Island and BleepingComputer documented a human-operated phishing platform that impersonates advertising products for ChatGPT, Gemini, Claude, Perplexity, and Manus. The pitch is a weekly ads brief, a spend audit, or an account connection. The Connect button does not open Google. It draws a fake browser window inside the page, complete with an address bar that shows accounts.google.com, and a live operator collects the password and the MFA code.
What happened
This is a browser-in-the-browser kit, not a transparent reverse proxy. The page rebuilds the provider login locally and sends credentials and MFA state to its own API over Socket.IO. Operators can ask for the password up to three times, request an SMS or authenticator code, push an Okta or Google approval, show a QR code, or reject a code and hold the victim on a waiting screen.
The newest lure, Muse Ads, appeared by 16 September, eight days after Meta announced Muse. Meta's Muse is not an advertising-account product. The attackers invented that link. Island traced the kit to misconfigured GitHub repos going back to March, and to a Telegram channel that had received hundreds of victim submissions. Supported sign-in flows include Google, Meta, TikTok, and Okta.
Who is affected
- Agency staff, media buyers, and admins whose ad accounts reach downstream clients.
- Anyone asked to connect Google, Meta, TikTok, or Okta to a new AI ads tool they did not procure.
- Organizations that treat an ad-account compromise as a marketing problem rather than an identity incident. Stolen accounts get used to spend balances or get resold.
What to do now
Tell anyone who buys ads: a real Google or Okta prompt is a separate window you can drag outside the browser. A window you cannot move is the phish. Do not enter a password or an MFA code into a Connect flow on a site you did not already use.
If someone already connected an account, revoke the session, reset the password, and review ad-account changes and spend from that hour. Check Okta and Google logs for a new sign-in from an unfamiliar app, not just a failed password. Phishing-resistant MFA still helps, but a push the user approves inside the fake flow does not.
Source: BleepingComputer, 6 October 2026, citing Island. https://www.bleepingcomputer.com/news/security/fake-chatgpt-gemini-sites-steal-advertising-accounts-mfa-codes/
Also on the blog
- FortiMail CVE-2026-104286 (CVSS 9.8) file-write zero-day
- CVE-2026-88779 crashes SAML NetScaler, patch by 7 October
- Atlassian CVE-2026-21589: unauthenticated file access, CVSS 9.3
- Exchange CVE-2026-96940: signed-in users can read other mailboxes
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.