Severity: ElevatedAction: Be aware

Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes

A new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks.

Excerpt from the primary source: BleepingComputer

Who is affected

Home users · Small businesses · Developers · Security professionals

Affected technology: ChatGPT & OpenAI API

What you should do · Be aware

No immediate action is indicated. Share this with the relevant teams and watch for updates.

Automated guidance based on this story's classification. Check the linked advisories for specifics.

Sources

We link to original and authoritative sources. Headlines and excerpts belong to their publishers.

Original reporting

Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes BleepingComputer · bleepingcomputer.com · Oct 6, 2026 · Primary source