When Chatbots Point the Wrong Way: AI Suggests Scam Shops

Security researchers warn that ChatGPT can surface cloned online stores and scam links by absorbing malicious web pages into its training data. Learn how these schemes work and simple steps to avoid losing money or banking details.

When Chatbots Point the Wrong Way: AI Suggests Scam Shops
Reading time: 3 Minutes
Follow on Google

Someone clicked a link that looked official. The price was too good to be true. The parcel never arrived. The bank account was emptied. This is not a tech thriller. It is a pattern security researchers are now spotting where conversational AI meets online fraud.

Recent investigations by fraud-check service Ask Silver found that ChatGPT can surface convincing but fake online stores when users ask about products from familiar British brands such as Russell & Bromley or Dunelm. Attractive discounts. Plausible storefronts. Links that steer shoppers to cloned websites built to steal money and payment details.

When training data becomes a weak link

Attackers plant malicious pages across the web. Those pages are crawled, indexed, and — when the timing is right — absorbed into the sources that feed large language models. The result is what experts call 'data poisoning': the model learns from fraudulent pages and then repeats the same bad guidance to everyday users.

Anna Jones from Ask Silver says criminals sometimes exploit odd moments in a brand's life cycle — like a change of ownership or the official site being down — to feed the AI fake references and make their sites appear legitimate. The trick is simple. Create a believable page. Make it look like the real store. Then let the model pick it up and recommend it.

Lewis Baxter, who heads the fraud team at the UK's National Trading Standards, warns that the mere presence of a website in an AI reply is not a stamp of authenticity. People turn to chatbots for quick shopping advice. Scammers have adapted just as quickly. Seeing a convincing link in a chatbot answer can lull a shopper into skipping basic checks.

The fake storefronts described in the reports are often disturbingly polished. They use domain names close to genuine brands — adding words like onlineuk or official next to a familiar name — and advertise steep discounts, sometimes up to 80 percent, to push buyers into acting without thinking. Many of these sites accept only bank transfers, another red flag.

Always verify the seller directly: search for the store by name, check the official site, and never pay by bank transfer unless you are certain the vendor is legitimate.

So what can users do right now? Slow down. Read the URL carefully. Watch for extra words, odd suffixes, and misspellings. Prefer cards or payment methods that offer buyer protection. If a site insists on a bank transfer, consider it a strong signal to walk away. When possible, type the retailer's name into a search engine or navigate there via a trusted bookmark rather than clicking a link offered by a chatbot.

  • Check the domain closely for extra words or unfamiliar endings.
  • Look for contact details and verifiable social proof.
  • Avoid bank-transfer-only payment options.
  • Use credit cards or payment services with buyer protection.

OpenAI says it has removed identified fraudulent sites from the model's search outputs and offers a way for users to report problematic links. Helpful. Necessary. But not a full fix. Models learn from large swathes of the web, and attackers only need to make a few convincing pages to cause damage.

Ultimately, the responsibility is shared. Tech teams must harden model pipelines and detect poisoning. Platforms must improve link vetting. And shoppers must treat AI suggestions as starting points, not endorsements. Keep curiosity alive. Keep caution closer.

Chloe Nakamura

“I love exploring gadgets, apps, and trends that redefine how we connect, work, and play in a digital world.”

Leave a Comment

Comments (2)

Reza

Slow down ppl, read the URL, check official site. If it asks for bank transfer, walk away 😬

atomwave

Is this even true? Chatbots linking fake shops... can LLMs be trusted anymore? I almost clicked a 'deal' last week, scary.