Phishing Sites Impersonate AI Tools to Steal Ad Accounts, MFA Codes A phishing campaign that impersonates AI tools has harvested hundreds of victim submissions, stealing advertising accounts and multi-factor authentication codes, according to a report on the operation. The scammers use a browser-in-the-browser technique to present fake login prompts that closely mimic legitimate sign-in pages and are difficult to detect. Scammers are now using fake AI tools to trick victims into handing over their ad accounts and multi-factor authentication codes, with one phishing campaign gathering hundreds of victim submissions. They're getting clever with a technique called browser-in-the-browser, creating fake login prompts that look legit and are almost impossible to spot.