Cybersecurity researchers have uncovered a human-operated phishing platform that impersonates the advertising portals of several major AI chatbots — including OpenAI's ChatGPT, Google Gemini, Anthropic's Claude, Perplexity, Meta's Muse, and Manus — in an operation that captures user credentials and one-time authentication codes in real time, according to a report published by The Hacker News.
The fake portals advertise services familiar to anyone who has bought ads: campaign optimisation, spend audits, and connections to business accounts. None of those services exist. The products are a pretext, and the platform's operators appear to monitor sessions live as victims type, turning each click into a credential and multi-factor authentication (MFA) haul.
How the bypass works
The mechanism deserves closer attention because it defeats the very control most organisations rely on as their last line of defence. MFA assumes that possession of a second factor proves a legitimate session. When a phishing platform captures a user's password and the resulting one-time code in real time, that assumption collapses: the attacker is not replaying a stolen code after it expires — they are sitting inside a session the victim has just authenticated for them.
That is where MFA stops protecting anything. And the persuasion behind the attack is unusually effective, because the pitch matches something real. Teams evaluating AI tools for their own workflows are already used to vendor pages asking for account connections, billing reviews, and ad-spend sign-ins. The fake portals borrow exactly that vocabulary.
The operational model matters too. This is not a self-service kit distributed to anonymous buyers — it is human-operated. That changes the threat profile: sessions are watched, codes are captured as they expire, and victims who suspect something and abandon the tab may already have handed over enough to matter.
What organisations should take from this
The practical response to a threat of this kind is not generic phishing awareness training. Advising staff to "spot the tell-tale signs" is already the floor, and it is evidently not enough when the lures are well-constructed and the timing is opportune. What is missing is a verification step specific to AI-tool onboarding — the stage where procurement moves faster than security review.
Teams adopting AI tools should independently confirm any portal with the vendor itself, using contact details obtained outside the original link or message. Requests for ad-manager access, billing audits, or business-account connections should be routed through the organisation's standard approval path, regardless of how urgent or legitimate the request appears. Vendors' entry points — which of their sites actually request credentials or account links — are worth mapping in advance, so that a genuine prompt can be recognised as genuine.
Finally, any captured code should be treated as compromised. Organisations should assume an active session may exist and revoke tokens, force logouts, and rotate credentials for the affected accounts.
A broader signal
The impersonation targets are themselves the story. Attackers are not building lures around generic "tech company" facades; they are mirroring specific, fast-growing AI products whose adoption is pushing into workflows faster than enterprise onboarding processes have kept up. In markets where AI tools are being rolled out quickly, that gap is wider than the phishing kits alone — and it is unlikely to stay untargeted.
As The Hacker News reported in its 6 October coverage, the campaign illustrates a pattern security teams will keep meeting: trust borrowed from products employees are eager to use, borrowed before anyone has learned to question it.
據The Hacker News報道,網絡安全研究人員揭露一個由真人操控的釣魚平台,冒充多個主流AI聊天機械人的廣告投放門戶,包括OpenAI的ChatGPT、Google Gemini、Anthropic的Claude、Perplexity、Meta的Muse以及Manus。該行動會即時截取用戶的登入憑證及一次性驗證代碼。
假門戶提供的服務,對任何曾投放過廣告的人都不會陌生:campaign optimisation、spend audits,以及連接至商業帳戶等。然而上述服務全部不存在。這些產品只是藉口,而平台營運者似乎會在受害者輸入資料時即時監察session,把每一次點擊都轉化為登入憑證及multi-factor authentication(MFA)的戰利品。
如何繞過MFA驗證
此機制值得深入關注,因為它正好破解了大多數機構所依賴的最後一道防線。MFA的前提是:持有第二重驗證因素即代表session屬合法。然而當釣魚平台即時截取用戶密碼及其產生的一次性代碼時,這前提便不攻自破:攻擊者並非在代碼過期後才重播被盜代碼,而是直接坐在受害者剛為他們驗證完成的session之中。
MFA正是在這種情況下完全失去保護作用。此外,該攻擊的說服力格外有效,因為其說辭與真實事物吻合。正在為自身工作流程評估AI工具的團隊,早已習慣供應商頁面要求連接帳戶、檢核帳單及登入廣告投放帳戶。假門戶正是借用這套話術。
其營運模式同樣值得注意。這不是發售予匿名買家的自助式釣魚工具包(kit),而是由真人操控的行動。這點改變了威脅的性質:session有人即時監察,驗證代碼在過期前即被截取,而那些察覺異樣並關閉分頁的受害者,可能早已交出了足以致命的資料。
機構應如何應對
針對這類威脅,實際的應對方法並非一般的釣魚意識培訓。提醒員工「留意可疑跡象」只是最基本的底線,而當釣魚內容製作精良、時機又恰到好處時,這顯然不足夠。真正欠缺的是AI工具引入流程中一個專屬的驗證步驟——即採購流程快於安全審查的那個階段。
採用AI工具的團隊應自行透過供應商核實任何門戶,並使用從原始連結或訊息以外途徑取得的聯絡方式。任何關於ad-manager權限、帳單審計或商業帳戶連接的要求,無論表面上多麼緊急或多麼真實,都應按機構的標準審批流程處理。供應商的各個入口點——他們哪些網站實際上會要求提供登入憑證或帳戶連接——值得事先繪製成圖,以便辨認真正(genuine)的提示訊息。
最後,任何已被截取的代碼都應視為已遭洩露。機構應假設可能已存在一個活躍session,並即時吊銷token、強制登出,以及為受影響的帳戶更換憑證。
更廣泛的警訊
被冒充的目標本身已是事件的核心。攻擊者並非以籠統的「科技公司」形象為誘餌,而是模仿特定、增長迅速的AI產品——這些產品的採用速度,已快過企業入職流程所能追上。在AI工具快速鋪開的市場,這一落差遠不止於釣魚工具包本身——而且此類漏洞不太可能長時間不被利用。
正如The Hacker News在10月6日的報道所指出,這起行動揭示了安全團隊將會反覆遇到的模式:信任來自員工急於使用的產品,而這份信任,在任何人學會質疑之前就已被借用。
