Skip to content
Back to blog

Blog

Fake AI Ad Tools Are Stealing Passwords and MFA Codes: How to Protect Your Business

8 October 2026

Many of us now rely on multi-factor authentication (MFA), the extra code or approval prompt when you sign in, as our main protection against stolen passwords. A new phishing campaign shows why it is not enough on its own.

Security researchers have reported a campaign that impersonates AI advertising tools branded as ChatGPT, Gemini, Claude and others. The pages promise to optimise your ad campaigns, audit your spend or connect your business account. In reality, they exist to capture your login details and your MFA code as you enter them.

What Makes This Different

This is not a crude fake email with spelling mistakes. According to the reports:

  • The fake sign-in window is drawn inside the web page itself, so it looks like a genuine browser pop-up.
  • The attackers work live. If you enter a password, they can ask for it again, request a code from your text message, authenticator app or single sign-on prompt, and reject a code to make you enter another.
  • While you are typing, they use what you give them to sign in to your real account straight away.

The main targets are marketing agencies, media buyers and anyone who administers a business advertising account. One compromised account can expose the billing details and budgets of every client behind it. The likely aim is to run the attackers' own campaigns on your money, or to sell on the access.

Why Small Businesses Should Care

You do not need to be an agency to be affected. If you run online ads, manage a company social media account, or have anyone who experiments with the latest AI tools for your business, the same trick can be used on you. The same approach works against Microsoft 365, banking and supplier portals.

The cost is not only a drained ad budget. A hijacked account can damage your reputation, lock you out of your own marketing, and take time to recover.

Three Practical Actions

1. Treat an unexpected sign-in prompt as a warning

If you get an MFA request you did not trigger, do not approve it. It usually means someone already has your password. Change it, and tell whoever looks after your IT.

2. Use stronger sign-in for the accounts that matter most

Passkeys and security keys are tied to the genuine website, so a fake page cannot relay them. Start with advertising, email, finance and administrator accounts, and move away from text-message codes where you can.

3. Check before you connect anything new

Before you link a business account to a new AI tool, go to the vendor's official website yourself rather than following a link from an advert or email. Agree a simple rule that new tools are checked with someone first, and review changes to your advertising account regularly.


Need a Hand?

If you are not sure how well your accounts are protected, or you would like stronger sign-in set up without the headache, we can help. We can review how your team signs in, roll out passkeys and security keys, set up alerts for suspicious sign-ins, and give your staff appropriate Security Awareness Training.

Get in touch and we will tell you where you stand and what to fix first. There is no obligation and no sales pitch, just a straight conversation.

Want to talk through your IT security?

We offer a free, no-obligation assessment for businesses across the UK.

Get in touch