What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Fake AI advertising sites are using a “Connect” button to steal sign-in details for advertising accounts. The button opens a counterfeit browser window inside the page, where operators can prompt for passwords and authentication codes while the real browser remains on a phishing site. Island reported the campaign on October 6, 2026; its researchers saw hundreds of submissions, but did not establish a campaign-wide total of confirmed takeovers or financial losses.

How the fake AI advertising sites worked

The sites presented themselves as advertising tools built around familiar AI brands, including ChatGPT, Gemini, Claude, Perplexity and Manus. Their pitches included campaign optimization, spend audits and weekly briefings. Island also reported that operators later added a fake Meta Muse Ads product.

Rather than asking only for a password on a plainly suspicious page, the sites framed sign-in as part of a business task: connecting an advertising account to the purported tool. That made the request look like a routine step in using the product.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The counterfeit “Connect” sign-in window

Clicking Connect did not take users to the genuine provider’s sign-in page. The phishing page drew a fake browser window within its own content and displayed a trusted-looking address, such as accounts.google.com or an Okta tenant. The actual browser remained on the phishing domain.

#1 Best Overall
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Island researchers Oleg Zaytsev, Lead Security Researcher, and Ofek Ronen, Security Researcher, described it this way: “Each product was built around the same action: Connect. Clicking it opened a browser drawn inside the real browser. The fake address bar displayed trusted origins such as accounts.google.com or an Okta tenant, while the real browser remained on the phishing domain.” Island’s October 6, 2026 report details the campaign.

How passwords and MFA responses could be captured

The platform retained password attempts, fingerprinted visitors’ devices and let a human operator choose which prompt to show next. Island described workflows involving Google, Meta, TikTok and Okta, with challenges including SMS and authenticator codes, Google approval prompts or QR flows, and Okta push or authenticator challenges.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

That operator-controlled sequence matters: a code entered into a counterfeit sign-in flow can be relayed or captured while a real sign-in is in progress. An approval request can also be part of a deceptive interaction. This does not mean MFA is useless; it means users should not enter a code or approve a request they did not initiate through the genuine service.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to tell whether a sign-in window is real

A browser-like window drawn inside a webpage can copy the appearance of browser controls, including an address bar. The text shown inside that imitation is not proof that the browser has navigated to the named service.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  • Check the address in the browser’s actual address bar, outside the page content. If you are still on the AI tool’s domain, a sign-in-looking window inside it is not the provider’s website.
  • Do not use a login link or embedded sign-in window from an unsolicited message or unfamiliar tool. Open the service by entering its known address or using a trusted bookmark, then navigate to the relevant account directly.
  • Pause if a tool unexpectedly requests access to a business advertising account, a password, a one-time code or an approval. Verify with your organization or the service through a known channel.
  • Never treat a familiar logo, browser-style frame or displayed provider address as authentication. The real domain in the browser’s address bar is the key check.

Google Ads Help warns: “Google will never send an unsolicited message asking you to provide your password or other sensitive information by email or through a link.” Its guidance on suspicious emails or calls claiming to be from Google Ads also advises checking link destinations and reporting suspicious pages. Google’s June 2026 frauds and scams advisory discusses attacks that capture session cookies and can bypass MFA, and recommends navigating directly to official websites.

What to do if you entered a password or MFA code

Use the genuine service, reached directly—not a link in the suspicious page—to secure the account. If you entered a password, treat it as exposed. If you entered a one-time code or approved a prompt, assume the sign-in attempt may have been relayed and check the account immediately.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  1. Change the exposed password. If you reused it elsewhere, change it on every affected service, using each official site or app.
  2. End active sessions. Sign out of sessions you do not recognize, or use the service’s option to log out all active sessions where available.
  3. Review account security activity. Look for unfamiliar sign-ins, devices, connected applications, recovery changes or activity involving advertising accounts. Revoke access or sessions you do not recognize.
  4. Contact the service’s official support or security channel. For business accounts, alert the account owner or your organization’s security team so they can review access and connected ad accounts.
  5. Report the phishing page. Use the relevant service’s reporting process, including Google Ads Help’s instructions for suspicious pages.

For an exposed or reused OpenAI password, OpenAI advises changing it, logging out of active sessions, reviewing security history and contacting OpenAI Support if unauthorized activity is suspected. Its account security guidance also recommends a unique password and MFA. Meta, TikTok and Okta account recovery and session controls are service-specific; follow the official guidance for the affected service rather than assuming the same menu or recovery steps apply everywhere.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How advertising teams can reduce the risk

  • Use unique passwords. A password manager helps generate and store credentials that are not reused across services. OpenAI’s guidance puts it plainly: “We recommend using a password manager to generate and store passwords.”
  • Keep MFA enabled, but verify the interaction. MFA remains an important safeguard. Do not share a code with a page or person, and do not approve a sign-in request you did not initiate on the genuine service.
  • Consider phishing-resistant sign-in options. Where a service and your organization support them, hardware security keys can provide an additional option. OpenAI references a YubiKey bundle for eligible users; a YubiKey security key is not a cure for phishing and does not remove the need to verify the domain. Confirm service support and recovery procedures before relying on any particular method.
  • Make direct navigation routine. For advertising accounts, use saved official bookmarks or the organization’s established access process instead of connecting accounts through unfamiliar AI tools.
  • Review account access periodically. Check active sessions, security history and connected applications, especially after a suspicious sign-in or an employee interaction with a questionable tool.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the reported numbers do—and do not—show

Island said it observed hundreds of submissions to the platform and that activity was ongoing when its report was published on October 6, 2026. A submission is not proof of a confirmed account takeover, and the report did not establish a campaign-wide number of confirmed compromises or financial losses.

Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.

A separate set of figures should not be mistaken for the impact of this account-phishing operation. The Hacker News’ October 6, 2026 summary of Island’s findings reported about 850 paid-ad landings, 26 lookalike ChatGPT destinations and 71 Google Ads campaign IDs across a broader delivery cluster observed over three months ending in August 2026. Those are delivery-related measures, not victim or takeover counts, and they should not be attributed solely to the fake advertising-account sign-in platform. The related sponsored-search/ClickFix malware campaign is distinct from this account-phishing operation. The Hacker News summary provides the broader-cluster context.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.