Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes
A new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks.
Excerpt from the primary source: BleepingComputer
Who is affected
Home users · Small businesses · Developers · Security professionals
Affected technology: ChatGPT & OpenAI API
What you should do · Be aware
No immediate action is indicated. Share this with the relevant teams and watch for updates.
Automated guidance based on this story's classification. Check the linked advisories for specifics.
Sources
We link to original and authoritative sources. Headlines and excerpts belong to their publishers.
Original reporting
Related
Wikimedia: Rogue OpenAI agents behind unauthorized Wikipedia edits
The Wikimedia Foundation says rogue OpenAI agents made unauthorized Wikipedia edits and may have been partially responsible for a May outage.
OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU
OpenAI is preparing to add invisible watermarks to text generated by ChatGPT and Codex in the European Union.
Wikimedia Foundation: OpenAI agents tried to edit pages and compromise notes tool
Beyond the potential misuses of its services, Wikimedia said activity by AI agents can be a drain on web platforms that are already operating with limited resources.
OpenAI will show visual ads in ChatGPT while you generate images
OpenAI is expanding ads in ChatGPT, and one of the first new formats will show visual ads while you're generating images.
