Fake ChatGPT, Gemini, Claude ad tools steal credentials with live MFA hijacking
TechNadu · x · 2026-10-07
A phishing campaign impersonating ChatGPT, Gemini, Claude and other AI ad tools is stealing credentials. Clicking "Connect" opens a fake browser window displaying spoofed Google or Okta login pages, letting attackers capture passwords and control MFA prompts in real time.
Related event: Fake AI Ad Tool Phishing Campaign Steals Credentials and Bypasses MFA(2 posts)→
More from Safety
- 44 prompt-injection runs, zero bypasses: CLIM Agent Guard enforces a deterministic tool-execution boundary — Slight_Analysis_5414 · 2026-10-07
- POC 2026 talk shows container escape through the NVIDIA GPU driver despite read-only limits — evilsocket · 2026-10-07
- Jaywalking Frames: computer vision catches jaywalkers, photos priced as fines — driesdepoorter · 2026-10-07
- Assessment: ChatGPT's Teen Experience Fails to Alert Parents When It Should — gaganghotra_ · 2026-10-07
- Asilomar 2026 conference lands in three weeks, AI safety community convenes again — prof_kamilov · 2026-10-07
- Anthropic says its AI security effort uncovered over 129,000 verified software vulnerabilities — TansuYegen · 2026-10-07