Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

Cyber attackers have devised a sneaky way to steal login credentials and multi-factor authentication (MFA) codes from unsuspecting victims, using fake portals for popular AI chatbots like ChatGPT, Gemini, and Claude. These impostor websites are designed to mimic the real deal, complete with identical branding and convincing interfaces, all in an attempt to trick users into divulging sensitive information.

The malicious portals work by creating a seamless user experience that mirrors the legitimate services. Once a victim enters their login credentials or MFA codes on these fake sites, the attackers can harvest this data for further exploitation. The scope of this campaign is concerning, as it’s not limited to any particular geographic region or demographic. Anyone using these AI chatbots – from casual users to businesses and organizations – could be at risk.

The technique employed by these attackers leverages a concept called “cross-domain privilege escalation.” In simple terms, this involves creating a vulnerable entry point on one website that allows attackers to gain access to other domains connected to it. By mapping these breach routes at critical points, malicious actors can create pathways for further exploitation. For instance, an attacker could compromise a user’s login credentials on the fake ChatGPT portal and use those same credentials to access sensitive information on another domain.

This campaign highlights the importance of verifying the authenticity of websites, particularly when dealing with services that rely heavily on user trust. Legitimate AI chatbots typically employ robust security measures, such as HTTPS encryption and strict access controls. However, users often overlook these safeguards in favor of convenience or familiarity. Attackers are capitalizing on this human weakness to carry out their malicious activities.

The stakes are high for organizations and individuals using these services. Compromised credentials can lead to sensitive data breaches, unauthorized transactions, or even the hijacking of entire systems. To mitigate this risk, it’s essential to adopt a cautious approach when interacting with AI chatbots. Always check for secure connections (HTTPS) and be wary of unsolicited login prompts or emails that ask for MFA codes.

Ultimately, users must remain vigilant in an increasingly complex online landscape. By taking the initiative to verify website authenticity and being mindful of security best practices, we can all reduce our exposure to these types of attacks. As a practical takeaway, make sure to scrutinize the URL when accessing popular services like ChatGPT or Gemini – a simple step that could save you from falling victim to this type of cyber deception.


Source: The Hacker News — 2026-10-06