AI Chatbots Inadvertently Aiding Phishing Scams by Providing Incorrect URLs

Reviewed byNidhi Govil

3 Sources

Research reveals that AI-powered chatbots, including ChatGPT, are often providing incorrect URLs when asked about company websites, potentially exposing users to phishing attacks and other cyber threats.

AI Chatbots Unintentionally Facilitating Phishing Attacks

Recent research has uncovered a concerning trend in the world of artificial intelligence: AI-powered chatbots, including popular models like ChatGPT, are frequently providing incorrect URLs when asked about company websites. This oversight could potentially expose users to phishing attacks and other cyber threats, raising significant security concerns in the AI community 1.

The Scope of the Problem

Source: The Register

Source: The Register

Cybersecurity firm Netcraft conducted a study using the GPT-4.1 family of models, which powers platforms like Microsoft's Bing AI and Perplexity. The research team prompted the AI with questions about login URLs for 50 different brands across various industries. The results were alarming:

  • Only 66% of the provided URLs were correct
  • 29% redirected to dead or suspended websites
  • 5% led to legitimate sites unrelated to the requested brand 2

This inaccuracy opens up opportunities for cybercriminals to exploit the AI's mistakes. By registering unclaimed domains suggested by the AI, attackers could set up convincing phishing sites to harvest users' sensitive information.

Real-World Implications

The threat is not merely theoretical. Netcraft's team observed a real-world instance where the AI search engine Perplexity redirected users to a fake Wells Fargo website, which appeared to be a phishing attempt 1.

Smaller brands, such as credit unions, regional banks, and mid-sized fintech platforms, are particularly vulnerable. These companies are often underrepresented in the AI's training data, increasing the likelihood of the AI generating incorrect or "hallucinated" URLs 3.

Evolving Tactics of Cybercriminals

Source: PC Magazine

Source: PC Magazine

In response to the growing reliance on AI-powered search tools, cybercriminals are adapting their strategies. Instead of focusing on traditional search engine optimization (SEO) for platforms like Google, attackers are now optimizing their phishing sites for large language models (LLMs) 2.

This shift in tactics has led to the creation of sophisticated phishing campaigns. For instance, an estimated 17,000 GitBook phishing pages targeting crypto users have been created by mimicking technical support pages, documentation, and login interfaces 3.

Recommendations for Users

Source: TechRadar

Source: TechRadar

Given these risks, cybersecurity experts are urging users to exercise caution when relying on AI-generated information, especially regarding web addresses. Some key recommendations include:

  1. Double-check URLs for inconsistencies before inputting sensitive data
  2. Verify any AI-generated content involving web addresses
  3. Type URLs directly into the search bar rather than clicking on provided links
  4. Be particularly cautious with URLs for smaller or less well-known brands 1 3

As AI continues to play an increasingly prominent role in our digital lives, it's crucial for users to remain vigilant and for AI developers to address these vulnerabilities to ensure a safer online experience.

Explore today's top stories

Capgemini Acquires WNS for $3.3 Billion to Boost AI-Powered Intelligent Operations

French tech giant Capgemini agrees to acquire US-listed WNS Holdings for $3.3 billion, aiming to strengthen its position in AI-powered intelligent operations and expand its presence in the US market.

euronews logoSilicon Republic logoAnalytics India Magazine logo

10 Sources

Business and Economy

6 hrs ago

Capgemini Acquires WNS for $3.3 Billion to Boost AI-Powered

Google DeepMind's Isomorphic Labs Nears Human Trials for AI-Designed Drugs

Isomorphic Labs, a subsidiary of Alphabet, is preparing to begin human trials for drugs developed using artificial intelligence, potentially revolutionizing the pharmaceutical industry.

Fortune logoBenzinga logoDigit logo

3 Sources

Science and Research

14 hrs ago

Google DeepMind's Isomorphic Labs Nears Human Trials for

BRICS Nations to Advocate for AI Data Protection and Fair Compensation

BRICS leaders are set to call for protections against unauthorized AI use, addressing concerns over data collection and fair payment mechanisms during their summit in Rio de Janeiro.

Reuters logoU.S. News & World Report logoMarket Screener logo

3 Sources

Policy and Regulation

22 hrs ago

BRICS Nations to Advocate for AI Data Protection and Fair

Huawei's AI Lab Refutes Accusations of Copying Alibaba's Model in Pangu Pro Development

Huawei's AI research division, Noah Ark Lab, denies allegations that its Pangu Pro large language model copied elements from Alibaba's Qwen model, asserting independent development and adherence to open-source practices.

Bloomberg Business logoReuters logoEconomic Times logo

3 Sources

Technology

6 hrs ago

Huawei's AI Lab Refutes Accusations of Copying Alibaba's

Samsung's Q2 Profit Expected to Plunge 39% Amid AI Chip Supply Challenges

Samsung Electronics is forecasted to report a significant drop in Q2 operating profit due to delays in supplying advanced memory chips to AI leader Nvidia, highlighting the company's struggles in the competitive AI chip market.

Reuters logoMarket Screener logo

2 Sources

Business and Economy

14 hrs ago

Samsung's Q2 Profit Expected to Plunge 39% Amid AI Chip
TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo