Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes
Overview
A new cyber campaign is targeting advertising account managers by creating fake websites that mimic popular AI platforms like ChatGPT, Gemini, Claude, and Perplexity. These fraudulent sites are designed to steal login credentials and multi-factor authentication (MFA) codes using browser-in-browser attacks. This method allows attackers to trick users into entering sensitive information, which can lead to unauthorized access to advertising accounts. The impact is significant for those in the advertising industry, as compromised accounts can result in financial losses and reputational damage. Users need to be cautious when entering credentials on unfamiliar sites and ensure they are using legitimate platforms.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Fake ChatGPT, Gemini, Claude, Perplexity websites
- Action Required: Users should verify the legitimacy of websites before logging in, implement strong password policies, and use additional security measures like password managers.
- Timeline: Newly disclosed
Original Article Summary
A new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks. [...]
Impact
Fake ChatGPT, Gemini, Claude, Perplexity websites
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Users should verify the legitimacy of websites before logging in, implement strong password policies, and use additional security measures like password managers.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Phishing.