Island researchers found fake AI advertising tools aimed at agency and ad-account staff. Here is who is targeted and how to keep your accounts safe.
What happened
Island researchers Oleg Zaytsev and Ofek Ronen published details of a phishing operation that imitates advertising products from major AI companies, including ChatGPT, Gemini, Claude, Perplexity, Meta and Manus. The sites promise campaign optimisation and spend audits, and every one of them asks the visitor to connect a business account.

That connection step is the trap: it is a fake sign-in that hands the account to the attackers. Victims are believed to arrive through invitation emails that impersonate the AI brands.
Who is targeted
The operation goes after agency staff, media buyers and the administrators of advertising manager accounts. A hijacked ad account with a clean spending history can be resold or used to run fraudulent ads, and Island notes that recovering one can take weeks or months. For a manager account, the damage reaches the agency's clients too. Mimecast reported in July 2026 that ad account theft has become a widespread commodity crime.
How to protect yourself
- Verify any invitation to an AI advertising tool through the vendor's official website or your account manager, never through a link in the email.
- Use passkeys or FIDO2 security keys for advertising and Google accounts: they only work on the real site, so a fake page cannot reuse them.
- Check the real address in your browser's own address bar before you sign in, and be wary of sign-in windows that appear inside a web page.
- Review new administrators and permission changes on your ad accounts regularly.
- Report suspicious invitations to the advertising platform and to your security team.
What we don’t know yet
The material does not say how many accounts were compromised or who runs the operation.
Original source: The Hacker News
Produced with AI support and reviewed by the newsroom



Comentarios
Publicar un comentario