ChatGPT and Phishing: How AI Can Hand You a Scam
Free online ChatGPT and Phishing that runs directly in your browser.
AI is a great tool - until it tells you to click the wrong link
You ask a question, you get an answer, you click. Simple, right?
But what if the link the AI gave you leads to the wrong place? Or worse – straight to a fake bank website?
Netcraft's report shows that this is not pure what-ifs. ChatGPT and other chatbots sometimes provide links… that don't exist. And this opens the gates to a new generation of phishing.
When a chatbot gives you the wrong address - a real-life scenario
Imagine: your online banking shortcut doesn't work.
You ask ChatGPT: "Give me the link to log in to XYZ Bank."
You get your answer. Sounds reasonable. You click.
And that might be the biggest mistake of the day.
🔍 What did the Netcraft test reveal?
Experts asked ChatGPT questions about the addresses of well-known brands - from banks, through stores, to technology companies. Results?
-
Only66% ofresponses contained a valid link
-
29%led to dead or suspended domains
-
5%pointed to real sites, but... not the ones you wanted
Sounds like harmless? Now imagine that someoneregistersone of these dead domains and puts a fake login page on it.
💀 When "almost good" = very bad
Chatbot cannot tell the difference between a real address and what "sounds like" a real address.
If someone asks for a login to "BankX" and the AI givesbankx-login.com- it could be a link to nowhere. But just a few hours later... there may be a ready-made phishing trap there.
Without any hacking.
No hacking.
Just a quick domain registration and you're done.
Scammers are already taking advantage of it
AI opens new doors - and someone is already waiting there
Phishers have always acted quickly. But now they have a new weapon - AI, which itself shows them whichdomains are worth registering. And this is before users even realize that something is wrong.
🕵️♂️ How does this scheme work?
-
The chatbot provided an incorrect or non-existent address for the bank/shop website.
-
Scammer registers this domain - works quickly before someone corrects it.
-
Builds a "live" website - login, logo, form.
-
Waits for another user to ask ChatGPT for the same address.
Boom – done. Phishing served on a platter, with a link straight from AI.
🧠 ChatGPT doesn't check what
recommends It's not a search engine. Does not check links in real time.
Can't see if the page exists. It works "linguistically" - it gives whatsounds credible. And this is enough for the clicking user to enter something that looks like the truth.
⚠️ CASE: fake bank, real loss
Netcraft described a case in which GPT-4.1 pointed to a non-existent bank address. After a few hours, this address... already existed - as a phishing copy of the website.
Someone had managed to record it and set up a trap. No hacking needed. Without security breaches.
Why does AI make such mistakes?
Because he doesn't know what he's talking about. But he says it confidently.
ChatGPT does not "check" information. He does not search the Internet live, does not visit websites, does not verify facts. He...generates. More specifically, it predicts which words are likely to match the question.
📚 Statistics instead of knowledge
Language models like ChatGPT work on the principle of probability sequences. He sees a question like "what is the login address for XYZ bank" and... he thinks:
"Hmm, people often write something likelogin.bankxyz.com- that's probably it."
Problem? Such a domain maynot exist. But the model doesn't know. He just "guesses" what looks convincing.
🧠 The AI doesn't lie, but...
There is no malicious intent. He doesn't "invent" links to harm you.
But his strength - his convincing style and instant response - is also a trap.
When a chatbot sounds like an expert, it's easy to forget that it's still a language-learning machine, not a specialized security system.
🗣️ Certainty = trap
Biggest risk? That AI speaks with such certainty as if it knew the absolute truth.
"The login address is login.bankxyz.com"
Sounds good. But it may disappoint you.
How to defend yourself against invalid links from AI
AI is a great helper - but you have to be your own firewall
The rule is simple:don't blindly click. Even if the link comes from ChatGPT, even if it looks reasonable, even if you're in a hurry. Phishing is based on haste and trust - both of which are your weak points.
🧷 1. Verify each link yourself
Instead of asking the AI for links to banks, logins or shopping:
-
Go to the official website via Google
-
Use a saved bookmark
-
Look at the email from the company
Never assume that a link from AI = revealed truth.
🔒 2. Always check HTTPS and domain
Going to the login page?
Check that:
-
The address starts with
https:// -
The domain name is accurate - without
bank-xyz-login.com,bankxyz1.comand other fakes
Even one letter the difference is sometimes the entire salary in the back.
🧠 3. Treat the AI like a forum friend
Gives you ideas. Sometimes very accurate.
But would you trust someone on Reddit enough to enter your bank login details without checking the link?
Exactly.
🚨 4. Suspect phishing? Don't click - report
If something looks suspicious:
-
Don't click.
-
Report the link to the security team (bank, company, etc.).
-
Mark the message as phishing in your browser or email client.
Final conclusions – AI as a helper, not an oracle
ChatGPT can be great. But he is not the guardian of your safety.
It's not about stopping using AI. On the contrary, it's a great tool. But as with any technology:you need to know where its competence ends.
AI can help with planning, writing, responding. But when security is involved - especially logins, passwords, payments - you need to take control.
📌 What is worth remembering?
-
ChatGPT doesn't check whether links are real - they just sound real.
-
Scammers can take advantage of this faster than you think.
-
Each link from AI is a suggestion - not a certificate of authenticity.
-
The principle of limited trust also applies to machines.
🧠 Have trust, but also have reflexes
AI is not the enemy. But sometimes it can go wrong at the worst moment. Therefore...
-
click wisely
-
check before providing data
-
do not treat convenience as a guarantee
Because even the most intelligent chatbot can tell you something very stupid. With full confidence.