Saltar al contenido
ES EN

Fake AI ad tools target advertisers' accounts: how to spot them

Island researchers found fake AI advertising tools aimed at agency and ad-account staff. Here is who is targeted and how to keep your accounts safe.

In 30 seconds Researchers at Island found fake websites posing as advertising products from AI brands such as ChatGPT, Gemini and Claude. They ask advertisers to connect their business accounts and then take them over. The targets are advertising accounts. Treat any unexpected invitation to an AI ads tool as suspicious until you verify it.

What happened

Island researchers Oleg Zaytsev and Ofek Ronen published details of a phishing operation that imitates advertising products from major AI companies, including ChatGPT, Gemini, Claude, Perplexity, Meta and Manus. The sites promise campaign optimisation and spend audits, and every one of them asks the visitor to connect a business account.

A close up of a cell phone with a keyboard
Image: Unsplash — A close up of a cell phone with a keyboard

That connection step is the trap: it is a fake sign-in that hands the account to the attackers. Victims are believed to arrive through invitation emails that impersonate the AI brands.

Who is targeted

The operation goes after agency staff, media buyers and the administrators of advertising manager accounts. A hijacked ad account with a clean spending history can be resold or used to run fraudulent ads, and Island notes that recovering one can take weeks or months. For a manager account, the damage reaches the agency's clients too. Mimecast reported in July 2026 that ad account theft has become a widespread commodity crime.

How to protect yourself

  • Verify any invitation to an AI advertising tool through the vendor's official website or your account manager, never through a link in the email.
  • Use passkeys or FIDO2 security keys for advertising and Google accounts: they only work on the real site, so a fake page cannot reuse them.
  • Check the real address in your browser's own address bar before you sign in, and be wary of sign-in windows that appear inside a web page.
  • Review new administrators and permission changes on your ad accounts regularly.
  • Report suspicious invitations to the advertising platform and to your security team.

What we don’t know yet

The material does not say how many accounts were compromised or who runs the operation.

Original source: The Hacker News

Produced with AI support and reviewed by the newsroom

Byline

· Chief editor · English edition · London

“Phishing-resistant sign-in costs far less than recovering a hijacked ad account.”

Comentarios

Publicar un comentario