign stand out:
- Brand trust is borrowed. By invoking well-known AI companies, the attackers inherit the credibility of those brands without needing to compromise them.
- The audience is professional. Targets are likely marketing, growth, and finance staff with access to corporate ad accounts and budgets.
- The lure is financial. Promises of better ad performance appeal directly to teams under pressure to justify spend.
- The operation is interactive. Human operators can tailor the experience to each victim, making the scam harder to detect.
Defensive Lessons for Security Teams
This campaign reinforces several durable security principles. First, MFA alone is not a complete defense. Organizations should prioritize phishing-resistant authentication such as hardware security keys or passkeys, which cannot be relayed by a human operator in the way a one-time code can.
Second, businesses should establish clear, documented processes for how employees access advertising platforms. If staff know that account connections and spend audits only happen through a specific internal workflow, an unexpected portal becomes far less convincing.
Third, monitoring matters. Sudden changes to ad account settings, new payment methods, or unusual login locations can all be early indicators that credentials have been compromised. Security and marketing teams should agree on who watches for those signals and how incidents are escalated.
Finally, user education should move beyond generic "watch out for phishing" messaging. Employees need to understand that attackers now build entire fake products, complete with support interactions, and that urgency and financial incentives are common hooks.
What Comes Next
As AI platforms expand their advertising offerings, copycat campaigns are likely to multiply. The operators behind this phishing platform have already demonstrated that they are willing to invest time in building realistic interfaces and staffing live interactions. Defenders should expect the next iteration to be even more polished.
The most effective response is layered: phishing-resistant authentication, verified access paths, continuous monitoring of ad accounts, and a workforce trained to question unsolicited offers of help with their budgets. The fake portals may look like the future of AI advertising, but the only thing they are optimizing is the attackers' access to corporate accounts.
Source: The Hacker News