Skip to content

Mon - Fri: 10.00 - 5.00

[email protected]

Delana Technologies

Delana Technologies

Delana Technologies delivers expert cybersecurity, cloud, and AI-driven IT strategy solutions. Transform your enterprise securely and intelligently.

  • Home
  • Contact Us
  • About Us
  • Case Studies
  • Workflow Automation & Systems Integration
  • AI Consulting & Agentic AI Solutions
  • Home
  • Contact Us
  • About Us
  • Case Studies
  • Workflow Automation & Systems Integration
  • AI Consulting & Agentic AI Solutions

Mon - Fri: 10.00 - 5.00

[email protected]

The Fake “Claude Ads” Portal Is a Trap: Phishers Clone AI Ad Tools to Steal Google Ads Accounts and MFA Codes (AI Trends, 7 October 2026)

  1. Home   »  
  2. The Fake “Claude Ads” Portal Is a Trap: Phishers Clone AI Ad Tools to Steal Google Ads Accounts and MFA Codes (AI Trends, 7 October 2026)

The Fake “Claude Ads” Portal Is a Trap: Phishers Clone AI Ad Tools to Steal Google Ads Accounts and MFA Codes (AI Trends, 7 October 2026)

October 7, 2026October 7, 2026 admincybersecurity, UncategorizedTagged ad account takeover, AI security, AI trends, browser-in-the-browser, ChatGPT ads, Google Gemini, MCP servers, Meta Muse, MFA bypass, passkeys, phishing, software supply chain

What’s trending in AI on 7 October 2026: Every time an AI company launches something new, a fake version of it now follows within days. Security researchers at Island have exposed a human-operated phishing platform that dresses itself up as advertising tools for ChatGPT, Gemini, Claude, Perplexity, Manus and Meta’s Muse. None of these “AI ads portals” is real. Each one offers a believable pitch, such as a weekly Google Ads brief or a spend audit, and a big “Connect” button. Click it, and a fake sign-in window drawn inside the web page collects your password and your multi-factor code while a live operator decides which security prompt to show you next. The prize is your advertising account: its stored card, its approved budget and, for agencies, every client account linked to it. Below: how the scam works step by step, who it targets, why AI launches make perfect bait, the wider “connect button” problem in AI marketplaces, and a before-you-connect decision path for your team.

Key takeaways

  • The products are invented. “Claude Ads”, “Gemini Ads” and “Muse Ads” portals on domains such as ads-claude.com and museads.ai are fronts. Island documented more than 130 fake ad domains.
  • The login window is fake too. A browser-in-the-browser (BitB) pop-up shows a convincing accounts.google.com or Okta address bar, but you never leave the attacker’s site.
  • A human runs the attack live. Operators see each password attempt, reject wrong ones and choose which MFA challenge you get next: SMS code, authenticator app, Google prompt or Okta push.
  • The scammers move with the news. A fake Muse Ads site appeared on 16 September 2026, eight days after Meta announced Muse.
  • Passkeys break the trick. Origin-bound sign-in methods such as passkeys and hardware security keys will not work on a look-alike domain, which is why they are the main fix.
The fake AI ads portal is a trapTitle card. Headline: the fake AI ads portal is a trap. Subhead: phishers clone ad tools for ChatGPT, Gemini, Claude and Muse to steal Google Ads accounts and MFA codes. Three tags: invented AI ad products; fake browser-in-the-browser login; live operator picks your MFA prompt. Illustration of a browser window containing a second, fake sign-in window with a Connect button and a hook. ads-claude.com 🔒 accounts.google.com Sign inEmail or phoneEnter code Connect AI TRENDS · 7 OCTOBER 2026 The fake AI ads portal is a trap Phishers clone “ad tools” for ChatGPT, Gemini, Claude and Muse to steal ad accounts and MFA codes. Invented AI ad products Fake browser-in-the-browser login A live operator picks your MFA prompt Source: Island research, via The Hacker News and GBHackers (6–7 Oct 2026)delana.co
The address bar inside the pop-up says Google. The real address bar, above it, says something else.

1. What Island found

Island researchers Oleg Zaytsev and Ofek Ronen published their findings in a report titled “Behind the Connect Button,” and the story was picked up by The Hacker News on 6 October and GBHackers on 7 October. The core finding: a single phishing operation is running several fake product lines at once, all sharing the same back end. The newest product line is “AI advertising.” It impersonates tools that sound plausible because the AI companies really are building ad businesses. Delana covered one real example on Monday, when OpenAI began testing ads inside ChatGPT image generation, in our textGrain and AI ads report.

The fake brands named in the research include ChatGPT, Gemini, Claude, Perplexity, Manus and Meta’s Muse, and GBHackers also lists a domain posing as a Mistral ad tool. Each gets its own sales pitch. According to Island, the ChatGPT version promised a “Monday Google Ads brief,” the Gemini version offered support for manager accounts (Google’s MCC) and linked clients, the Claude version presented itself as an “advertising portal,” and the Perplexity version promised campaign planning and spend audits. Every path ends at the same “Connect” button.

The scale is meaningful. Island documented more than 130 fake ad domains, including ads-claude.com, anthropic-ads.com, beta-gemini-ads.com and museads.ai. The Hacker News reports that across a three-month observation period ending in August 2026, the broader delivery cluster included about 850 paid-ad landing pages, 26 look-alike ChatGPT destinations and 71 Google Ads campaign IDs. In other words, the attackers were buying real search ads to send victims to fake ad tools. Island says victim submissions were still arriving, in the hundreds, when it published.

Fake productThe pitch, as reportedExample domains named by researchersWho it is aimed at
“ChatGPT Ads”A weekly “Monday” Google Ads briefadvertising-chatgpt.com, ads-team-openai.comMedia buyers and marketers
“Gemini Ads”Manager account (MCC) and linked-client supportbeta-gemini-ads.com, advertising-gemini.comAgencies managing many clients
“Claude Ads”An “advertising portal”ads-claude.com, ads-claude-beta.com, anthropic-ads.comMarketing teams trying new AI tools
“Perplexity Ads”Campaign planning and spend auditsNot individually listed in the reports we readPerformance marketers
“Muse Ads”AI ad management for paid media workflowsmuseads.aiEarly adopters of Meta’s new agent
Compiled from Island’s report, The Hacker News and GBHackers. None of these products or domains belongs to the AI company named.

2. How the trap works, step by step

The technique at the heart of this campaign is called browser-in-the-browser, or BitB. When you click “Connect,” you expect a pop-up from Google, Meta or your company’s Okta login. What appears instead is a picture of a browser window, built from HTML and CSS inside the phishing page. It has a title bar, a padlock and an address bar showing accounts.google.com or an Okta tenant. Island found the attackers had gone as far as copying the frosted toolbar style of real iPhone Safari and Chrome pop-ups. But your real browser never left the attacker’s domain. The address bar that matters is the one at the very top of your screen, and it still shows the fake portal.

Behind the scenes, the page creates a record for each visitor and fingerprints the device: IP address, approximate location, screen size and graphics capabilities. Then the credentials flow, in real time, to a human operator over a live connection (the researchers identified the Socket.IO library and a Telegram-linked command channel). That is what makes this campaign different from a static fake login page.

Anatomy of the fake AI ads attackFlow diagram in six steps. Step 1: a paid search ad or link. Step 2: a fake AI ads portal with a product pitch. Step 3: the victim clicks Connect. Step 4: a browser-in-the-browser fake Google, Meta, TikTok or Okta login. Step 5: a live operator receives the password and chooses the MFA challenge. Step 6: the ad account is taken over. A note in orange says the real browser address bar never leaves the attacker’s domain. Anatomy of the fake AI ads attack From a search ad to a hijacked ad account, as described by Island 1Paid search ador link 2Fake “AI Ads”portal + pitch 3Victim clicks“Connect” 4Fake BitB loginGoogle · Okta 5Live operatorpicks MFA step 6Ad accounttaken over The tell that the fake cannot hide The padlock and “accounts.google.com” are drawn inside the page. Your real address bar still shows the fake portal.A fake pop-up also cannot be dragged outside the browser window, and your password manager will not auto-fill it.Supported fake logins, per Island: Google, Meta, TikTok and Okta. Source: Island, “Behind the Connect Button” (Oct 2026)delana.co
Steps 4 and 5 are where the attack happens; steps 1 to 3 are just marketing.

3. Why a live operator beats your MFA

Most people think of multi-factor authentication as a wall. Against this kind of attack, codes and push approvals are more like a speed bump, because a person on the other end is relaying them to the real service while you wait. Island’s analysis of the exposed code shows how hands-on the operation is. The kit keeps up to three separate password attempts, so even a mistyped password is useful. The operator can reject an entry and force a retry, then choose which challenge appears next: a text-message code, an authenticator-app code, a Google sign-in prompt or an Okta push approval. There is even a command to show a “wrong code” message, which nudges the victim to type a fresh one, and a command to ban visitors who look like researchers.

Inside the operator’s consoleMock console listing the operator commands Island found in the phishing kit’s code, with plain-English meanings. slash 2fa: show a text-message code screen. slash authApp: ask for an authenticator app code. slash googlePrompt: trigger a Google sign-in prompt. slash oktaApprove: ask for an Okta push approval. slash wrong2fa: tell the victim the code was wrong. slash done: finish and release the victim. slash ban: block the visitor. A side panel notes the kit stores up to three password attempts. Inside the operator’s console Commands found in the kit’s exposed code, and what each does to the victim’s screen /2fashow a text-message code screen /authAppask for an authenticator code /googlePrompttrigger a Google sign-in prompt /oktaApproveask for an Okta push approval /wrong2fa“wrong code”, type another /donefinish and release the victim /banblock a suspicious visitor 3password attemptsstored per victimEven a typo helps the attacker. What stops itPasskeys and security keysare tied to the real domain,so they fail on a fake one. Source: Island code analysis, via GBHackers and The Hacker Newsdelana.co
Codes and push approvals can be relayed by a human. A passkey cannot be relayed to the wrong website.

This is why the researchers, and Delana, keep coming back to phishing-resistant authentication. A passkey or a hardware security key is cryptographically bound to the real website’s address. On ads-claude.com it simply has nothing to offer, no matter how convincing the window looks. We made the same argument about stolen sessions in Credential and Identity Theft Is Reaching Crisis Levels, and Microsoft’s latest threat report, which we summarized in The 24-Hour Window, points the same way.

4. Why ad accounts, and why agencies are the jackpot

An advertising account is close to a payment card with a marketing dashboard attached. It holds a stored payment method, an approved budget and, often, a long clean history that ad platforms trust. Island describes several ways the stolen access turns into money:

  • Spend your budget. Run the attacker’s own campaigns on your stored card, often promoting other scams.
  • Sell the account. Aged accounts with a clean spend history sell on Telegram for two to four times the price of a new one, according to Island, with some Google Ads accounts for “high-risk” ad categories listed at $200 to $270.
  • Climb the agency ladder. A Google Ads manager account controls many client accounts. One compromised agency login can reach every client’s budget and data.
  • Take the work identity. When the fake login is for Google Workspace or Okta, the attacker may also get into the victim’s email, files and other company apps.

That last point matters beyond marketing. If your company signs in to its ad platforms with the same Google or Okta identity used for everything else, a “marketing” phish is really an identity compromise. It is the same trust-chain problem we described in SaaS Supply Chain and OAuth Attacks.

One stolen agency login, many victimsHub diagram. In the center, an agency’s Google Ads manager account compromised through a fake AI ads portal. Six spokes lead to client ad accounts, each with a stored card and budget. Side panel lists what attackers do with access: spend the budget, resell aged accounts at two to four times the price of new ones, and reach email and files through the same Google or Okta identity. One stolen agency login, many victims Why manager accounts are the most valuable target in this campaign Agencymanager account Client Acard + budget Client Bcard + budget Client Ccard + budget Client Dcard + budget Client Ecard + budget Client Fcard + budget What attackers do next • Run their own ads on your card• Resell aged accounts for 2–4×the price of new ones• “High-risk” Google Ads accountslisted at $200–$270• Reach email and files throughthe same Google or Okta login Source: Island, “Behind the Connect Button” (Oct 2026). Client count is illustrative.delana.co
For agencies, one click on a fake “Gemini Ads” connector can put every client’s budget at risk.

5. Scams that move with the news

The detail that should worry marketing and security teams most is speed. Meta announced its Muse personal agent on 8 September 2026. The fake museads.ai appeared on 16 September, eight days later. As Island put it, “Phishing pages are now built to order.” AI helps here too: the researchers note the unusually fast creation of new, polished brand pages, which fits what we have seen across the year in posts such as The Proof-of-Human Problem.

The AI ads lure is only the newest coat of paint. Island found the same back end, the same three-password retry logic and the same operator vocabulary behind two older scam lines: fake refund and billing pages (domains such as confirm-payments.com and sync-billing.com) and fake recruitment sites for brands including Tesla, Nike, Louis Vuitton, Adidas and Adecco. One back-end server, hosted on Railway, showed up in 73 archived scans across 25 domains between 27 May and 20 June 2026. The operators also left their code exposed in misconfigured public GitHub repositories, which is how researchers could read the console commands.

The lesson is that brand-new AI products are the perfect bait. Nobody knows yet what the real “Muse Ads” or “Claude Ads” sign-up looks like, so there is no familiar page to compare against. Teams are under pressure to try new AI tools quickly. And “beta access” sounds exclusive enough to click. We saw the same dynamic with agent permission prompts in “Allow Always” Is the New “I Agree”.

6. The bigger “connect button” problem: AI marketplaces with no gatekeeper

Fake ad portals are the criminal end of a wider issue: we are being asked to connect AI tools to our accounts faster than anyone can check them. A separate study published via The Hacker News on 6 October, contributed by security firm OX Security, looked at 15,465 publicly listed Model Context Protocol (MCP) servers, the plug-ins that let AI assistants reach other apps and data. Across five MCP registries they found 5,095 unique hostnames, and no consistent review process on any of the marketplaces.

15,465 MCP servers, no gatekeeperInfographic of OX Security’s study of public Model Context Protocol servers. 15,465 listed servers across 5 registries, deduplicated to 5,095 unique hostnames. 15.6 percent of hostnames resolve outside the United States, including 19 in China and 18 in Russia. 2.3 percent no longer resolve, and 6 sit on expired domains that could be re-registered for 4 to 12 dollars a year. 0.45 percent run through consumer tunneling services from personal machines. 15,465 MCP servers, no gatekeeper What OX Security found when it checked where public AI plug-ins actually live 15,465listed servers, 5 registries 5,095unique hostnames 15.6%resolve outside the US, incl. 19 in China and 18 in Russia 2.3%no longer resolve at all 6on expired domains anyone could buy for $4–$12 a year 0.45%run through consumer tunnels from personal machines Source: OX Security, “15,465 MCP Servers, 0 Governance,” via The Hacker News (6 Oct 2026)delana.co
An expired domain behind a trusted plug-in name is a ready-made trap for whoever buys it next.

The numbers are a reminder that the “Connect” step is now one of the riskiest clicks in a company. A remote plug-in can run different code from the public repository it points to. It can send data to a country your contracts do not allow. And if its domain lapses, whoever re-registers it inherits the trust. OX Security’s study is vendor research, so treat it as a strong signal rather than a census, but its advice is sensible: until marketplaces vet what they list, companies need to check origin, ownership and code themselves. Our posts on the AI control plane and shadow AI explain where to start.

7. Before you click “Connect”: a decision path

Print this and stick it next to whoever manages your ad accounts. Work through the questions in order. A single “no” means stop and ask IT or security before going further.

  1. Did I find this tool myself, from the vendor’s own website? Not from a search ad, an email, a LinkedIn message or a “beta invite.” Type the vendor’s main address yourself and look for the product there. If OpenAI, Google, Anthropic or Meta does not mention it on its own site, it does not exist.
  2. Does the real address bar show the company I expect? Look at the very top of the browser, not inside the pop-up. A domain such as ads-claude.com or beta-gemini-ads.com is not Anthropic or Google.
  3. Is the sign-in window a real window? Try dragging it outside the browser. A browser-in-the-browser fake is trapped inside the page. Also notice if your password manager refuses to fill it; that refusal is a warning, not a bug.
  4. Am I signing in with a passkey or security key? If the site suddenly asks for a password and a code instead of the passkey you normally use, stop. That change is the attack.
  5. Am I being asked for a second or third code after a “wrong code” message? Repeated prompts, especially right after you were sure you typed correctly, are a classic sign of a live relay. Close the tab.
  6. Does this connection need a manager or agency account? If yes, it needs a second person’s approval. Never connect a new tool with a login that controls client accounts.
  7. Is the tool on our approved list? If not, it goes through review first, the same way a new MCP plug-in or browser extension would.

If someone already clicked and entered details, treat it as an incident, not an embarrassment. Sign out all sessions, reset the password, remove unknown users, partners and payment methods from the ad account, check recovery email and phone settings, pause campaigns you did not create, and contact the ad platform’s support. Then check the same identity’s email and file access, since the fake Google and Okta windows can unlock more than ads.

8. Who should do what this week

RoleActionWhy it matters here
Marketing and agency leadsBrief everyone who touches ad platforms on the fake “AI Ads” portals and the decision path aboveMedia buyers and agency staff are the named targets
IT and identity teamMove ad-platform admins and manager accounts to passkeys or hardware keys firstOrigin-bound sign-in defeats the fake BitB window
Ad account ownersReview users, partners, linked accounts, payment methods and recent campaigns for anything unfamiliarTakeovers show up as new managers and unapproved spend
Security teamBlock and hunt for the published domains and indicators, such as connections to unfamiliar Railway or Render back endsIsland published domains and code patterns to search for
FinanceSet spend alerts and card limits on ad accountsLimits cap the damage if an account is hijacked
LeadershipRequire approval before any AI tool or plug-in is connected to company accountsThe same rule covers fake ad tools and unvetted MCP servers
Delana’s role split, based on the recommendations in Island’s report and OX Security’s MCP study.

9. What to watch next

Three things. First, the next big AI launch: expect a fake “ads,” “beta” or “enterprise” portal for it within about a week, so warn your team the day it is announced. Second, whether the real AI ad platforms publish clear guidance on what their genuine onboarding looks like, which would make fakes easier to spot. Third, whether MCP registries introduce review, signing or ownership checks before listing a server. Until then, the safest assumption is simple: any AI tool that asks you to sign in through a pop-up deserves a second look.

Frequently asked questions

Are “Claude Ads,” “Gemini Ads” and “Muse Ads” real products?

The portals described in Island’s research, on domains such as ads-claude.com, beta-gemini-ads.com and museads.ai, are fakes run by a phishing operation. Some AI companies are developing real advertising products, so always find a tool through the vendor’s own website rather than an ad, email or invite.

What is a browser-in-the-browser attack?

It is a fake sign-in pop-up drawn inside a web page with HTML and CSS. It shows a convincing title bar, padlock and address such as accounts.google.com, but you never leave the attacker’s site. A fake window cannot be dragged outside the browser, and your password manager will usually not fill it.

Can this attack get past multi-factor authentication?

Yes, for codes and push approvals. A live operator relays what you type to the real service and can choose which challenge you see next, including SMS, authenticator codes, Google prompts and Okta pushes. Passkeys and hardware security keys resist it because they only work on the genuine website’s domain.

Who is being targeted?

Advertising managers, media buyers, agency staff and administrators of Google Ads manager accounts, according to the researchers. The same infrastructure also runs fake refund pages and fake job sites aimed at job seekers.

What do attackers do with a stolen ad account?

They run their own campaigns on the stored payment method, resell aged accounts with clean history for two to four times the price of new ones, and, with manager accounts, reach linked client accounts. If the login was a Google Workspace or Okta identity, email and files may also be exposed.

What should I do if I entered my details on one of these sites?

Act quickly: sign out of all sessions, change the password, remove unknown users, partners and payment methods from the ad account, check recovery settings, pause unfamiliar campaigns, tell your IT or security team and contact the ad platform’s support. Then switch the account to a passkey or security key.


Sources

  • Island: Behind the Connect Button, the fake AI ads campaign
  • The Hacker News: Fake ChatGPT, Gemini and Claude ad portals capture credentials and MFA codes (6 Oct 2026)
  • GBHackers: Fake ChatGPT, Claude and Gemini ads use browser-in-the-browser phishing to steal accounts (7 Oct 2026)
  • The Hacker News (contributed by OX Security): Welcome to the jungle, what we found inside 15,465 public MCP servers (6 Oct 2026)

Post navigation

Previous: AI Just Wrote Its First Prescription: Utah Lets Nolla Health’s App Start Acne Treatment Without a Doctor Visit (AI Trends, 6 October 2026)

Florida Service Location

  • Cybersecurity, AI Consulting & IT Services in West Palm Beach, Florida
  • Cybersecurity, AI Consulting & IT Services in Sarasota, Florida
  • Cybersecurity, AI Consulting & IT Services in Port St. Lucie, Florida
  • Cybersecurity, AI Consulting & IT Services in Pembroke Pines, Florida
  • Cybersecurity, AI Consulting & IT Services in Naples, Florida
  • Cybersecurity, AI Consulting & IT Services in Miramar, Florida
  • Cybersecurity, AI Consulting & IT Services in Miami, Florida
  • Cybersecurity, AI Consulting & IT Services in Hollywood, Florida
  • Cybersecurity, AI Consulting & IT Services in Hialeah, Florida
  • Cybersecurity, AI Consulting & IT Services in Fort Myers, Florida
  • Cybersecurity, AI Consulting & IT Services in Fort Lauderdale, Florida
  • Cybersecurity, AI Consulting & IT Services in Cape Coral, Florida
  • Cybersecurity, AI Consulting & IT Services in Boca Raton, Florida
  • Cybersecurity, AI Consulting & IT Services in Coral Springs, Florida

Technology Services

  • Cybersecurity Compliance & Regulatory Framework Services
  • Workflow Automation & Systems Integration
  • Cloud Modernization & Technology Innovation Services
  • Fractional CTO & Expert Technical Consultants
  • Data Analytics, BI & Modern Data Platforms
  • Cyber Litigation Support & Digital Forensics
  • Cybersecurity Solutions & Zero Trust Architecture
  • AI Consulting & Agentic AI Solutions
  • Case Studies
  • Home
  • Contact Us
  • Privacy Policy
  • Cybersecurity Compliance & Regulatory Framework Services
  • Workflow Automation & Systems Integration
  • Cloud Modernization & Technology Innovation Services
  • Fractional CTO & Expert Technical Consultants
  • Data Analytics, BI & Modern Data Platforms
  • Cyber Litigation Support & Digital Forensics
  • Cybersecurity Solutions & Zero Trust Architecture
  • AI Consulting & Agentic AI Solutions

© Copyright 2025 Delana Technologies LLC