Fake ChatGPT, Gemini and Claude Ad Tools Target Your Login

Fake AI advertising tools lure businesses into counterfeit login windows. Here is what Island researchers found and how to spot the trap.

By O&M COMPANY•
Fake ChatGPT, Gemini and Claude Ad Tools Target Your Login

A tool promising to improve your advertising campaigns could instead be collecting your account credentials. A report published by Island on October 6, 2026 describes a phishing operation impersonating AI advertising products associated with names including ChatGPT, Gemini and Claude.

The research concerns counterfeit third-party pages. It does not establish that the genuine AI services themselves have been breached.

What happens after you click Connect?

According to Island’s investigation, the pages pitch useful business features, then invite visitors to connect an account. The next screen resembles a familiar provider’s sign-in window, but is drawn inside the attacker’s page.

This “browser-in-the-browser” trick can display an apparently reassuring address bar. The important address is still the one belonging to your actual browser, outside the imitation window.

Why a verification code may not protect you

The researchers describe human operators guiding victims through password and multi-factor authentication requests in real time. A code entered into the counterfeit page can therefore be handed to the attacker during an attempted login. A familiar logo or security prompt is not proof that the page is genuine.

Why advertisers are attractive targets

An advertising account can carry budgets, billing access and links to client accounts. For an agency, one compromised identity may therefore have consequences beyond a single campaign.

The Hacker News and TechRadar also reported the findings. The news is about an observed campaign, not a claim that every AI advertising integration is fraudulent.

Before connecting an account

  • Find the product through the vendor’s official website instead of trusting an invitation.
  • Check the real browser address before entering credentials.
  • Do not approve a login request you did not initiate.
  • Where available, use origin-bound passkeys or hardware security keys.

If you submitted information to a suspicious page, open your account provider directly. Review active sessions, recovery settings, advertising administrators and unapproved spending. Alert your organisation’s security team if a work account was involved.

Published October 7, 2026. Featured image is an AI-generated symbolic illustration, not an actual phishing-page screenshot.

Event date:

Sources

Related news