# Fake ChatGPT, Gemini, Claude and Perplexity sites phish advertising accounts with a browser-in-the-browser login

> Island researchers describe fake AI sites that show a forged Google login window to take advertising-account credentials and MFA codes, with pages tuned for macOS.

FireAI Security & Research Team (HisnLabs) · Published 2026-10-07
Canonical: https://hisnlabs.com/en/news/fake-ai-sites-browser-in-the-browser-ad-account-phishing-island

Researchers at the browser-security company Island described a phishing operation that uses counterfeit ChatGPT, Gemini, Claude and Perplexity pages to take over advertising accounts, BleepingComputer reported on 6 October 2026. The activity has been traced back to March [[1]](https://www.bleepingcomputer.com/news/security/fake-chatgpt-gemini-sites-steal-advertising-accounts-mfa-codes/).

## Background

A browser-in-the-browser (BitB) attack draws a fake browser window, including an address bar, inside a web page. The window looks like a genuine sign-in pop-up from a provider such as Google, but it is part of the page and not a separate window.

## Findings

According to the report, the pages invite visitors to connect an account to a fake AI product. A forged login window displays “accounts.google.com” in its address bar. After credentials are entered, human operators take over and may ask repeatedly for the password, SMS codes, authenticator codes or an Okta push approval [[1]](https://www.bleepingcomputer.com/news/security/fake-chatgpt-gemini-sites-steal-advertising-accounts-mfa-codes/).

The targets are ad account managers, media buyers and agency administrators, including people who hold access to several clients’ accounts. Compromised accounts can be used to spend available balances on fraudulent campaigns or be resold [[1]](https://www.bleepingcomputer.com/news/security/fake-chatgpt-gemini-sites-steal-advertising-accounts-mfa-codes/). Other lures include fake recruitment and refund pages. The operators’ Telegram channel received “hundreds of victim submissions”, which the report says does not necessarily equal successful compromises [[1]](https://www.bleepingcomputer.com/news/security/fake-chatgpt-gemini-sites-steal-advertising-accounts-mfa-codes/).

The kit adapts its interface to Windows, macOS, iOS and Android, including browser styling and dark mode. It rebuilds the provider’s interface locally and collects credentials and MFA state through its own APIs, rather than relaying a real login. The infrastructure uses a Next.js and Socket.IO stack with Vercel front ends and Railway or Render back ends, and researchers followed it through exposed GitHub repositories [[1]](https://www.bleepingcomputer.com/news/security/fake-chatgpt-gemini-sites-steal-advertising-accounts-mfa-codes/).

> Phishing pages run in the browser, but what a Mac connects to is visible. FireAI, the on-device firewall for macOS developed by HisnLabs, can check traffic against optional public phishing lists. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/fireai/en/download)

## Implications for people who use a Mac

The campaign is aimed at people who manage advertising accounts, but the technique works against anyone who signs in to a service through a pop-up. A Mac gives no protection by itself, as the kit is built to look native on macOS. The report notes a practical check: the fake window is an element of the page, so it cannot be dragged outside the browser window or resized the way a real OAuth pop-up can [[1]](${BC}).

## Recommendations

1. Open AI tools from a bookmark or by typing the address, not from an advertisement, message or recruitment link.
2. When a sign-in pop-up appears, try to drag it beyond the browser window; a window that cannot leave the page is fake.
3. Do not approve a push notification or enter an MFA code that was not prompted by a sign-in you started yourself.
4. Where an account is shared across clients, use a phishing-resistant sign-in method if the provider offers one, and review account access regularly.
5. If credentials were entered on a suspect page, change the password and revoke active sessions from the provider’s own site.

## Relevance to FireAI

FireAI is a firewall for one Mac. When the optional threat lists are turned on, FireAI downloads public lists, including Phishing Army and OpenPhish, once a day and can block a match that a list confirms; the traffic itself is never sent to the lists. A newly built fake site is unlikely to appear on a list at first. FireAI does not inspect web pages, cannot recognise a forged login window and does not prevent a user from typing credentials into a page.

> FireAI blocks what an optional public phishing list confirms and shows where a Mac connects. It cannot tell a forged sign-in window from a real one. Try it free for 17 days. [Download FireAI for Mac](https://hisnlabs.com/fireai/en/download)

## Limitations

This account rests on BleepingComputer’s report of Island’s findings. The number of victims, the loss amounts and the identity of the operators are not stated, and the report counts submissions to a Telegram channel, not confirmed compromises [[1]](https://www.bleepingcomputer.com/news/security/fake-chatgpt-gemini-sites-steal-advertising-accounts-mfa-codes/).

To see where a Mac connects, [download FireAI](https://hisnlabs.com/fireai/en/download) and try it free for 17 days. FireAI is made by HisnLabs.

## Sources

- [BleepingComputer, 6 October 2026: Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes](https://www.bleepingcomputer.com/news/security/fake-chatgpt-gemini-sites-steal-advertising-accounts-mfa-codes/)
