Fake ChatGPT and Gemini ad portals steal Google and Okta MFA codes
Browser-in-the-browser phishing against ad account admins

Fake ChatGPT and Gemini ad portals steal Google and Okta MFA codes

Island researchers disclosed a human-operated phishing platform that impersonates advertising tools for ChatGPT, Gemini, Claude, Perplexity, Manus, and a fake Muse Ads product. The goal is the password and the MFA code for Google, Meta, TikTok, and Okta, not a malware drop.

What happened

Each fake product is built around a Connect button. Clicking it opens a browser drawn inside the real browser. The fake address bar shows a trusted origin such as accounts.google.com or an Okta tenant. The real browser never leaves the phishing domain. That is the browser-in-the-browser trick.

Behind the page, the kit stores every password attempt, fingerprints the device, and lets a live operator choose which MFA challenge the victim sees next. One lure, museads.ai, appeared on 16 September 2026, a little over a week after Meta launched Muse. Island says victims are steered in by invitation emails that impersonate the brands.

The same platform also runs Google Ads refund lures and recruitment sites posing as Tesla, Louis Vuitton, Nike, and Adecco. The sites share a Next.js and Socket.IO stack. Earlier source was left in misconfigured public GitHub repositories.

Who is affected

The ad-portal track targets agency staff, media buyers, and people who administer manager accounts. A stolen ads account with a clean spend history is resale stock. Attackers typically add their own administrators and downgrade the real owner. Recovery can take weeks, and a manager account spreads the damage to the agency's clients.

What to do now

  • Treat any email that asks you to connect an ad account to a new AI tool as hostile until the domain is confirmed with the vendor, not with the link.
  • Require phishing-resistant MFA, such as a hardware key, on Google and Okta accounts that can spend ad budget or administer a tenant.
  • Review recent admin additions and billing changes on Google Ads, Meta, and TikTok manager accounts.
  • Warn staff that a lock icon inside a popup is not the browser address bar.

Source: The Hacker News, citing Island researchers Oleg Zaytsev and Ofek Ronen. Fake ChatGPT, Gemini, and Claude ad portals capture credentials and MFA codes.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

Ninja Forms CVE-2026-94504 exploited on a plugin used by 500,000 sites
WordPress stored XSS plants a hidden administrator