Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

A wave of sophisticated phishing attacks is sweeping the globe, targeting users who interact with popular language models like ChatGPT, Gemini, and Claude. These high-profile portals have become unwitting accomplices in a massive credential harvesting operation, leaving millions of people vulnerable to identity theft and other cyber threats.

At the heart of these scams are fake chatbots that mimic the functionality of their legitimate counterparts. These clones create convincing interfaces for users to engage with, often using stolen branding or logos to appear authentic. However, once users enter their login credentials or multifactor authentication (MFA) codes in response to these fake portals’ prompts, they inadvertently hand over sensitive information to attackers.

The mechanics behind this operation are relatively straightforward. Attackers set up phishing websites that closely resemble the real chatbots, complete with identical branding and layout. When unsuspecting users visit these sites, they’re presented with a convincing interface that asks for their login credentials or MFA codes. These credentials can then be used to gain unauthorized access to the user’s accounts, allowing attackers to carry out various malicious activities.

The sheer scale of this operation is alarming, with reports suggesting that millions of people have been targeted by these fake chatbots in recent months alone. The impact extends far beyond individuals, as compromised business and organizational accounts can lead to devastating consequences for both employees and customers. Furthermore, the use of MFA codes adds an extra layer of complexity to these attacks, making it more challenging for users to detect and prevent them.

One of the most disturbing aspects of this trend is its implications for national security. Attackers have been using these fake portals to gather sensitive information from government officials, military personnel, and other high-profile targets. This information can be used to compromise entire organizations or even nation-states, highlighting the need for enhanced cybersecurity measures in critical infrastructure sectors.

As the cybersecurity landscape continues to evolve, it’s essential for users to remain vigilant against such threats. To avoid falling victim to these phishing attacks, individuals should exercise extreme caution when interacting with unfamiliar chatbots or portals, especially those that request sensitive information. By adopting robust password management practices and enabling two-factor authentication whenever possible, users can significantly reduce their risk exposure in this regard.


Source: The Hacker News — 2026-10-06