Fake AI Ad Portals Steal Credentials and MFA Codes

Fake AI Ad Portals for ChatGPT, Gemini, Claude, Perplexity, Meta Muse, and Manus do not begin with an obvious threat. They arrive dressed as business tools. A visitor sees promises of campaign optimization, advertising audits, budget insights, and account connections. The design feels polished. The language sounds familiar. Somewhere on the page, a bright button says, “Connect.”

That button changes the scene.

Cybersecurity researchers recently described a human operated phishing platform that copies advertising products linked to popular AI services. The operators built each portal around the same objective: capture account credentials and multi factor authentication codes.

The deception depends on a trick called browser in the browser. It creates a convincing login window inside the real browser window. The imitation includes a familiar address bar, perhaps showing accounts.google.com or an Okta tenant. Yet the genuine browser still points to the criminal website. The eye sees one thing. The browser knows another.

That difference matters because many people treat the address bar as a verdict. It is not. A padlock does not certify a company’s honesty, and a familiar logo does not prove that a login window belongs to Google, OpenAI, Anthropic, or any other provider. In this case, the attacker draws the evidence of trust directly onto the screen.

The operator does more than collect a password. The platform records each attempt, fingerprints the device, and chooses which MFA prompt the target sees next. That detail turns a static scam into a live performance. Someone watches from the other side, adjusts the script, and waits for the moment when the target grows impatient.

That human element deserves attention. Security teams often describe phishing as an automated numbers game, and much of it is. This campaign adds a person behind the curtain. The criminal can respond when a user enters a code, requests another prompt, or hesitates at an unfamiliar step. The victim experiences a smooth support journey. The operator experiences a stream of decisions.

One portal, identified in the research as museads.ai, appeared shortly after Meta introduced its Muse product. Timing gives the scheme an extra advantage. New services create curiosity, and curiosity lowers the guard. People search for ways to connect an account before security guidance catches up.

Why familiar MFA still cannot carry the whole burden

Multi factor authentication remains essential, but it cannot rescue every poorly timed decision. If a user types a password into a fraudulent window and then supplies the requested code, the criminal may pass both checks. MFA confirms that the attacker obtained the second factor. It does not confirm that the user visited the right website.

That distinction creates one of the central challenges for the CISO in the age of AI. Security leaders must protect employees who move quickly between new tools, advertising systems, customer platforms, and experimental services. A company may encourage AI adoption on Monday, approve a new integration on Tuesday, and discover an imitation portal on Wednesday. The business wants speed. The security team inherits the consequences.

A seasoned CISO looking at this campaign would likely reject a narrow response that simply tells staff to “be careful.” Awareness matters, but a warning cannot compete with a convincing interface, a plausible business request, and a login prompt that appears at the precise moment a user expects one.

Companies need several sturdier habits.

Employees should open AI services through saved bookmarks or official applications, rather than through advertisements or unfamiliar search results. They should inspect the actual browser address, not the address drawn inside a login window. They should question unexpected requests to connect advertising accounts, especially when a new service has no established relationship with the business.

Security teams can also limit risky browser extensions, monitor unusual sign in activity, and favor phishing resistant authentication methods such as passkeys or hardware security keys. Those controls do not eliminate deception, but they reduce the value of stolen passwords and intercepted codes. A security key, unlike a copied visual address bar, can recognize the genuine website.

The wider criticism concerns the AI industry itself. Every new product expands the vocabulary that criminals can imitate. Companies launch names, logos, dashboards, and connection flows at remarkable speed, while users receive little help distinguishing an official service from a clever counterfeit. Product teams celebrate frictionless access. Attackers study that same frictionless access as an invitation.

The fake portal succeeds because it does not ask the victim to do something bizarre. It asks for the normal thing, in a setting that looks normal, at a moment that feels productive. That is why the incident matters beyond one campaign. Information security in the age of AI demands more than detecting malicious files or blocking suspicious messages. It requires organizations to question the entire visual language of trust, including the screens employees have learned to obey.

Strengthening Digital Defenses for Competitive Advantage

“Over 50% of organizations have been victims of a ransomware attack.” – CrowdStrike Global Threat Report

Embracing cybersecurity best practices is critical for business success in the digital age. By analyzing the strategies of industry leaders in cybersecurity, companies can develop robust defenses without excessive expenditure. However, it’s vital to adapt these strategies to your unique business needs, as copying them without consideration can lead to vulnerabilities and compliance issues.

Some essential points to remember:

  1. Verify the destination before signing in. Use bookmarked vendor URLs, inspect the domain carefully, and avoid sponsored search results or unsolicited “AI tool” links.
  2. Use a password manager. It will generally refuse to autofill credentials on look-alike domains, limiting credential reuse and automated capture.
  3. Prefer phishing-resistant MFA. Deploy passkeys or hardware security keys. Treat emailed or SMS-delivered codes as vulnerable; never disclose them to a prompt, caller, or webpage.
  4. Strengthen endpoint and web controls. Block malicious advertising, enforce DNS and browser filtering, restrict unauthorized AI portals, and keep browsers and security tools updated.
  5. Prepare for rapid containment. Monitor sign-ins, revoke active sessions, rotate exposed passwords, disable compromised tokens, and report fraudulent domains immediately.

How these lessons connect: Together, they apply Securing Success in a Digitally Driven World through identity protection, Navigating Cyber Threats for Sustainable Growth through layered prevention, and Building Resilience in the Age of Digital Transformation through detection, recovery, and organizational readiness.

From the Author

The cybersecurity landscape is evolving rapidly, with new threats emerging daily. This compounding problem is a call to action for the cybersecurity community to unite in developing innovative solutions and sharing critical threat intelligence.

I endeavor to curate stories like this one on my website. This serves a dual purpose: firstly, to provide a valuable reference for my writing endeavors, and secondly, to share insightful narratives with the wider community. If you like this story, you should check out some of the other stories in the Management section or Small Business section.
You can also find more of my Cybersecurity writings here in the Cybersecurity section.

To check the original story Click here

Stay Up-to-date
Stay informed on the latest cybersecurity strategies and tools, check out Google Cybersecurity Certification.

Cyber-V2

Mani

A seasoned professional in IT, Cybersecurity, and Applied AI, with a distinguished career spanning over 20+ years. Mr. Masood is highly regarded for his contributions to the field, holding esteemed affiliations with notable organizations such as the New York Academy of Sciences and the IEEE – Computer and Information Theory Society. His career and contributions underscores his commitment to advancing research and development in technology.

Mani Masood

A seasoned professional in IT, Cybersecurity, and Applied AI, with a distinguished career spanning...