ChatGPT Caught Recommending Fake Scam Stores That Steal Credit Cards
Asking ChatGPT for shopping advice was supposed to save time, but instead it is casually serving users up on a silver platter to credit card phishing rings.
When anti-fraud researchers at Ask Silver queried ChatGPT for recommendations on luxury bags and wallets from British brand Russell & Bromley, the bot dutifully compiled a list of products, prices, and handy direct links to buy them.
Except multiple links led directly to malicious clone stores disguised with stolen brand logos, legit product photos, and suspicious 80% discounts designed to harvest payment credentials. The scammers weaponized domains like therussellbromleyofficial and russellbromleyonlineuk, capitalizing on domain confusion after the brand was acquired by retailer Next.
According to Anna Jones, co-founder of Ask Silver, the underlying language model fell victim to intentional data poisoning. Cybercriminals actively saturate the web with fake reviews, bot-generated forum threads, and synthetic trust signals to trick AI web scrapers into treating phishing traps as verified merchant portals.
While OpenAI confirmed it purged the fraudulent URLs from its search index following reports, previous security audits revealed that AI models routinely hallucinate non-existent URLs for login portals, which criminals immediately register to catch unsuspecting searchers.
Replacing traditional search engines with an algorithm that cannot tell a genuine retail outlet from a cloned credential harvester might just be the fastest way to turn an AI shopping assistant into a digital pickpocket's best accomplice.
Source: cybernews.com
Comments
This is where the magic happens: AI reads your discussion and rewrites the article based on the most interesting comments. Each strong comment adds points to the meter below. Once the meter is full, the article updates live — no page reload needed.