Security firm Island published research on October 6, 2026 about a phishing platform that poses as advertising products from ChatGPT, Gemini, Claude, Perplexity, Manus and Muse. Its "Connect" button opens a fake Google sign-in window that captures passwords and verification codes. The targets are people who manage ad accounts.
What we know
- Who is reporting it: Island, a security company that sells an enterprise browser, in a report dated October 6, 2026 by Oleg Zaytsev and Ofek Ronen. It describes a human-operated platform. This is third-party research, not an advisory from Google, OpenAI, Anthropic or Meta.
- Which brands it copies: according to Island, it was already using the names of Gemini, Claude, ChatGPT, Perplexity and Manus. The newest skin, "Muse Ads", was live by September 16, eight days after Meta introduced its Muse agent on September 8, by that report's dates.
- How it arrives: through invitation emails, which Island says IRONSCALES and Intezer have documented. On September 9 IRONSCALES described one with the subject line "Your Gemini Ads workspace is ready", sent to a paid-media manager at an agency. According to that firm, the message passed SPF, DKIM and DMARC checks.
- What "Connect" does: it does not open Google. The page draws a browser window inside itself, with a lock icon and an address bar showing accounts.google.com or a company's Okta address. The real browser stays on the phishing domain. The technique is known as browser-in-the-browser.
- What it takes: every password attempt (it keeps up to three), verification codes and a device fingerprint. An operator watches each submission live and chooses what the victim is asked next. Island describes flows for Google, Meta, TikTok and Okta accounts.
- How far it reaches: Island says it saw hundreds of victim submissions to the platform and that activity was ongoing when it wrote the report. It does not say how many accounts were lost or in which countries, and it does not attribute the operation to any group.
- Why ad accounts: an ad account holds a stored payment method and an approved budget, and a manager account (MCC) reaches several client accounts. Recovery can take weeks or months, according to Island.
Island's indicator list contains 89 ad-lure domains. Counted for this article: 20 carry "claude" or "anthropic", 17 imitate Gemini (two of them misspelled), 12 carry "chatgpt" or "openai", 5 "manus" and 4 "perplexity". Another 11 carry "mcc". The names of Semrush, Mistral, Cursor and TikTok show up too.
What changes and what doesn't
The lure changes. It is no longer the "your account has been suspended" notice: it is a believable product with an AI brand and advertiser vocabulary. And it arrives while real products are moving too. On October 5 OpenAI said it will test a new ad format in ChatGPT and that businesses can sign up at ads.openai.com.
The basics do not change. A page can draw an address bar, but it cannot change the real browser address, Island notes. And there is no flaw in Google Ads, ChatGPT, Gemini or Claude here: the report describes deception, not a vulnerability.
Anthropic said on February 4, 2026 that Claude will stay ad-free, and that post is still on its site. Even so, 20 of the 89 domains use its name, by this article's count. The hook does not need the product to exist.
How to tell if this affects you
It does if you, someone on your team or whoever runs your advertising signs in to Google Ads, Meta or TikTok with an account that has a payment method on file. Seven steps:
- Treat the invitation as an access request. An "AI ads" beta you never asked for is asking for the keys to your account.
- Go there yourself. Skip the button in the email: type the vendor's official address and look for the program there.
- Read the bar at the very top. Before typing a password, read the browser's own address, not the one in the window that just appeared. On a computer, try dragging that window off the page: a real one leaves the page's edges, a drawn one cannot.
- If the right password is rejected, stop. Island describes a platform that asks for retries and keeps every one. Change it from the official site.
- Turn on a passkey or a hardware security key for the account that runs your ads. Island recommends it: it is bound to the real domain and leaves no reusable password or code.
- Check who has access. In Google Ads, the "Access and security" section lists users and linked manager accounts. Remove anything you do not recognize, in Meta and TikTok too.
- If you already typed your details: change the password, sign out of open sessions and look for new users, changed recovery details and campaigns or spend nobody approved.
If an agency or a freelancer runs your ads, ask who holds admin access and which verification method they sign in with.
Related: Claude for Startups: Free Year of Claude Team, $1,000 Credits
Sources
- Island, "Behind the Connect Button: The Fake AI Ads Campaign", October 6, 2026
- IRONSCALES, advisory on the fake "Gemini Ads" invitation, September 9, 2026
- Anthropic, "Claude is a space to think", February 4, 2026
- OpenAI, "Building advertising for the way people use AI", October 5, 2026
Updates: this note will be extended if Google, OpenAI, Anthropic or Meta comment on this campaign, or if Island updates its report.