Island reports phishing platform posing as AI advertising tools
Island researchers described a human-operated phishing platform disguised as AI advertising products, impersonating Gemini, Claude, ChatGPT and Perplexity. Island said it observed hundreds of victim submissions while the campaign was active.

Key takeaways · 4
- 01
The fake advertising products impersonated Gemini, Claude, ChatGPT and Perplexity.
- 02
A fake browser window could show a trusted Google address while the real browser stayed on the phishing domain.
- 03
Operators could review submissions, choose what a victim saw next and preserve submitted values.
- 04
Island recommends verifying AI programs and account connectors on vendors’ official websites before connecting accounts.
AI advertising offers served as lures
Island researchers described a human-operated phishing platform disguised as AI advertising products, which impersonated Gemini, Claude, ChatGPT and Perplexity.[1] One example was Muse Ads, presented on museads.ai by September 16, after Meta introduced Muse as a personal AI agent on September 8, 2026.[1] Muse Ads promised to help advertisers reach buyers, connect an advertising account and run sponsored placements.[1] The lures also included a Google Ads briefing, manager-account features and support for linked clients.[1] The date shown on Island’s report is October 6, 2026.[1]
The login window was part of the page
Clicking Connect opened a browser-like window drawn inside the phishing webpage rather than opening Google.[1] That imitation could display trusted-looking addresses such as accounts.google.com while the actual browser remained on the phishing domain.[1] The fake browser was designed to adapt to Windows, macOS, iOS and Android.[1] The platform also fingerprinted devices using information including IP address, location, screen size and WebGL data.[1] For teams, the practical lesson is to check the real browser address and verify a purported AI service or connector through the vendor’s official website before granting account access.[1]
Operators controlled the interaction
The platform supported authentication workflows for Google, Meta, TikTok and Okta.[1] It locally rebuilt provider interfaces and collected credentials and MFA state through its own APIs.[1] An operator could see each submission and decide what the victim saw next; operators could also reject an entry, prompt the victim to try again and preserve every submitted value.[1] That human control means an apparently familiar sign-in flow should not be treated as proof that a login is genuine.[1]
Advertising accounts were the target
Island said the lures targeted agency staff, media buyers and manager-account administrators because advertising accounts are spending accounts.[1] Stolen accounts could be used to run attackers’ campaigns or sold for profit, and Island cited research that aged accounts with clean spending histories could sell for two to four times the price of new accounts.[1] Attackers could also add their own administrators and downgrade legitimate owners, with recovery taking weeks or months.[1] Island recommended phishing-resistant authentication, including origin-bound passkeys and hardware-backed authentication, to reduce reliance on reusable passwords and one-time codes.[1]
Advertising teams should treat new AI tools that request account access as a security decision, not just a software trial. The combination of account spending authority and operator-controlled sign-in flows makes independent verification and phishing-resistant authentication useful safeguards.
Why it matters
Test yourself on this story — 1 question.
Create a free account to take the quiz, earn XP, and get a daily session built for your industry.
Take the quizHow this developed
8 October 2026
Island reports phishing platform posing as AI advertising tools