What is the scam and why does it matter?
Cybercriminals are exploiting the popularity of AI marketing tools by creating fake websites that impersonate well-known platforms like ChatGPT, Google Gemini, and Claude. These sites target advertisers and marketing managers by offering AI-powered product features as bait, but their true goal is to steal Google business account credentials and multi-factor authentication (MFA) codes.
The stolen accounts often have linked payment methods and approved budgets, giving attackers the ability to misuse advertising funds and access multiple client accounts through manager permissions. This type of attack poses financial and reputational risks to businesses, as compromised advertising accounts can lead to unexpected charges and loss of control over marketing campaigns.
How do these phishing attacks work in detail?
The phishing campaigns use sophisticated tactics, notably the "browser-in-the-browser" (BitB) technique. When a victim tries to log in, the attack displays a fake browser window inside their actual browser. This interface even includes realistic browser elements like an address bar showing legitimate domains, making it difficult for users to detect deceit at a glance.
Additionally, the phishing platform mimics the victim's operating system interface — whether macOS or Windows — to add authenticity. On the backend, scam operators actively monitor the victim’s actions in real-time, deciding what error messages or MFA screens to present, making the attack perfectly tailored and adaptive.
The platform supports multiple authentication workflows, including Google, Meta, TikTok, and Okta, enabling broad-reaching credential harvesting. Victims inadvertently hand over reusable passwords, MFA codes, and session tokens, which give attackers persistent access.
Who is targeted and what is at stake?
The campaign focuses on advertising professionals who manage business accounts with substantial budgets and stored payment methods. Accounts managed by agencies or media buyers are particularly valuable because one account can control several client accounts, each with independent billing profiles.
This access allows attackers to run unauthorized advertising campaigns, siphon funds, or sell access on the dark web. Since advertising accounts undergo rigorous verification, attackers prefer hijacking existing accounts rather than creating new ones, streamlining illicit usage.
What can marketers and businesses do to protect themselves?
Organizations should treat any request to connect AI integrations or tools as a sensitive account-access event. Verify the true origin of login requests by examining not just the visible address bar but all browser elements.
Implementing phishing-resistant authentication methods such as hardware-backed passkeys or security keys greatly reduces the risk, as these methods are less vulnerable to credential interception. Regularly audit advertising accounts for suspicious changes, such as new managers or payment methods, and promptly review campaign approvals and budget spends.
Finally, train staff to recognize advanced phishing attempts and encourage scrutiny of browser windows and login prompts, emphasizing vigilance against fake AI product offers promising simplified workflows.
Clear takeaway for security-conscious advertisers
Fake AI marketing tools represent a new frontier for credential theft targeting advertising professionals. Their sophisticated imitation of real platforms and the use of live operators to navigate MFA demands make them particularly dangerous. The best defense is to assume any unexpected account connection request is potentially malicious, enforce strong authentication controls, and maintain proactive monitoring of your advertising account access and billing information.
Staying alert and adopting phishing-resistant technologies can prevent attackers from exploiting your trusted business accounts and protect your marketing budgets from being drained by criminals masquerading behind AI buzzwords.
