Researchers have identified a large-scale phishing operation deploying fake advertising portals that impersonate legitimate campaign-management interfaces for popular AI chatbot services—including OpenAI's ChatGPT, Google Gemini, Anthropic's Claude, Perplexity, Meta's Muse, and others. The attackers' goal is straightforward: harvest login credentials and multi-factor authentication codes from business account holders, gaining access to high-value AI platform accounts tied to organisations and their billing infrastructure.
How the Phishing Infrastructure Operates
The campaign uses a human-operated phishing platform—not a standard credential-stealing kit. This means attackers are actively managing the fake portals, likely monitoring captured data in real-time and potentially performing live social engineering when targets interact with the pages. The fake portals present themselves as legitimate "ad management" or "campaign optimisation" consoles, surfaces that business users regularly authenticate to when managing paid AI-model API usage or advertising spend.
Attackers typically distribute links to these portals via email, SMS, or other messaging channels, often spoofing sender addresses that resemble official support communications from the AI platforms. The visual design closely mirrors the authentic interfaces—a technique that relies on familiarity fatigue. Business users checking their ad budgets or account status may not notice subtle domain variations or certificate mismatches, particularly under time pressure or when approaching the URL from a casual link rather than a bookmark.
Once credentials are entered, the attacker's infrastructure captures not just the username and password, but also any one-time codes generated by authenticator apps or SMS-based MFA. This real-time harvesting is crucial: if the attacker can intercept an MFA code during the same session or within its validity window, they can authenticate as the legitimate user before the account holder notices anything is wrong.
Why Business AI Accounts Are Attractive Targets
Business accounts for AI platforms often have elevated permissions and billing information attached. A compromised ChatGPT business account grants attackers access to organisation-wide API quotas, fine-tuned models, and billing data. They can spin up expensive inference tasks, modify rate limits, or extract proprietary datasets uploaded for training. Similarly, Gemini and Claude business tiers unlock higher rate limits and custom configurations that free accounts lack.
More critically, these accounts are often entry points to broader infrastructure. If the business uses single sign-on (SSO) tied to the AI platform account, or if the AI account credentials are reused elsewhere, attackers obtain lateral-movement capabilities. A compromised advertising manager's credentials might also provide access to related cloud services—AWS, GCP, or Azure—if billing or authentication is consolidated.
Infrastructure and Detection Gaps
The success of this campaign reveals a structural gap in how users verify service authenticity. Unlike banking portals, which benefit from long-standing security awareness, AI chatbot platforms are newer. Users are less attuned to recognising authentic domain names or certificate details. The portals can be hosted on cheap, bulletproof hosting with minimal due diligence—particularly in jurisdictions with lax hosting provider verification requirements or poor cooperation with law enforcement.
Email filtering systems often miss these phishing campaigns because the fake portals themselves are not inherently malicious (they don't host malware or exploit zero-days). They're social-engineering infrastructure, which is harder to detect via URL reputation alone. An organisation's email gateway might flag a link to a suspicious domain, but only if it's been previously categorised as malicious. New domains serving phishing portals can circulate for days before security vendors label them.
Defending Against This Attack Pattern
Organisations using business tiers of AI platforms should enforce several hardening measures. First, mandate hardware security keys (FIDO2 tokens) for MFA rather than time-based codes. A security key cannot be harvested by a phishing portal because the protocol requires proof of the legitimate domain—the attacker's fake portal will simply fail to authenticate.
Second, educate users to verify domain names before entering credentials. This is basic advice, but it remains effective. Teach teams to check the SSL certificate details and to bookmark authentic login URLs rather than following links from email. Some organisations disable email links to login portals entirely and require users to navigate manually.
Third, organisations should consider deploying conditional access policies that flag logins from unusual geographies or devices, particularly for AI platform accounts with elevated permissions. Most business-tier AI services support IP whitelisting and session management; using these features restricts account access to expected office networks or VPNs.
Finally, monitor API usage and billing anomalies. If a compromised account suddenly spawns hundreds of inference requests or runs models that the account owner never requested, automated alerts can catch the intrusion before significant damage accrues.
This phishing operation illustrates a persistent pattern in modern attacks: as platforms become more critical to business operations, they become more attractive targets for credential theft. The infrastructure enabling these campaigns is routine and inexpensive to deploy, making large-scale campaigns viable even with modest conversion rates. Defence requires both technical controls and sustained user vigilance.
