AI Chatbots Inadvertently Aiding Phishing Scams by Providing Incorrect URLs

Reviewed byNidhi Govil

3 Sources

Research reveals that AI-powered chatbots, including ChatGPT, are often providing incorrect URLs when asked about company websites, potentially exposing users to phishing attacks and other cyber threats.

AI Chatbots Unintentionally Facilitating Phishing Attacks

Recent research has uncovered a concerning trend in the world of artificial intelligence: AI-powered chatbots, including popular models like ChatGPT, are frequently providing incorrect URLs when asked about company websites. This oversight could potentially expose users to phishing attacks and other cyber threats, raising significant security concerns in the AI community 1.

The Scope of the Problem

Source: The Register

Source: The Register

Cybersecurity firm Netcraft conducted a study using the GPT-4.1 family of models, which powers platforms like Microsoft's Bing AI and Perplexity. The research team prompted the AI with questions about login URLs for 50 different brands across various industries. The results were alarming:

  • Only 66% of the provided URLs were correct
  • 29% redirected to dead or suspended websites
  • 5% led to legitimate sites unrelated to the requested brand 2

This inaccuracy opens up opportunities for cybercriminals to exploit the AI's mistakes. By registering unclaimed domains suggested by the AI, attackers could set up convincing phishing sites to harvest users' sensitive information.

Real-World Implications

The threat is not merely theoretical. Netcraft's team observed a real-world instance where the AI search engine Perplexity redirected users to a fake Wells Fargo website, which appeared to be a phishing attempt 1.

Smaller brands, such as credit unions, regional banks, and mid-sized fintech platforms, are particularly vulnerable. These companies are often underrepresented in the AI's training data, increasing the likelihood of the AI generating incorrect or "hallucinated" URLs 3.

Evolving Tactics of Cybercriminals

Source: PC Magazine

Source: PC Magazine

In response to the growing reliance on AI-powered search tools, cybercriminals are adapting their strategies. Instead of focusing on traditional search engine optimization (SEO) for platforms like Google, attackers are now optimizing their phishing sites for large language models (LLMs) 2.

This shift in tactics has led to the creation of sophisticated phishing campaigns. For instance, an estimated 17,000 GitBook phishing pages targeting crypto users have been created by mimicking technical support pages, documentation, and login interfaces 3.

Recommendations for Users

Source: TechRadar

Source: TechRadar

Given these risks, cybersecurity experts are urging users to exercise caution when relying on AI-generated information, especially regarding web addresses. Some key recommendations include:

  1. Double-check URLs for inconsistencies before inputting sensitive data
  2. Verify any AI-generated content involving web addresses
  3. Type URLs directly into the search bar rather than clicking on provided links
  4. Be particularly cautious with URLs for smaller or less well-known brands 1 3

As AI continues to play an increasingly prominent role in our digital lives, it's crucial for users to remain vigilant and for AI developers to address these vulnerabilities to ensure a safer online experience.

Explore today's top stories

Databricks Secures $1 Billion Funding at $100 Billion Valuation, Targets AI Database Market

Databricks raises $1 billion in a new funding round, valuing the company at over $100 billion. The data analytics firm plans to invest in AI database technology and an AI agent platform, positioning itself for growth in the evolving AI market.

TechCrunch logoReuters logoCNBC logo

12 Sources

Business

22 hrs ago

Databricks Secures $1 Billion Funding at $100 Billion

Microsoft Excel Introduces AI-Powered COPILOT Function for Advanced Data Analysis

Microsoft has integrated a new AI-powered COPILOT function into Excel, allowing users to perform complex data analysis and content generation using natural language prompts within spreadsheet cells.

The Verge logoThe Register logoXDA-Developers logo

9 Sources

Technology

22 hrs ago

Microsoft Excel Introduces AI-Powered COPILOT Function for

Adobe Revolutionizes PDF with AI-Powered Acrobat Studio

Adobe launches Acrobat Studio, integrating AI assistants and PDF Spaces to transform document management and collaboration, marking a significant evolution in PDF technology.

Wired logoThe Verge logoXDA-Developers logo

10 Sources

Technology

22 hrs ago

Adobe Revolutionizes PDF with AI-Powered Acrobat Studio

Meta Launches AI-Powered Voice Translation for Facebook and Instagram Creators

Meta rolls out an AI-driven voice translation feature for Facebook and Instagram creators, enabling automatic dubbing of content from English to Spanish and vice versa, with plans for future language expansions.

TechCrunch logoCNET logoThe Verge logo

5 Sources

Technology

14 hrs ago

Meta Launches AI-Powered Voice Translation for Facebook and

Nvidia Enhances App with Global DLSS Override and AI-Powered Features for Smoother Gaming Experience

Nvidia introduces significant updates to its app, including global DLSS override, Smooth Motion for RTX 40-series GPUs, and improved AI assistant, enhancing gaming performance and user experience.

The Verge logoThe How-To Geek logoDigital Trends logo

4 Sources

Technology

22 hrs ago

Nvidia Enhances App with Global DLSS Override and
TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo