3 Sources
[1]
ChatGPT Could Help Phishing Scammers Steal Your Banking Login
So far, we've seen large language models (LLMs) like ChatGPT used to produce political propaganda by foreign powers, cheat on academic coursework, and even generate imagery for scam campaigns. But now, researchers are highlighting a new way OpenAI's flagship tool can be used for bad, this time to
[2]
ChatGPT creates phisher's paradise by serving wrong URLs
AI-powered chatbots often deliver incorrect information when asked to name the address for major companies' websites, and threat intelligence business Netcraft thinks that creates an opportunity for criminals. Netcraft prompted the GPT-4.1 family of models with input such as "I lost my bookmark.
[3]
ChatGPT and other AI tools could be putting users at risk by getting company web addresses wrong
Attackers are now optimizing sites for LLMs rather than for Google New research has revealed AI often gives incorrect URLs, which could be putting users at risk of attacks including phishing attempts and malware. A report from Netcraft claims one in three (34%) login links provided by LLMs,
Share
Copy Link
Research reveals that AI-powered chatbots, including ChatGPT, are often providing incorrect URLs when asked about company websites, potentially exposing users to phishing attacks and other cyber threats.
Recent research has uncovered a concerning trend in the world of artificial intelligence: AI-powered chatbots, including popular models like ChatGPT, are frequently providing incorrect URLs when asked about company websites. This oversight could potentially expose users to phishing attacks and other cyber threats, raising significant security concerns in the AI community
1
.
Source: The Register
Cybersecurity firm Netcraft conducted a study using the GPT-4.1 family of models, which powers platforms like Microsoft's Bing AI and Perplexity. The research team prompted the AI with questions about login URLs for 50 different brands across various industries. The results were alarming:
2
This inaccuracy opens up opportunities for cybercriminals to exploit the AI's mistakes. By registering unclaimed domains suggested by the AI, attackers could set up convincing phishing sites to harvest users' sensitive information.
The threat is not merely theoretical. Netcraft's team observed a real-world instance where the AI search engine Perplexity redirected users to a fake Wells Fargo website, which appeared to be a phishing attempt
1
.Smaller brands, such as credit unions, regional banks, and mid-sized fintech platforms, are particularly vulnerable. These companies are often underrepresented in the AI's training data, increasing the likelihood of the AI generating incorrect or "hallucinated" URLs
3
.Related Stories

Source: PC Magazine
In response to the growing reliance on AI-powered search tools, cybercriminals are adapting their strategies. Instead of focusing on traditional search engine optimization (SEO) for platforms like Google, attackers are now optimizing their phishing sites for large language models (LLMs)
2
.This shift in tactics has led to the creation of sophisticated phishing campaigns. For instance, an estimated 17,000 GitBook phishing pages targeting crypto users have been created by mimicking technical support pages, documentation, and login interfaces
3
.
Source: TechRadar
Given these risks, cybersecurity experts are urging users to exercise caution when relying on AI-generated information, especially regarding web addresses. Some key recommendations include:
1
3
As AI continues to play an increasingly prominent role in our digital lives, it's crucial for users to remain vigilant and for AI developers to address these vulnerabilities to ensure a safer online experience.
Summarized by
Navi
[2]