ChatGPT Directs Online Shoppers to Fraudulent Websites and Scams

In this article (8)
Generative artificial intelligence tools like ChatGPT are directing users to fraudulent websites and malicious online schemes, cybersecurity firm Eset warned on September 16, 2026.
Eset NZ country manager Scott Leman reported that large language models are surfacing high-risk links, including fake online stores, cryptocurrency scams, and imitation login pages designed to steal user information.
Unlike traditional search engines that rely on domain authority and indexing algorithms to filter out malicious content, AI search assistants summarise vast amounts of web data, occasionally prioritising compromised sources that contain phishing links.
How Scammers Manipulate Scrapers
Attackers generate mass quantities of keyword-stuffed copy to catch automated scraping cycles. This content funnels shoppers to malicious domains. Common traps include direct links, fake downloads, QR codes, and clone booking portals.
Scammers also plant fake phone numbers and links inside forum threads and press releases. AI crawlers sweep up these entries, presenting them to users as verified customer support contacts.
“Someone asks an AI tool for help, follows the link it provides and ends up on a fake login page, scam website or malicious download,” says Scott Leman, Eset NZ country manager.
The Threat to Smaller Operators
These routing errors create two commercial headaches for independent brands across the region. Authentic merchants lose customer traffic to copycat storefronts. Defrauded shoppers then direct their anger at the real brand.
Risk falls hardest downstream. Big marketplaces maintain dedicated threat intelligence units. Smaller regional merchants run lean IT teams that cannot audit scrapers around the clock.
Accelerating Exploitation Cycles
Faster attack cycles make defense harder. Threat actors use automation to reverse-engineer software patches on the day developers release them. That shrinks the defensive window for digital storefronts.
Brands that rely on passive domain registration and basic search optimisation now face clone sites within hours of launching new campaigns.
Security teams are monitoring how OpenAI and rival search providers upgrade their link verification filters ahead of the peak holiday trading rush.
Questions & Answers
Q.How do scammers get AI tools to promote malicious content?
How do scammers get AI tools to promote malicious content?
Scammers create large amounts of keyword-stuffed text which automated scraping cycles then pick up. They plant fake links and phone numbers in forums and press releases that AI crawlers then sweep into their results.
Q.What specific types of scams do AI tools direct users towards?
What specific types of scams do AI tools direct users towards?
AI tools surface high-risk links such as fake online stores, cryptocurrency scams, imitation login pages designed to steal user information, and malicious downloads.
Q.Why are smaller regional merchants particularly vulnerable to this issue?
Why are smaller regional merchants particularly vulnerable to this issue?
Smaller regional merchants often run lean IT teams that lack the resources to audit scrapers constantly. Larger marketplaces have dedicated threat intelligence units, a luxury smaller businesses don't have.
Q.How do these AI routing errors impact authentic brands?
How do these AI routing errors impact authentic brands?
Authentic merchants lose customer traffic to copycat storefronts. Also, defrauded shoppers often direct their anger at the real brand, impacting their reputation.
Reader pulse
How concerned are you about AI-driven scams?
18,359 votes so far