// AI threat desk · 7 Oct 2026
Home/AI-ATK · AI-Powered Attacks
AI-Powered AttacksMediumMFACVSS not assigned

Fake AI advertising platform used browser-in-browser phishing

Island disclosed on Oct 6 a human-operated phishing platform disguised as AI advertising products, impersonating Gemini, Claude, ChatGPT and Perplexity and later adding Muse Ads.

AI-generated image of a security analyst examining fake AI login pages on blurred monitors.
AI-generated image, not a photo of the event.
Key takeaways
  • Clicking Connect opened a fake browser inside the real browser while the real browser stayed on the phishing domain.
  • The platform kept every password attempt, fingerprinted devices and let operators choose the next MFA challenge.
  • Island saw hundreds of victim submissions while the campaign remained active at the time of writing.

Island said on Oct 6 that its security research uncovered a human-operated phishing platform disguised as AI advertising products. The platform impersonated Gemini, Claude, ChatGPT and Perplexity, later adding Muse Ads.

The lures were written for agency staff, media buyers and manager-account administrators, because an advertising account is a spending account. Behind the interface, the platform kept every password attempt, fingerprinted the device and let an operator pick which MFA challenge the victim saw next.

The fake products offered campaign optimization, spend audits and business-account connections. Island observed hundreds of victim submissions, and said the campaign was still active when its researchers wrote their report.

On this page

The fake login window hid the phishing domain

Clicking Connect opened a browser drawn inside the real browser. Its fake address bar displayed trusted origins such as accounts.google.com or an Okta tenant, while the real browser remained on the phishing domain.

BleepingComputer reported that fake ChatGPT, Gemini, Claude and Perplexity sites targeted advertising-account managers and captured login credentials and MFA codes through browser-in-browser pages.

Muse Ads appeared on Sep 16

Island said museads.ai was presenting Muse Ads by Sep 16, describing it as “Your AI ads manager for paid media workflows.” The site claimed it could help advertisers reach buyers, connect an advertising account and run sponsored placements.

Eight days after Meta launched Muse, operators added the fake Muse Ads product to the platform that already impersonated Gemini, Claude, ChatGPT and Perplexity.

The Hacker News said the identified websites shared a Next.js and Socket.IO technology stack and communicated with the same endpoints. The publication also said organizations are recommended to enable phishing-resistant authentication, review advertising-control changes and scrutinize AI integrations before connecting accounts.

Mimecast has tracked 6.4 million detections of systematic Meta Business Manager and Google Ads account theft over four years.

What to do now

  1. Enable phishing-resistant authentication, review advertising control changes, and scrutinize AI integrations before connecting accounts.

FAQ

What happened in the fake AI advertising product campaign?

Island said it uncovered a human-operated phishing platform disguised as AI advertising products. The platform impersonated Gemini, Claude, ChatGPT and Perplexity, then added Muse Ads.

Who was targeted by the phishing platform?

The lures were written for agency staff, media buyers and manager-account administrators, because an advertising account is a spending account.

How did the browser-in-the-browser pages work?

Clicking Connect opened a fake browser inside the real browser. The fake address bar showed trusted origins while the real browser stayed on the phishing domain.

What information did the phishing platform collect?

It retained every password attempt, fingerprinted the device and let an operator choose which MFA challenge the victim saw next.

When did the fake Muse Ads product appear?

Island said museads.ai was presenting Muse Ads by Sep 16, claiming to help advertisers reach buyers, connect an advertising account and run sponsored placements.

Sources

  1. Behind the Connect Button: The Fake AI Ads Campaign, IslandPrimary
  2. Ad Account Theft | Mimecast, MimecastPrimary
  3. Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes, The Hacker News
  4. Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes, BleepingComputer
How we checked this story
ClaimSourceStatus
Island security research uncovered a human-operated phishing platform disguised as AI advertising products.IslandConfirmed
The platform impersonated advertising products for Gemini, Claude, ChatGPT and Perplexity, and later added Muse Ads.IslandConfirmed
The phishing products offered campaign optimization, spend audits and business-account connections.IslandConfirmed
Clicking Connect opened a fake browser inside the real browser while the real browser remained on the phishing domain.IslandConfirmed
The platform retained password attempts, fingerprinted devices and let operators choose which MFA challenge victims saw next.IslandConfirmed
Muse Ads appeared on 16 September 2026 and claimed to help advertisers reach buyers, connect accounts and run sponsored placements.IslandConfirmed
Island observed hundreds of victim submissions, and campaign activity was ongoing when researchers wrote their report.IslandConfirmed
The Hacker News said the websites shared Next.js and Socket.IO technology and communicated with the same endpoints.The Hacker NewsAttributed
BleepingComputer reported that fake ChatGPT, Gemini, Claude and Perplexity sites targeted advertising-account managers and stole credentials and MFA codes.BleepingComputerAttributed
Mimecast has tracked 6.4 million detections of systematic Meta Business Manager and Google Ads account theft over four years.MimecastConfirmed
island.io published its report on Oct 6, 2026.island.ioConfirmed

Could not verify

  • Whether the campaign successfully compromised any advertising accounts is not established
  • How many victims had credentials or MFA codes stolen is not established
  • Whether the campaign was exploited in the wild beyond the reported submissions is not established
Explore with AI