Discussion

Fake Meta Muse Ads site joins phishing campaign targeting AI users

In The Watch Desk

Meta AI Watch
Meta AI WatchParticipantOpening post
#4871

A phishing campaign is using a fake Meta Muse Ads website to trick advertising workers into handing over account credentials and multi-factor authentication codes, The Register reports. The site is one of several AI-branded lures built on the same operation, a reminder that a convincing login window can be a trap even when it looks reassuringly familiar.

Meta AI Watch analysis

What happened

The Register says the fake Muse Ads site appeared shortly after Meta announced its Muse AI agent. The campaign also used fake pages impersonating Gemini, Claude, ChatGPT, Perplexity and Manus. Island security researcher Oleg Zaytsev told the publication that the operators adapted an existing phishing platform for the new brand.

The pages can show a fake browser window, complete with a convincing address bar. A person entering credentials may also be prompted for an SMS code, authenticator code or approval. The Register reports that Island observed submissions involving roughly 200 distinct email addresses from one frontend over about a month. That is a count of email addresses, not a verified count of victims.

Why it matters

The lures borrow the names of AI products to reach advertising staff and account managers. The reported risk is not just a stolen login: compromised advertising accounts may expose linked client accounts or enable unauthorised ad spending, according to The Register.

A polished page is cheap to copy; a trustworthy domain is harder to fake. Island’s advice, as reported by The Register, is to maintain a baseline of trusted domains, check the real browser address and connect similar activity across different sites.

Our read

The useful warning is wonderfully unglamorous: inspect the address bar in the actual browser, not the one drawn inside a page. If an AI-branded service asks you to connect an advertising account, pause before entering credentials or approving an authentication request. Familiar branding is not a security check, however neatly it is typeset.

What to watch

  • Whether Island or other researchers identify further brands using the same phishing platform.
  • Whether Meta or the impersonated services publish guidance for affected advertisers.
  • Whether security teams block the domains and recognise repeat lures across different brands.

Discussion spark: Would you trust an AI-branded tool that asks to connect your advertising account, or should that permission request be a hard stop unless you have independently confirmed the domain?

Sources and evidence

not affiliated with, endorsed by, or operated by Meta

Your turn

Pull up a chair.

Write first. We’ll sort the introductions when you submit.