Welcome to the forefront of conversational AI as we explore the fascinating world of AI chatbots in our dedicated blog series. Discover the latest advancements, applications, and strategies that propel the evolution of chatbot technology. From enhancing customer interactions to streamlining business processes, these articles delve into the innovative ways artificial intelligence is shaping the landscape of automated conversational agents. Whether you’re a business owner, developer, or simply intrigued by the future of interactive technology, join us on this journey to unravel the transformative power and endless possibilities of AI chatbots.
A phishing operation uncovered this week is not bothering to impersonate a bank or a shipping company. It is impersonating the AI tools millions of marketers already trust. According to a report published October 7, 2026, a human-operated phishing platform is posing as advertising products for Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus, luring in agency staff and media buyers with promises of campaign optimization, spend audits, and business-account connections, then quietly draining their logins and multi-factor authentication (MFA) codes.
The findings come from researchers at Island, who documented a kit built specifically to defeat MFA rather than just scrape a password. That distinction matters. Security teams have spent the better part of a decade telling employees that a second factor is the fix for phishing. This campaign treats that second factor as just another field to capture.
The report, titled “Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes,” describes a platform built around a single, deceptively simple action. Every fake product, whatever brand it borrows, is designed around one button: Connect. Researchers Oleg Zaytsev and Ofek Ronen put it plainly in their write-up, noting that “each product was built around the same action: Connect”, a design choice that lets the operators reuse the same back-end phishing logic across six different brand skins (The Hacker News).
That single-button design is what makes the kit efficient for its operators. Build one convincing login flow, then stamp it with Gemini branding for one lure and Claude branding for the next. The victim never notices the machinery underneath because the surface-level pitch, campaign performance, budget audits, account linking, is exactly what a marketer already expects to see from an advertising dashboard.
The technical core of the campaign is a browser-in-the-browser (BitB) attack. Instead of redirecting a victim to a real-looking but separate phishing domain, the kit draws a fake browser window inside the legitimate browser tab the victim is already using. The address bar inside that fake window shows a trusted-looking origin, such as accounts.google.com or an Okta tenant, while the real browser’s actual address bar never leaves the attacker’s domain.
Zaytsev and Ronen described the effect directly: “Clicking it opened a browser drawn inside the real browser. The fake address bar displayed trusted origins such as accounts.google.com or an Okta tenant, while the real browser remained on the phishing domain” (The Hacker News). The trick works because most people check the address bar with a glance, not a click-to-verify habit, and a rendered pop-up window is visually indistinguishable from a genuine one unless you try to drag it outside the parent tab’s borders.
BitB is not new as a concept; security researchers have warned about the technique for several years. What is new here is the scale of brand impersonation layered on top of it, and the fact that the back end is run by a live human operator rather than a fully automated script, according to the researchers’ description of the platform as “human-operated.”
The choice of brands is itself a signal of where attackers think the money and the trust currently sit. Google Gemini, Anthropic Claude, and OpenAI ChatGPT are the three most recognized consumer AI chatbots, giving the kit instant credibility with marketers who already use them daily. Perplexity extends the pool into AI-powered search. Meta Muse and Manus round out the list, pulling in newer AI agent products that advertising teams have started experimenting with for campaign work, a trend covered in shattered.io’s comparison of OpenAI’s dots agent platform against Meta’s Muse.
Each brand gets its own themed landing page and its own fake “ad product,” but the underlying capture logic is identical. That is the efficiency play: six storefronts, one warehouse.
Once a victim lands on the fake Connect flow, the platform asks for a username and password inside the spoofed BitB window. According to the report, the kit is built to retain three separate password attempts rather than failing out after one wrong entry, a detail that suggests the operators anticipated typos or half-remembered passwords and did not want to lose a victim over a single mistake.
After credentials are captured, the platform moves to the step that separates this campaign from a routine password-stealer: live MFA interception. The documented lures can present SMS codes, authenticator-app codes, Google approval prompts, Google QR verification, Google number matching, and the equivalent Okta screens for username, password, SMS, push approval, authenticator app, and number matching. Because a human operator is watching the session in real time, they can choose which MFA challenge to throw at the victim next based on what the victim’s real account setup actually supports.
That real-time decision-making is the part that should worry security teams most. A static phishing kit either works or it does not. A human-operated one adapts mid-attack, the same way a human-operated ransomware intrusion adapts once it is inside a network rather than relying purely on a worm’s pre-written logic.
Perhaps the most concrete evidence in the researchers’ write-up is the list of operator commands documented inside the platform. These are the literal controls a human attacker uses to steer a live victim session toward the next credential or MFA screen.
Six of the twelve commands are prefixed for Okta specifically, covering username, password, SMS, push approval, authenticator app, and number-matching verification. That level of granularity implies the operators built and tested the kit against real Okta tenant behavior, not a generic mock-up. The other commands target Google’s own account-recovery and sign-in flows, including the newer number-matching and QR-based verification methods Google has rolled out to reduce prompt-bombing. The kit treats both as just another screen to render inside its fake browser window.
The disclosure comes from Oleg Zaytsev and Ofek Ronen, researchers at Island, a company focused on enterprise browser security. Their vantage point, inside the browser session itself, is likely why this particular kit was caught: a BitB attack only fools a user, not necessarily a security tool watching rendering behavior at the browser layer. The researchers’ report was picked up and corroborated by multiple outlets, including BleepingComputer and Cybersecurity News, both of which independently described the same six-brand impersonation pattern and BitB mechanics on October 6 and 7, 2026.
The researchers have not publicly disclosed the exact phishing domains in the versions of the report available so far, and the number of victims, stolen accounts, or financial losses tied to the campaign has not been confirmed. That gap is worth sitting with rather than papering over with a guess, because it is the single biggest open question hanging over this story.
Ad platform credentials are not the first thing most people picture when they think about valuable stolen data, but they sit at the center of a surprisingly efficient fraud chain. An advertising manager account at an agency typically has access to multiple clients, their billing details, and pre-approved budgets. Compromise one login and an attacker inherits spending power that was already cleared by a finance department, no new approval required.
That dynamic mirrors a pattern shattered.io has tracked elsewhere in the AI-agent fraud economy, where stolen access to automated tools has been resold cheaply precisely because the payout per account is so lopsided compared to the cost of acquiring it, as seen in shattered.io’s reporting on AI agents used to harvest 600,000 payment cards for as little as $25 per compromised company. A single hijacked ad account plugged into this new campaign could plausibly follow the same resale logic, cheap for the attacker to obtain, expensive for the victim business to absorb.
The table below lays out the six brands the platform imitates, the lure used for each, and the real-world product category being spoofed.
The second table breaks down the MFA bypass methods the researchers documented, mapped to the specific operator commands used to trigger each one live.
Browser-in-the-browser phishing is not a 2026 invention. Security researchers first demonstrated the technique publicly in 2022, warning that a fake pop-up window could spoof an OAuth login flow convincingly enough to fool careful users, not just careless ones. What has changed since then is the packaging. Early BitB demos were proof-of-concept code aimed at red teams. What Island documented this month is a fully operational, brand-flexible platform with live human operators and a defined command set, closer to a managed service than a one-off exploit.
It also sits alongside a broader shift toward social-engineering techniques that route around automated defenses rather than through them. shattered.io covered a related pattern in September when a supply-chain compromise used the ClickFix technique to push malicious instructions through more than 100,000 sites, relying on tricking a human into pasting a command rather than exploiting a software flaw, as detailed in shattered.io’s report on the Brevo supply-chain breach. Both campaigns share a philosophy: when MFA and endpoint defenses have gotten harder to beat with pure automation, attackers are putting a person back in the loop to beat the human on the other end of the screen instead.
None of the six impersonated companies, Google, Anthropic, OpenAI, Perplexity, Meta, or Manus, built or operated the phishing kit. But all six now carry a brand-trust problem they did not create. Every time a marketer sees a legitimate-looking “Connect your ad account” prompt referencing one of these names, the line between the real product and a cloned one gets a little blurrier, and that ambiguity is exactly what the kit is designed to exploit.
The timing also lands while regulators are already paying closer attention to how AI agent products handle access and security. The Federal Trade Commission opened an inquiry earlier this year into how leading AI labs are securing agentic products, a move covered in shattered.io’s report on the FTC’s investigation into OpenAI and Anthropic over AI agent attacks. A phishing campaign that borrows the brand equity of exactly the products under regulatory scrutiny is unlikely to make that scrutiny lighter.
For ad agencies and media-buying firms, the immediate market impact is operational: every employee with access to a client’s ad spend is now a plausible target for a campaign specifically engineered to look like routine account maintenance. Agencies that have not reviewed who can approve new third-party “Connect” integrations on client ad accounts have a concrete, dated reason to do so this week.
It is worth being precise about what remains unverified, because overstating this story would be its own kind of disinformation. As of this writing, there is no confirmed victim count, no confirmed figure for stolen accounts or financial losses, no named list of operators, and no publicly disclosed set of phishing domain names tied to the campaign. The date the campaign began has also not been pinned down in the reporting available so far.
That is not unusual for a freshly disclosed, human-operated campaign; takedown and attribution work tends to lag disclosure by weeks, sometimes months. But it does mean every headline citing a specific dollar loss or victim count for this particular campaign right now is, at minimum, getting ahead of what researchers have actually confirmed.
The most durable fix for a BitB-based MFA-phishing attack is not a better pop-up blocker, it is removing the phishable factor from the login flow entirely. Passkeys and FIDO2-based hardware security keys use origin-bound cryptographic challenges that a fake browser window cannot replay, because the authentication ceremony is tied to the real domain the browser is actually on, not whatever a rendered overlay claims to display. shattered.io’s explainer on what security teams should tell employees before a passkey rollout is a reasonable starting point for teams that have been putting this off, and the walkthrough on turning a hardware wallet into a FIDO2 security key shows how cheap that hardware-backed protection has become.
Short of a full passkey migration, three lower-effort steps help immediately. First, train advertising and marketing staff specifically, not just IT and finance, since this campaign targets exactly the job function least likely to have been through phishing-simulation drills aimed at engineers. Second, restrict who inside an agency can approve new third-party connections on ad platform accounts, treating a “Connect your AI assistant” prompt with the same suspicion as a wire-transfer request. Third, favor authentication methods resistant to real-time relay, like number-matching with out-of-band context checks or hardware-bound passkeys, over SMS codes and basic push approvals, both of which this kit is explicitly built to intercept. NIST’s own guidance on multi-factor authentication basics, available at nist.gov, is a useful baseline for teams rebuilding their MFA policy from scratch.
What is the browser-in-the-browser (BitB) technique?
It is a phishing method that renders a fake browser pop-up window inside a real browser tab, complete with a fake address bar showing a trusted domain, while the actual browser stays on the attacker’s phishing page.
Which AI brands are being impersonated in this campaign?
Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus, according to the Island researchers’ report.
Can this attack really bypass multi-factor authentication?
Yes, for MFA methods that rely on a code, prompt, or tap being relayed through the browser session, including SMS codes, authenticator app codes, and push approvals. It generally cannot bypass hardware-bound passkeys or FIDO2 security keys, since those are cryptographically tied to the real origin domain.
How many people or companies have been affected?
That has not been confirmed. The researchers’ report does not include a verified victim count, stolen-account total, or financial loss figure as of this writing.
Who discovered the campaign?
Researchers Oleg Zaytsev and Ofek Ronen at Island disclosed the findings in a report published October 7, 2026.
Is this the fault of Google, Anthropic, OpenAI, Meta, or Perplexity?
No. The phishing platform impersonates these companies’ branding without their involvement. The companies are victims of brand abuse in this scenario, not the source of the vulnerability.
What is the single best defense against this kind of attack?
Moving away from phishable MFA factors (SMS, basic push approval) toward passkeys or FIDO2 hardware security keys, which are resistant to browser-in-the-browser relay because the authentication is bound to the real domain, not whatever the browser window visually displays.
Were specific phishing domain names disclosed?
Not in the reporting available as of this writing. Specific domains, the exact campaign start date, and the identity of the operators remain unconfirmed.
Dr. Elena Marchetti writes about cryptography and the math that underpins it: hash functions, collision attacks, and why algorithms age out of trust. She has a research background in applied cryptography and tests a claim before explaining it.
Independent explainers on cryptography, security, privacy and the technology behind provably-fair systems. Home of the original SHA-1 collision research.