Phishing campaign uses fake AI ad tools to steal credentials
Researchers report a phishing operation targeting digital advertising professionals through counterfeit AI tools like ChatGPT, Gemini, Claude, and Muse. The attackers use fake login windows within a browser to trick victims into providing credentials and multi-factor authentication codes. These attacks let criminals gain access to ad accounts, enabling fraudulent ad spending or further resale. The platforms claim to help with ad campaigns and optimization, luring victims to connect their business accounts.
- Targets ad agencies and media buyers with fake AI ad tools
- Uses in-browser phishing windows to steal credentials
- Attackers obtain MFA codes to bypass security layers
- Stolen accounts can be used for fraudulent ad campaigns
- Part of a larger, ongoing phishing operation
Sources covering this
In this story
More in Cybersecurity
Hackers send extortion message through ASOS app
Hackers took control of ASOS's app notification system and sent a message to users claiming to have breached the company's Snowflake…
ClickFix attacks use browser cache to smuggle payloads
A recent ClickFix campaign is hiding malicious Visual Basic scripts disguised as image files in browser caches on victims' devices,…
Nikkei reveals breaches of employee email accounts
Japanese media group Nikkei disclosed that two employee cloud email accounts were breached in separate incidents this year.
Oracle Health breach exposed data of nearly 20 million
A cyberattack on Oracle Health in early 2025 exposed sensitive data belonging to nearly 20 million people, according to the Texas…