Fake AI Advertising Platforms Are Turning Trust Into a Credential Theft Weapon

Artificial intelligence is rapidly becoming part of everyday business operations.

Marketing teams, advertising agencies, media buyers, and business administrators are increasingly using AI platforms to analyze campaigns, optimize advertising spend, connect accounts, and automate workflows.

Cybercriminals are now exploiting that familiarity.

A recently identified phishing campaign is using fake versions of popular AI services such as ChatGPT, Google Gemini, Anthropic Claude, Perplexity, Manus, and Meta Muse to target advertising professionals and steal account credentials and multi-factor authentication information. Researchers found that the campaign uses convincing AI advertising portals and browser-in-the-browser techniques to make fraudulent login pages appear legitimate.

The campaign demonstrates an important shift in modern phishing:

Attackers are no longer simply impersonating banks or email providers. They are impersonating the AI tools businesses increasingly trust.

Why AI Brands Are Becoming Attractive Phishing Targets

AI platforms have quickly become recognizable business brands.

Employees may already be familiar with ChatGPT, Gemini, Claude, Perplexity, and other AI services. That familiarity creates an opportunity for attackers.

Instead of sending a generic phishing email, attackers can create a convincing business scenario around an AI powered advertising product.

The fake platforms identified by researchers presented services such as:

• Advertising campaign optimization
• Campaign planning
• Advertising spend analysis
• Business account connections
• Customer targeting
• Marketing automation
• AI assisted advertising management

The objective was to convince users that connecting their advertising accounts would provide additional functionality.

Once users attempted to connect an account, the phishing process began.

The Browser in the Browser Problem

One of the most concerning techniques used in the campaign is known as Browser in the Browser, or BitB.

The technique creates a fake authentication window inside the legitimate browser window.

The fraudulent window can be designed to resemble a genuine Google, Okta, or other authentication interface, including an address bar that appears to show a trusted domain.

This can make it difficult for users to distinguish the fake login window from a legitimate authentication process.

The browser itself may still be displaying the attacker’s website in the background.

That distinction is extremely important.

A user may believe they are entering credentials into an official authentication service when they are actually interacting with a fraudulent interface controlled by an attacker.

Researchers from Island found that the campaign was designed to capture credentials and then interact with victims in real time during the authentication process.

MFA Does Not Automatically Stop This Attack

Multi-factor authentication remains one of the most important security controls available to organizations.

However, the campaign demonstrates why organizations should distinguish between traditional MFA and phishing resistant authentication.

The attackers were reportedly able to request different authentication challenges during the phishing process, including:

• SMS verification codes
• Authenticator codes
• Push notifications
• Google approval prompts
• QR based authentication flows

A victim who provides a valid authentication code to a fraudulent website may unintentionally give an attacker the information required to complete an authentication attempt.

This means that simply having MFA enabled does not guarantee protection against sophisticated phishing.

Organizations should increasingly consider phishing resistant authentication technologies such as FIDO2 and WebAuthn based security keys and passkeys.

The Real Target May Be the Advertising Account

The campaign appears to be particularly focused on advertising professionals and administrators.

This makes financial sense for attackers.

Advertising accounts can have significant financial value because they may contain:

• Payment methods
• Advertising budgets
• Established account histories
• Client relationships
• Campaign information
• Business identities
• Trusted domains
• Access to multiple client accounts

A compromised advertising account can potentially be abused to launch unauthorized campaigns or can be monetized through underground markets.

For agencies and organizations managing multiple advertising accounts, the consequences can extend beyond a single compromised employee.

A single administrator account may provide access to multiple customer or client environments.

Agencies Face a Larger Blast Radius

Advertising agencies can represent a particularly attractive target.

An employee responsible for managing campaigns may have access to several customer accounts.

If that employee’s credentials are compromised, attackers may gain access to more than one organization’s advertising environment.

This creates a supply chain style security problem.

The initial victim may be an employee at an agency, but the potential consequences can reach:

• Multiple clients
• Multiple advertising accounts
• Customer budgets
• Payment information
• Campaign data
• Business analytics
• Brand reputation

Organizations should therefore treat privileged advertising accounts as sensitive business assets.

Attackers Are Adapting Their Lures Quickly

The campaign also demonstrates how quickly cybercriminals can adapt their phishing infrastructure to new technology trends.

Researchers observed a fake Muse advertising product appearing shortly after Meta introduced its Muse AI agent.

Other fake platforms were designed around established AI brands and advertising concepts.

This demonstrates a broader pattern in modern social engineering.

Attackers monitor technology trends and rapidly build new lures around products that users recognize.

Today the lure may be an AI advertising assistant.

Tomorrow it could involve an AI coding tool, enterprise AI agent, productivity assistant, security platform, or another emerging technology.

Security awareness programs therefore need to teach employees how to identify suspicious behavior rather than relying only on lists of known phishing brands.

The Campaign Is Larger Than AI Advertising

Researchers also identified other phishing themes connected to the broader infrastructure.

These included:

• Advertising refund claims
• Payment confirmation pages
• Recruitment related websites
• Brand impersonation campaigns

This suggests that the underlying infrastructure is not limited to AI advertising.

Instead, AI brands appear to be one of several themes that can be used to attract victims.

This is another important lesson for security teams.

Defensive monitoring should focus on attacker infrastructure, authentication behavior, domain reputation, identity anomalies, and suspicious workflows rather than simply blocking individual phishing websites.

AI Impersonation Creates a New Social Engineering Challenge

AI has changed how people interact with technology.

Employees may now expect software to provide natural language assistance, automated recommendations, account connections, and intelligent workflows.

Attackers can exploit those expectations.

A fraudulent AI service can appear more believable because users already expect AI products to request access to other applications.

For example, an employee may not immediately question why an AI marketing platform wants to connect to a Google Ads or Meta account.

That makes authorization requests an important part of security awareness.

Employees should ask:

• Why does this application need access?
• Is the service officially provided by the organization?
• Does the domain belong to the legitimate provider?
• Is the integration expected?
• Who approved the integration?
• What permissions are being requested?
• Can the same task be completed through the official platform?

Organizations Should Move Toward Phishing Resistant Authentication

One of the strongest defensive lessons from this campaign is the importance of phishing resistant authentication.

Traditional passwords and one time authentication codes can be vulnerable to phishing and real time interception.

Organizations should consider adopting:

• FIDO2 security keys
• WebAuthn authentication
• Passkeys
• Strong identity verification
• Conditional access policies
• Device trust controls
• Privileged access management
• Risk based authentication

The objective should be to make stolen credentials less useful to attackers.

Protect Privileged Advertising Accounts

Organizations should also treat advertising platforms as critical business systems.

Security teams should review:

• Administrator accounts
• User permissions
• Agency access
• Client account relationships
• Payment permissions
• API access
• Connected applications
• OAuth integrations
• Authentication methods
• Recent account changes

Access should follow least privilege principles.

Employees who only need campaign management capabilities should not automatically receive administrative privileges.

Monitor Changes After Authentication

Credential theft is only the beginning of the attack.

Organizations should monitor what happens after authentication.

Security teams should look for:

• New administrators
• Unexpected permission changes
• New payment methods
• Unusual campaign activity
• Suspicious geographic access
• New devices
• Unexpected OAuth applications
• Unusual API activity
• Changes to account recovery settings
• Large changes in advertising spend

Behavioral monitoring can help detect account takeover even when attackers successfully authenticate.

Marketing and Security Teams Need to Work Together

Cybersecurity programs sometimes focus heavily on technical teams while overlooking departments that control significant financial and digital assets.

Marketing teams, advertising agencies, finance teams, and business administrators can have access to valuable accounts.

Security awareness should therefore be tailored to their workflows.

Training should include realistic scenarios involving:

• Fake AI platforms
• Advertising account phishing
• Fraudulent account connection requests
• Browser in the Browser attacks
• MFA manipulation
• Fake collaboration invitations
• Malicious OAuth applications
• Social engineering

Security training is more effective when it reflects the systems employees actually use.

Industries Most Exposed
Advertising and Marketing Agencies

Agencies are among the most directly exposed because employees may manage multiple customer advertising environments.

COE Security can help agencies assess identity controls, privileged accounts, SaaS integrations, cloud environments, APIs, and application security while improving phishing resilience.

Financial Services and Banking

Financial institutions face risks involving account takeover, financial fraud, identity compromise, and unauthorized access to sensitive systems.

COE Security can help strengthen identity security, phishing resistance, application security, API security, threat monitoring, and compliance controls.

Retail and E-commerce

Retail organizations rely heavily on digital advertising, customer platforms, payment systems, marketing applications, and cloud services.

COE Security can help secure customer facing applications, advertising integrations, APIs, cloud environments, identity systems, and sensitive customer data.

Healthcare and Life Sciences

Healthcare organizations increasingly use digital marketing, patient platforms, SaaS applications, and connected systems.

COE Security can help protect sensitive information through identity assessments, application security testing, cloud security reviews, data governance, vulnerability management, and compliance aligned security programs.

Technology and SaaS Companies

Technology organizations are frequent targets because employees may have access to source code, cloud platforms, customer information, advertising accounts, and administrative systems.

COE Security can help assess SaaS applications, APIs, cloud environments, identity systems, third party integrations, and AI enabled platforms.

Government and Public Sector

Government organizations also rely on cloud applications, digital communications, advertising platforms, and third party services.

COE Security can help strengthen identity security, cloud security, application security, data protection, vulnerability management, and compliance programs.

What Organizations Should Do Now

The campaign provides several practical lessons for security leaders.

Use phishing resistant authentication.

Where possible, organizations should move beyond passwords and one time codes toward FIDO2, WebAuthn, and passkey based authentication.

Review privileged accounts.

Advertising administrators and other high value accounts should receive additional security controls.

Monitor authentication behavior.

Unexpected login locations, devices, authentication attempts, and permission changes should be investigated.

Control third party integrations.

Organizations should maintain visibility into applications connected to Google, Meta, Microsoft, Okta, and other business platforms.

Monitor account changes.

New administrators, payment changes, unusual campaigns, and unexpected OAuth permissions can indicate account takeover.

Train high risk teams.

Marketing, advertising, finance, sales, and administrative teams should receive targeted phishing awareness training.

Verify AI services before connecting accounts.

Employees should use official applications and independently verify unexpected AI integrations before entering credentials or approving access.

The Bigger Lesson for AI Security

This campaign demonstrates that artificial intelligence is influencing cybersecurity in two different ways.

AI is being adopted as a business technology.

At the same time, AI brands are becoming powerful social engineering tools.

Cybersecurity programs therefore need to protect both the technology and the trust surrounding it.

Organizations should not assume that a familiar AI brand, professional looking interface, or authentication window is proof of legitimacy.

Security teams must increasingly combine identity protection, phishing resistant authentication, behavioral analytics, application security, employee awareness, third party risk management, and continuous monitoring.

Conclusion

The campaign involving fake ChatGPT, Gemini, Claude, Perplexity, Manus, and Muse advertising platforms demonstrates how quickly cybercriminals adapt to emerging technology.

Attackers are using familiar AI brands to create believable business scenarios, while browser in the browser techniques make fraudulent authentication windows appear legitimate.

The objective is not necessarily to attack the AI platforms themselves.

Instead, attackers are exploiting trust in the brands and workflows surrounding AI to steal credentials, MFA information, and valuable advertising accounts.

For organizations, the lesson is clear.

AI adoption must be accompanied by stronger identity security, phishing resistant authentication, least privilege access, third party application controls, continuous monitoring, and targeted employee training.

As AI becomes increasingly embedded in business operations, attackers will continue looking for ways to weaponize familiarity and trust.

Organizations that combine strong technical controls with security awareness will be better positioned to protect identities, financial assets, customer accounts, and sensitive business information.

About COE Security

COE Security partners with organizations in financial services, healthcare, retail, manufacturing, and government to secure AI-powered systems and ensure compliance.

Our offerings include:

• AI-enhanced threat detection and real-time monitoring
• Data governance aligned with GDPR, HIPAA, and PCI DSS
• Secure model validation to guard against adversarial attacks
• Customized training to embed AI security best practices
• Penetration Testing (Mobile, Web, AI, Product, IoT, Network & Cloud)
• Secure Software Development Consulting (SSDLC)
• Customized CyberSecurity Services
• Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption.

In addition, COE Security helps organizations address phishing, identity, AI, and account takeover risks through phishing resilience assessments, identity and access management reviews, privileged access assessments, application security testing, API security testing, cloud security assessments, third party integration reviews, vulnerability management, threat monitoring, security awareness programs, and penetration testing.

For advertising and marketing agencies, COE Security helps assess privileged advertising accounts, identity controls, SaaS integrations, APIs, cloud environments, third party applications, and security awareness processes to reduce account takeover and unauthorized access risks.

For financial services and banking organizations, we help strengthen identity security, authentication controls, application security, API security, fraud related controls, cloud security, threat monitoring, and compliance programs.

For retail and e-commerce organizations, we help secure customer facing applications, payment environments, digital advertising platforms, APIs, cloud infrastructure, identity systems, and third party integrations.

For healthcare and life sciences organizations, we help protect sensitive information through data governance, identity security, application security testing, cloud security assessments, vulnerability management, and compliance aligned cybersecurity programs.

For technology and SaaS companies, COE Security helps assess AI enabled applications, SaaS platforms, APIs, cloud environments, identity systems, third party integrations, and software development environments.

For government and public sector organizations, we help strengthen identity management, cloud security, application security, data protection, vulnerability management, threat monitoring, and compliance controls.

COE Security also helps organizations evaluate emerging AI security risks, including malicious AI impersonation, unsafe AI integrations, prompt injection, AI data exposure, excessive permissions, insecure connectors, and AI enabled social engineering.

Our goal is to help organizations identify security gaps, reduce cyber risk, protect sensitive information and business accounts, strengthen cyber resilience, and maintain compliance across increasingly connected digital environments.

Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption and to stay updated and cyber safe.

Click to read our LinkedIn feature article