Staying Safe from Chatbot Scams: Your Ultimate Guide – Security.org

Welcome to the forefront of conversational AI as we explore the fascinating world of AI chatbots in our dedicated blog series. Discover the latest advancements, applications, and strategies that propel the evolution of chatbot technology. From enhancing customer interactions to streamlining business processes, these articles delve into the innovative ways artificial intelligence is shaping the landscape of automated conversational agents. Whether you’re a business owner, developer, or simply intrigued by the future of interactive technology, join us on this journey to unravel the transformative power and endless possibilities of AI chatbots.
The realistic nature of automated chat features and devices may make people comfortable sharing their personal information. However, criminals often use these popular technologies in phishing schemes.
Automated chatbots have various uses today: ordering pizza, checking bank account balances, or mental health therapy. One in three U.S. men even use ChatGPT for relationship advice.1
The uses for chatbots are nearly endless. But, businesses primarily use them to engage their website visitors and increase their online purchases. That’s one of the driving factors for the chatbot industry’s expected 26.4 percent annual growth rate.2
As businesses find more applications for chatbots, bad actors are also finding new ways to exploit chatbot users and steal their personal information. And unfortunately, most people are not aware of this threat. According to our recent study, 58 percent of adults said they didn’t know chatbots could be manipulated to gain access to personal information.
This guide will help you use chatbots safely and securely and show you how to spot a scammy chat before you share sensitive information.
Although they benefit businesses and customers, there are certain risks and vulnerabilities to be aware of when using chat features on websites. Most people are not confident that these online chats are completely secure. In fact, only 11 percent were very or extremely confident that companies had sufficiently secured these chat features.
How confident are you that companies have taken sufficient action to ensure that their retail or banking chatbots are secure
If customers would not feel safe placing an order with their credit card number over public WiFi networks, they should not when ordering through a chatbot, either. According to our research, people seemed to be more concerned about their information security in online banking chats than in online retailers’ chats. This makes sense, given the sensitive information associated with bank accounts that could be damaging if placed in the wrong hands.
User level of concerns for online privacy while using chatbots for banking and shopping online
However, even in retail shopping chats, criminals could access victims’ credit card information if a company has a data breach. In 2024 alone, the personal data of about 1.7 billion people was exposed in data breaches. If credit card or other personal data was shared and stored in automated chats, hackers could steal and manipulate it. No matter what chatbot you use, it’s essential to be vigilant and protective of your personal information.
Info Box What is Fishing
Chatbot scammers often impersonate trustworthy brands when planning their schemes. According to Kaspersky Labs research, major brands like Apple, Amazon, and eBay are the ones that phishers impersonate most often. Let’s cover some real examples of how these chatbot scams work in practice.
Delivery service scams continue to evolve, with criminals exploiting the surge in online shopping. DHL is a courier, package delivery, and express mail service company. In May 2022, a chatbot phishing scam spread – but it did not start in chatbot form. Essentially, the scammers asked unsuspecting people to pay additional shipping costs to receive packages. Victims had to share their credit card information to pay the shipping charge.
DHL Chatbot Scam shipping update email
First, the victims received an email about package delivery issues. If they clicked on the email link, they were eventually directed to a chatbot. The chatbot conversation may have seemed trustworthy to some users since it included a captcha form, email and password prompts, and even a photo of a damaged package. However, there were a few tell-tale signs that this was a scam:
DHL chatbot scam email with blank from field

Did You Know: Phishing scams don’t just end in your inbox. Cybercriminals have evolved their phishing scams to include text messages. Read our guide to phishing text messages called “smishing” to learn more. We’ve also created a guide on how to stop spam texts.
$1.9 billion of fraud losses stem from scams initiated on social media platforms.5 One of these scams is a chatbot scam on Meta’s Messenger and Facebook. Some Facebook users received a fraudulent email explaining that their page violated community standards. Their Facebook account would be automatically deleted if they didn’t appeal the decision within 48 hours.
Facebook Messenger chat scam email
A link took unsuspecting readers to an automated support chat within Facebook Messenger. The chatbot directed them to share their Facebook username and password with the scammers, which was the scheme’s goal.
There were a few clear signs that this was a scam:
Chatbots can be hugely valuable and are typically very safe, whether you’re using them online or in your home via a device such as the Alexa Echo Dot. Knowing what to look for can help you avoid becoming one of the millions who lose money to online scams each year.
If you receive frequent texts from unknown numbers that contain suspicious links,  you can adjust your carrier settings to filter out spam calls and texts. You can also use built-in features on iPhones and Android devices to automatically filter unknown senders. Forward any scam text messages you receive to the Federal Trade Commission (FTC) at 7726, so they can track and investigate the fraud
Chatbot threats aren’t only online – most Americans have already opened their homes to very similar interfaces. The same conversational AI powering internet chatbots is coded into virtual personal assistants (VPA) like Amazon’s Alexa, Google’s Home, and Apple’s Siri.
More than half of respondents in a survey we conducted own an AI assistant, meaning that 120 million Americans share personal information with such devices regularly. Amazon’s Alexa is the most popular model today.
Home assistants offer convenience by handling household operations with an understanding of our personal needs and preferences. That functionality also makes the interfaces a risk to privacy and security. Appropriately, not everyone trusts them.
More than 90 percent of users have doubts about home assistant security, and less than half have any level of confidence in them.
How confident are you that companies have taken sufficient action to ensure that their AI voice-activated home assistants are secure
This skepticism is justified. Voice-activated assistants lack many protocols that can foil a browser-linked scambot. Rather than requesting password logins through verifiable web pages, assistants can accept commands from anyone without visual confirmation of their remote connections. This process allows for fraud on either end of the equation. Including always-on microphones completes a recipe for potential disaster.
Some VPA security lapses are borderline comical, like when children commandeer them to buy toys with parental credit cards. Other stories feel far more nefarious. In 2023, Amazon agreed to pay $25 million in FTC settlements over Alexa privacy violations that included them keeping children’s voice recordings.6
Third-party hacks are particularly frightening since virtual assistants often have access to personal accounts and may be connected to household controls (lighting, heating, locks, and more).
>> Dive in: What Is a Scam?
Outside breaches of AI assistants usually fall into one of the following categories:
While manufacturers regularly patch security vulnerabilities, smart home users should take proactive steps to protect their privacy. Luckily, there are simple steps that consumers can take to help secure their devices.
Additionally, one must remember to follow the baseline safety protocols inherent in any online device. Some consider VAs family members rather than gadgets, yet it’s still critical to keep firmware updated, use strong passwords, and connect them only to secured personal routers.
Beware of romance scams if you’re looking for love on dating apps. According to the FTC, romance scams reached $1.14 billion in reported losses in 2023, with the median individual loss at $2,000.8
Scammers use bots to sign up for new accounts and create fake dating profiles. This happens on a massive scale across all major dating platforms.
AI technology such as ChatGPT is allowing scammers to be more successful at making conversation with potential victims. Still, there are signs that you may be talking to a bot or a scammer relying on AI to make conversation:
With advanced AI tools, a single scammer can now manage hundreds of fake profiles simultaneously, making these schemes more prevalent than ever.
>> Related: Is ChatGPT Safe?
Most of the time, chatbots are legitimate and as safe as any other apps or websites. Security measures like encryption, data redaction, multi-factor authentication, and cookies keep information secure on chatbots. If you accidentally give a legitimate chatbot your Social Security number or date of birth, redaction features can automatically erase the data from the transcript.
That said, you should tread carefully when sending personally identifiable information and other types of sensitive data. Sometimes, sending PII is unavoidable since interacting with a chatbot is similar to logging into an account and submitting PII yourself. Here are some personal data points you should not send via chatbot:
At a minimum, practice data minimization – only share what’s absolutely necessary. Refrain from sending or volunteering extra information beyond what is required. For instance, don’t give your complete address if the chatbot asks only for your ZIP code. Never share information you would ordinarily not need to, and think carefully before sending any personal information online. For example, you would never have to share your Social Security number to check on a package delivery or get your bank balance.

source

Scroll to Top