Security researchers have documented a phishing campaign that exploits trust in major AI platforms by impersonating their advertising and business-account management portals. The operation targets users of ChatGPT, Google Gemini, Anthropic Claude, Perplexity, Meta Muse, and other services through fake campaign-management interfaces designed to appear legitimate.
How the Phishing Infrastructure Works
The campaign operates a convincingly designed platform that mimics official AI vendor ad dashboards. Targets are typically directed to these sites through phishing emails or compromised redirect chains, often using urgent language around account verification, billing issues, or campaign optimisation opportunities. Once on the fake portal, users enter their credentials—email address and password—and are prompted to authenticate using multi-factor authentication (MFA). The attackers capture the MFA code as well, giving them full account access regardless of whether the target has enabled MFA.
This two-stage credential capture is critical to the attackers' effectiveness. Many security-conscious users assume MFA protects them against credential theft, but this campaign demonstrates that interception at the point of MFA entry nullifies that protection. The attacker gains not just the credentials but also a valid MFA token, allowing immediate lateral movement into the target account.
Business Account Compromise and Lateral Movement
The primary targets appear to be business or enterprise accounts associated with legitimate organisations. Once an attacker controls a business account with an AI advertising platform, several attack vectors open: they can modify billing information and payment methods, access spending data and campaign performance metrics that may reveal business strategies, pivot to other connected services (often linked via OAuth or SSO), or simply maintain persistence for long-term intelligence gathering.
For organisations operating multiple AI services across a single identity provider or SSO realm, compromise of one account can lead to cascade compromise of others. This is especially relevant for larger firms using enterprise single sign-on, where a unified credential set unlocks multiple systems. Attackers can use hijacked accounts to enumerate the organisation's broader cloud estate and identify higher-value targets.
Why Business Users Are Vulnerable
The phishing campaign succeeds because it exploits several trust assumptions. Business users are accustomed to managing multiple SaaS accounts and platforms, making them less suspicious of authentication prompts for AI ad services. The domains used in the campaign are often visually similar to legitimate URLs, relying on typosquatting or homograph variants. Email delivery is typically personalised and references real business activities—budget reviews, campaign performance, or account security alerts—that create plausible urgency.
Additionally, many users do not routinely verify the URL bar before entering credentials, especially on mobile devices where the address bar is partially hidden. The fake portals are hosted on infrastructure that may evade basic reputation filtering if it's newly provisioned or uses legitimate hosting providers that lack aggressive credential-theft detection.
Defensive Measures
Organisations should implement several controls to reduce the risk of falling victim to this type of attack. Use dedicated credential managers that refuse to autofill credentials on domains not explicitly whitelisted, reducing the likelihood of accidental entry on a fake site. Enable security keys (hardware-based MFA) rather than time-based or SMS codes; security keys bind authentication to the legitimate domain and cannot be intercepted during phishing attacks.
For infrastructure and security teams, consider implementing email authentication standards (DMARC, SPF, DKIM) to prevent spoofing of internal or trusted external senders. User training should emphasise verifying the full domain in the address bar before entering credentials, and business processes should include periodic credential audits to detect anomalous access patterns in AI platform accounts.
Finally, organisations should assume that any account with API access, billing permissions, or data-export capabilities is a high-value target and apply stricter controls—such as requiring approval workflows for sensitive changes or enforcing step-up authentication for administrative actions.
The campaign illustrates a persistent reality in security: even mature platforms with built-in MFA can be compromised through user-facing phishing attacks that intercept credentials before authentication systems can validate them. The most effective defence remains layered—strong authentication protocols, user training, and architectural assumptions that any single credential set might be compromised.
