On October 6, 2026, Island reported that fake advertising portals tied to AI brands used counterfeit sign-in windows and human-directed prompts to collect passwords and multi-factor authentication (MFA) information. The operation was phishing through impersonation pages—not an intrusion into the legitimate AI services.

Fake AI-ad portals posed as business tools

Island identified fake portals impersonating advertising tools associated with ChatGPT, Gemini, Claude, Perplexity, Manus and Meta Muse. Their pitches varied: some promoted campaign planning or spending audits, while others offered account connections or a weekly Google Ads brief. Island described agency staff, media buyers and advertising manager-account administrators as intended targets.

The common hook was a “Connect” button. Rather than simply connecting an account, it opened a sign-in flow designed to capture credentials and MFA information.

How the fake sign-in window works

Island reports fake AI-ad portals steering sign-ins in real time

Island described the technique as browser-in-the-browser (BitB): a fake browser window drawn inside the phishing page. The inner window could display a convincing address bar with a trusted-looking sign-in address, while the real browser remained on the phishing domain.

That makes the outer browser’s address bar the one to check. An address displayed inside a window on the page can be part of the deception; it does not establish where the real browser is connected.

Operators could steer authentication in real time

Island reported that human operators could view submissions and choose what happened next. They could request another password, select an MFA prompt—including text-message or authenticator-code requests—or reject a submitted code and continue the flow. The reported sign-in workflows included Google, Meta, TikTok and Okta.

Island also said the platform fingerprinted devices and retained multiple password attempts. Its account describes a web of prompts that operators could direct, rather than a static fake login form.

The reported platform extended beyond AI-ad lures

Island reported that the identified sites used Next.js and Socket.IO, a technology for exchanging data and commands between a website and a server. It also described shared implementation elements across fake AI-ad, refund and recruitment lures. Those other lures were part of the broader platform, not proof that every page used the same prompts or behaved identically.

What Island reported about activity—and how to reduce exposure

Island reported hundreds of submissions to the phishing platform. That count refers to submissions, not confirmed account takeovers. Island described fraudulent ad spending or account resale as a likely motive, not a verified outcome.

When a sign-in window appears, check the real browser address bar rather than an address drawn inside the page. Island also recommends phishing-resistant authentication and reviewing changes to advertising-account controls.

The Federal Trade Commission advises against clicking software ads to download a tool. Instead, go directly to the provider’s website, or search for it and skip sponsored results. The agency also recommends keeping security software, operating systems, browsers and phones updated.