ChatGPT Caught Recommending “Products” That Are Just Scams That Steal Your Credit Card Info
ChatGPT is recommending fraudulent storefronts that impersonate defunct retail brands, exposing a critical vulnerability in AI recommendation systems just as major tech firms race to deploy autonomous shopping agents. For institutional investors in fintech, payments infrastructure, and AI platforms, this incident signals both immediate liability exposure and the urgent need for content verification standards before agentic commerce scales.
- ChatGPT recommended cloned Russell & Bromley websites after the brand entered administration in January 2026 and was absorbed by Next.
- Fake storefronts use official-sounding URLs like “therussellbromleyofficial dot com” to harvest credit card and banking details from users.
- Amazon, Google, and OpenAI are all rolling out autonomous shopping features, creating a scaled vector for fraud if AI recommendation systems remain unvetted.
- January 2026 Date when Russell & Bromley ceased independent operations after administration.
- 3 Major tech firms, OpenAI, Amazon, Google, now offer or developing autonomous AI shopping tools.
- 1 Verified instance of scam website recommended by ChatGPT for specific product query.
Scammers are exploiting a fundamental weakness in large language models: the inability to verify whether recommended websites are legitimate. Ask Silver, a scam-checking service, identified multiple instances in which ChatGPT directed users to fraudulent storefronts impersonating real retailers.
The most documented case involved a fake Russell & Bromley site, the British footwear and handbag retailer that ceased operations in January 2026 when it entered administration and was absorbed by Next.
Because the official brand website no longer exists, prospective customers searching for “popular Russell & Bromley purses and bags” received direct links to criminal replicas designed to harvest payment credentials.
The attack works because ChatGPT’s training data likely contains references to the now-defunct official site, and scammers have populated the internet with lookalike domains that rank highly in the model’s pattern-matching systems.
Anna Jones, an analyst at Ask Silver, suggested to The Guardian that ChatGPT’s underlying large language model may have been “poisoned” by malicious content introduced during training or crawled from the web after deployment.
The fake websites are professionally constructed, featuring official-sounding domain names and visual design that mimics legitimate retailers, making them difficult for ordinary consumers to distinguish from the real thing.
Poisoned Training Data Creates Vulnerability OpenAI Has Yet to Address
The core issue is that large language models have no built-in mechanism to distinguish between legitimate and fraudulent websites. Unlike search engines, which employ ranking algorithms and manual review to flag phishing sites, ChatGPT simply patterns-matches based on training data.
If that training data includes malicious content, either injected during initial corpus collection or snuck into the model’s context window via recent web crawls, the chatbot becomes a vector for fraud.
This vulnerability extends beyond retail. Earlier this year, a BBC journalist demonstrated how easily ChatGPT could be manipulated into spreading false claims about a person by simply publishing fabricated blog posts designed to game the model’s algorithms. The journalist convinced ChatGPT that he was a renowned hot dog eating champion through content pollution alone.
That experiment proved what cybersecurity researchers have long warned: leading AI systems can be tricked into confidently spreading misinformation or directing users to harmful sites through techniques far simpler than breaking the underlying model architecture.
The Russell & Bromley case is distinct because it combines data poisoning with social engineering. Scammers exploited a real-world gap, the absence of an official website after a brand’s acquisition, and filled it with convincing fakes that ChatGPT treats as legitimate recommendations.
Users expecting the AI to pull from official sources let their guard down, increasing the likelihood they will enter payment information on a criminal replica. OpenAI has not announced specific remediation steps, though it maintains content policy teams and has previously stated it monitors for harmful outputs in real time.
Autonomous Shopping Systems Create Scaled Risk for Credential Theft
The timing of this incident is particularly concerning because major technology companies are simultaneously preparing to hand purchasing authority to AI agents. OpenAI’s ChatGPT now includes a shopping hub that allows users to buy products directly within the chatbot interface.
Amazon offers a shopping AI assistant capable of automatically purchasing items when prices drop below a user-set threshold. Google is fine-tuning a new payments protocol specifically designed to enable AI agents to execute transactions on behalf of users without additional authentication.
If autonomous shopping becomes mainstream before AI recommendation systems are hardened against fraud, the financial exposure could be enormous. Credit card companies are already working on new technical standards to prevent AI agents from draining accounts, but those standards remain in development and have not been universally adopted.
The current vulnerability, where ChatGPT recommends fraudulent sites, exists in a relatively low-friction environment where users must still manually enter payment details. Once agentic shopping scales, a compromised AI system could move funds automatically, with delays measured in seconds rather than the time it takes a human to type a credit card number.
Louise Baxter, head of the scams team at a major financial institution, noted that “consumers are increasingly turning to AI tools for advice and recommendations, but criminals are adapting just as quickly.” Scammers have already begun optimizing their fraud techniques for AI systems, understanding that each new layer of automation creates new attack surfaces.
A shopping agent that trusts its underlying recommendation model becomes a scaled theft vector if that model has been poisoned.
No Industry Standard Yet Exists for Vetting AI Recommendations Before Purchase
The absence of agreed standards for validating website legitimacy within AI systems is a critical gap. Search engines use multiple verification layers: domain ownership records, SSL certificate validation, historical Trust & Safety data, and human review.
Chatbots, by contrast, are stateless systems that treat each query as independent and operate without built-in access to real-time verification databases. OpenAI could theoretically integrate ChatGPT with verification APIs that check whether a domain is registered to a legitimate brand, whether it has valid security certificates, and whether it has been flagged by fraud-detection services.
To date, such integration is not standard practice.
Institutional investors should note that this gap creates immediate liability for technology platforms offering shopping features. A user harmed by a fraudulent transaction facilitated through ChatGPT’s recommendations may have legal recourse against OpenAI, particularly if OpenAI did not disclose the risk of recommendation-based fraud or take reasonable steps to validate links.
Payment processors and credit card networks face reputational and regulatory pressure to prevent AI-driven fraud, which could result in stricter requirements for how agentic systems are deployed. Financial regulators in the EU, UK, and US have begun examining AI systems that handle payments, and scam recommendations are likely to trigger formal inquiries.
The incident also raises questions about training data governance. If ChatGPT’s model has been “poisoned” by malicious web content, OpenAI may need to refresh and validate its training data more frequently than current practice allows. That process is computationally expensive and would slow model update cycles.
Competitors using more recent training data or more aggressive filtering may gain an advantage in user trust, particularly among institutions that cannot tolerate fraud risk.
The key question now is whether OpenAI, Amazon, and Google will pause autonomous shopping rollouts until they can verify website legitimacy in real time, or whether they will proceed with current systems while implementing backend fraud detection. Credit card networks have signaled they are developing new standards to limit AI transaction authority, but those standards have no enforced timeline. Watch for announcements from OpenAI on ChatGPT shopping security measures within the next 60 days, and track whether major payment processors issue guidance restricting agentic checkout on unverified retailers, a step that could either strengthen consumer protection or fragment the market depending on how it is implemented.
