Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hackers Mimic as OpenAI and Sora Services to Steal Login Credentials

## Phishing Campaign Targeting AI Services

Phishing Campaign Targeting AI Services

A recent phishing campaign has emerged that targets users of AI services by impersonating OpenAI and the Sora 2 AI platform. The campaign uses cloned landing pages to deceive users into divulging login credentials, participating in false surveys, and engaging in cryptocurrency scams.

Security researchers advise caution, recommending users verify URLs before interacting with any AI services.

The phishing sites replicate OpenAI branding but host fraudulent content. For instance, the domain "gotosora2.com/pricing" offers subscription plans with a design that closely resembles the legitimate OpenAI portal. However, the underlying metadata includes unauthorized Chinese descriptions and keywords.

Users attempting to select a plan are redirected to fake login forms that collect email addresses and passwords for malicious use.

The campaign extends beyond English, targeting other languages such as Russian. The site sora2.tech offers services in Russian, complete with professionally translated text and interactive elements.

A recent phishing campaign has emerged that targets users of AI services by impersonating OpenAI and the Sora 2 AI platform.
Rebecca Stone · Thehackingpost

After providing credentials, victims are prompted to complete bogus surveys or offers, collecting further personal data.

Some phishing sites promote counterfeit cryptocurrency tokens like SORA2 or $SORA2, encouraging purchases on decentralized exchanges. These tokens typically exhibit characteristics of fraudulent schemes, with users exchanging real funds for worthless assets.

To mitigate phishing risks, users should:

Verify domains against official sources. Inspect metadata for inconsistencies. Avoid links from social media or third-party referrals. Use multi-factor authentication and password managers.

Advertisement

For AI-related services, navigate directly to the official websites such as openai.com or sora.so.

As phishing tactics become more sophisticated, vigilance and careful verification of URLs are crucial for protection against impersonation scams.

Stay informed and prioritize online safety.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories