What’s trending in AI on 7 October 2026: Every time an AI company launches something new, a fake version of it now follows within days. Security researchers at Island have exposed a human-operated phishing platform that dresses itself up as advertising tools for ChatGPT, Gemini, Claude, Perplexity, Manus and Meta’s Muse. None of these “AI ads portals” is real. Each one offers a believable pitch, such as a weekly Google Ads brief or a spend audit, and a big “Connect” button. Click it, and a fake sign-in window drawn inside the web page collects your password and your multi-factor code while a live operator decides which security prompt to show you next. The prize is your advertising account: its stored card, its approved budget and, for agencies, every client account linked to it. Below: how the scam works step by step, who it targets, why AI launches make perfect bait, the wider “connect button” problem in AI marketplaces, and a before-you-connect decision path for your team.
Key takeaways
- The products are invented. “Claude Ads”, “Gemini Ads” and “Muse Ads” portals on domains such as ads-claude.com and museads.ai are fronts. Island documented more than 130 fake ad domains.
- The login window is fake too. A browser-in-the-browser (BitB) pop-up shows a convincing accounts.google.com or Okta address bar, but you never leave the attacker’s site.
- A human runs the attack live. Operators see each password attempt, reject wrong ones and choose which MFA challenge you get next: SMS code, authenticator app, Google prompt or Okta push.
- The scammers move with the news. A fake Muse Ads site appeared on 16 September 2026, eight days after Meta announced Muse.
- Passkeys break the trick. Origin-bound sign-in methods such as passkeys and hardware security keys will not work on a look-alike domain, which is why they are the main fix.
1. What Island found
Island researchers Oleg Zaytsev and Ofek Ronen published their findings in a report titled “Behind the Connect Button,” and the story was picked up by The Hacker News on 6 October and GBHackers on 7 October. The core finding: a single phishing operation is running several fake product lines at once, all sharing the same back end. The newest product line is “AI advertising.” It impersonates tools that sound plausible because the AI companies really are building ad businesses. Delana covered one real example on Monday, when OpenAI began testing ads inside ChatGPT image generation, in our textGrain and AI ads report.
The fake brands named in the research include ChatGPT, Gemini, Claude, Perplexity, Manus and Meta’s Muse, and GBHackers also lists a domain posing as a Mistral ad tool. Each gets its own sales pitch. According to Island, the ChatGPT version promised a “Monday Google Ads brief,” the Gemini version offered support for manager accounts (Google’s MCC) and linked clients, the Claude version presented itself as an “advertising portal,” and the Perplexity version promised campaign planning and spend audits. Every path ends at the same “Connect” button.
The scale is meaningful. Island documented more than 130 fake ad domains, including ads-claude.com, anthropic-ads.com, beta-gemini-ads.com and museads.ai. The Hacker News reports that across a three-month observation period ending in August 2026, the broader delivery cluster included about 850 paid-ad landing pages, 26 look-alike ChatGPT destinations and 71 Google Ads campaign IDs. In other words, the attackers were buying real search ads to send victims to fake ad tools. Island says victim submissions were still arriving, in the hundreds, when it published.
| Fake product | The pitch, as reported | Example domains named by researchers | Who it is aimed at |
|---|---|---|---|
| “ChatGPT Ads” | A weekly “Monday” Google Ads brief | advertising-chatgpt.com, ads-team-openai.com | Media buyers and marketers |
| “Gemini Ads” | Manager account (MCC) and linked-client support | beta-gemini-ads.com, advertising-gemini.com | Agencies managing many clients |
| “Claude Ads” | An “advertising portal” | ads-claude.com, ads-claude-beta.com, anthropic-ads.com | Marketing teams trying new AI tools |
| “Perplexity Ads” | Campaign planning and spend audits | Not individually listed in the reports we read | Performance marketers |
| “Muse Ads” | AI ad management for paid media workflows | museads.ai | Early adopters of Meta’s new agent |
2. How the trap works, step by step
The technique at the heart of this campaign is called browser-in-the-browser, or BitB. When you click “Connect,” you expect a pop-up from Google, Meta or your company’s Okta login. What appears instead is a picture of a browser window, built from HTML and CSS inside the phishing page. It has a title bar, a padlock and an address bar showing accounts.google.com or an Okta tenant. Island found the attackers had gone as far as copying the frosted toolbar style of real iPhone Safari and Chrome pop-ups. But your real browser never left the attacker’s domain. The address bar that matters is the one at the very top of your screen, and it still shows the fake portal.
Behind the scenes, the page creates a record for each visitor and fingerprints the device: IP address, approximate location, screen size and graphics capabilities. Then the credentials flow, in real time, to a human operator over a live connection (the researchers identified the Socket.IO library and a Telegram-linked command channel). That is what makes this campaign different from a static fake login page.
3. Why a live operator beats your MFA
Most people think of multi-factor authentication as a wall. Against this kind of attack, codes and push approvals are more like a speed bump, because a person on the other end is relaying them to the real service while you wait. Island’s analysis of the exposed code shows how hands-on the operation is. The kit keeps up to three separate password attempts, so even a mistyped password is useful. The operator can reject an entry and force a retry, then choose which challenge appears next: a text-message code, an authenticator-app code, a Google sign-in prompt or an Okta push approval. There is even a command to show a “wrong code” message, which nudges the victim to type a fresh one, and a command to ban visitors who look like researchers.
This is why the researchers, and Delana, keep coming back to phishing-resistant authentication. A passkey or a hardware security key is cryptographically bound to the real website’s address. On ads-claude.com it simply has nothing to offer, no matter how convincing the window looks. We made the same argument about stolen sessions in Credential and Identity Theft Is Reaching Crisis Levels, and Microsoft’s latest threat report, which we summarized in The 24-Hour Window, points the same way.
4. Why ad accounts, and why agencies are the jackpot
An advertising account is close to a payment card with a marketing dashboard attached. It holds a stored payment method, an approved budget and, often, a long clean history that ad platforms trust. Island describes several ways the stolen access turns into money:
- Spend your budget. Run the attacker’s own campaigns on your stored card, often promoting other scams.
- Sell the account. Aged accounts with a clean spend history sell on Telegram for two to four times the price of a new one, according to Island, with some Google Ads accounts for “high-risk” ad categories listed at $200 to $270.
- Climb the agency ladder. A Google Ads manager account controls many client accounts. One compromised agency login can reach every client’s budget and data.
- Take the work identity. When the fake login is for Google Workspace or Okta, the attacker may also get into the victim’s email, files and other company apps.
That last point matters beyond marketing. If your company signs in to its ad platforms with the same Google or Okta identity used for everything else, a “marketing” phish is really an identity compromise. It is the same trust-chain problem we described in SaaS Supply Chain and OAuth Attacks.
5. Scams that move with the news
The detail that should worry marketing and security teams most is speed. Meta announced its Muse personal agent on 8 September 2026. The fake museads.ai appeared on 16 September, eight days later. As Island put it, “Phishing pages are now built to order.” AI helps here too: the researchers note the unusually fast creation of new, polished brand pages, which fits what we have seen across the year in posts such as The Proof-of-Human Problem.
The AI ads lure is only the newest coat of paint. Island found the same back end, the same three-password retry logic and the same operator vocabulary behind two older scam lines: fake refund and billing pages (domains such as confirm-payments.com and sync-billing.com) and fake recruitment sites for brands including Tesla, Nike, Louis Vuitton, Adidas and Adecco. One back-end server, hosted on Railway, showed up in 73 archived scans across 25 domains between 27 May and 20 June 2026. The operators also left their code exposed in misconfigured public GitHub repositories, which is how researchers could read the console commands.
The lesson is that brand-new AI products are the perfect bait. Nobody knows yet what the real “Muse Ads” or “Claude Ads” sign-up looks like, so there is no familiar page to compare against. Teams are under pressure to try new AI tools quickly. And “beta access” sounds exclusive enough to click. We saw the same dynamic with agent permission prompts in “Allow Always” Is the New “I Agree”.
6. The bigger “connect button” problem: AI marketplaces with no gatekeeper
Fake ad portals are the criminal end of a wider issue: we are being asked to connect AI tools to our accounts faster than anyone can check them. A separate study published via The Hacker News on 6 October, contributed by security firm OX Security, looked at 15,465 publicly listed Model Context Protocol (MCP) servers, the plug-ins that let AI assistants reach other apps and data. Across five MCP registries they found 5,095 unique hostnames, and no consistent review process on any of the marketplaces.
The numbers are a reminder that the “Connect” step is now one of the riskiest clicks in a company. A remote plug-in can run different code from the public repository it points to. It can send data to a country your contracts do not allow. And if its domain lapses, whoever re-registers it inherits the trust. OX Security’s study is vendor research, so treat it as a strong signal rather than a census, but its advice is sensible: until marketplaces vet what they list, companies need to check origin, ownership and code themselves. Our posts on the AI control plane and shadow AI explain where to start.
7. Before you click “Connect”: a decision path
Print this and stick it next to whoever manages your ad accounts. Work through the questions in order. A single “no” means stop and ask IT or security before going further.
- Did I find this tool myself, from the vendor’s own website? Not from a search ad, an email, a LinkedIn message or a “beta invite.” Type the vendor’s main address yourself and look for the product there. If OpenAI, Google, Anthropic or Meta does not mention it on its own site, it does not exist.
- Does the real address bar show the company I expect? Look at the very top of the browser, not inside the pop-up. A domain such as ads-claude.com or beta-gemini-ads.com is not Anthropic or Google.
- Is the sign-in window a real window? Try dragging it outside the browser. A browser-in-the-browser fake is trapped inside the page. Also notice if your password manager refuses to fill it; that refusal is a warning, not a bug.
- Am I signing in with a passkey or security key? If the site suddenly asks for a password and a code instead of the passkey you normally use, stop. That change is the attack.
- Am I being asked for a second or third code after a “wrong code” message? Repeated prompts, especially right after you were sure you typed correctly, are a classic sign of a live relay. Close the tab.
- Does this connection need a manager or agency account? If yes, it needs a second person’s approval. Never connect a new tool with a login that controls client accounts.
- Is the tool on our approved list? If not, it goes through review first, the same way a new MCP plug-in or browser extension would.
If someone already clicked and entered details, treat it as an incident, not an embarrassment. Sign out all sessions, reset the password, remove unknown users, partners and payment methods from the ad account, check recovery email and phone settings, pause campaigns you did not create, and contact the ad platform’s support. Then check the same identity’s email and file access, since the fake Google and Okta windows can unlock more than ads.
8. Who should do what this week
| Role | Action | Why it matters here |
|---|---|---|
| Marketing and agency leads | Brief everyone who touches ad platforms on the fake “AI Ads” portals and the decision path above | Media buyers and agency staff are the named targets |
| IT and identity team | Move ad-platform admins and manager accounts to passkeys or hardware keys first | Origin-bound sign-in defeats the fake BitB window |
| Ad account owners | Review users, partners, linked accounts, payment methods and recent campaigns for anything unfamiliar | Takeovers show up as new managers and unapproved spend |
| Security team | Block and hunt for the published domains and indicators, such as connections to unfamiliar Railway or Render back ends | Island published domains and code patterns to search for |
| Finance | Set spend alerts and card limits on ad accounts | Limits cap the damage if an account is hijacked |
| Leadership | Require approval before any AI tool or plug-in is connected to company accounts | The same rule covers fake ad tools and unvetted MCP servers |
9. What to watch next
Three things. First, the next big AI launch: expect a fake “ads,” “beta” or “enterprise” portal for it within about a week, so warn your team the day it is announced. Second, whether the real AI ad platforms publish clear guidance on what their genuine onboarding looks like, which would make fakes easier to spot. Third, whether MCP registries introduce review, signing or ownership checks before listing a server. Until then, the safest assumption is simple: any AI tool that asks you to sign in through a pop-up deserves a second look.
Frequently asked questions
Are “Claude Ads,” “Gemini Ads” and “Muse Ads” real products?
The portals described in Island’s research, on domains such as ads-claude.com, beta-gemini-ads.com and museads.ai, are fakes run by a phishing operation. Some AI companies are developing real advertising products, so always find a tool through the vendor’s own website rather than an ad, email or invite.
What is a browser-in-the-browser attack?
It is a fake sign-in pop-up drawn inside a web page with HTML and CSS. It shows a convincing title bar, padlock and address such as accounts.google.com, but you never leave the attacker’s site. A fake window cannot be dragged outside the browser, and your password manager will usually not fill it.
Can this attack get past multi-factor authentication?
Yes, for codes and push approvals. A live operator relays what you type to the real service and can choose which challenge you see next, including SMS, authenticator codes, Google prompts and Okta pushes. Passkeys and hardware security keys resist it because they only work on the genuine website’s domain.
Who is being targeted?
Advertising managers, media buyers, agency staff and administrators of Google Ads manager accounts, according to the researchers. The same infrastructure also runs fake refund pages and fake job sites aimed at job seekers.
What do attackers do with a stolen ad account?
They run their own campaigns on the stored payment method, resell aged accounts with clean history for two to four times the price of new ones, and, with manager accounts, reach linked client accounts. If the login was a Google Workspace or Okta identity, email and files may also be exposed.
What should I do if I entered my details on one of these sites?
Act quickly: sign out of all sessions, change the password, remove unknown users, partners and payment methods from the ad account, check recovery settings, pause unfamiliar campaigns, tell your IT or security team and contact the ad platform’s support. Then switch the account to a passkey or security key.
Sources
- Island: Behind the Connect Button, the fake AI ads campaign
- The Hacker News: Fake ChatGPT, Gemini and Claude ad portals capture credentials and MFA codes (6 Oct 2026)
- GBHackers: Fake ChatGPT, Claude and Gemini ads use browser-in-the-browser phishing to steal accounts (7 Oct 2026)
- The Hacker News (contributed by OX Security): Welcome to the jungle, what we found inside 15,465 public MCP servers (6 Oct 2026)
