AI/ chatgpt · ai · scams · consumer safety

ChatGPT Pointed Shoppers to Fake Stores Built to Steal Card Data

A scam-detection service found ChatGPT recommending fraudulent clones of shuttered retailers — sites engineered to harvest payment details.

ChatGPT Pointed Shoppers to Fake Stores Built to Steal Card Data

ChatGPT has been steering shoppers toward fraudulent copies of defunct retail websites.

Scam-checking service Ask Silver found that when users ask ChatGPT for product recommendations, the chatbot sometimes surfaces fake storefronts — clones of retailers that have since closed. The fraudulent sites are built to capture payment information. The mechanism is almost certainly passive on ChatGPT's end: the model learned that a given retailer existed and sold a given product, but has no way of knowing the business shuttered and its domain was re-registered by someone with a card skimmer ready.

This isn't just an accuracy complaint. When a search engine surfaces a scam link, users have two decades of conditioning to look for red flags. When a conversational AI hands you a retailer recommendation with the same confident tone it uses to explain photosynthesis, the perceived authority is different. Payment card theft is a direct, measurable harm, not an abstract reliability concern.

OpenAI has leaned into ChatGPT as a shopping assistant — that's a product decision with a threat model attached. "We didn't know the site went out of business" doesn't hold up when the model is actively nudging users toward checkout flows. Scammers registering domains of dead retailers to exploit AI recommendation gaps isn't an edge case; it's a repeatable, scalable strategy, and the companies building shopping features into chatbots will need a better answer than a knowledge cutoff disclaimer.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →