AI Search Scams Prompt Warning for Kiwi Consumers and Businesses
New Zealand consumers and businesses are being warned about AI search scams after cybersecurity data found ChatGPT responses directing users to websites already classified as unsafe. The issue, which has also featured on RNZ, is raising concern as more people use artificial intelligence tools to decide where to shop, what software to download and which websites to trust.
ESET data found AI-generated results linking users to fake online stores, cryptocurrency scams, imitation login pages and malicious computer code capable of stealing information or compromising devices.
AI Search Scams Challenge Trust in AI Recommendations
The central risk behind AI search scams is not simply that unsafe websites exist. Cybersecurity specialists say users may place additional trust in a link because it has been surfaced by an AI assistant rather than received through an unsolicited email, text message or social media post.
Scott Leman, ESET NZ country manager, says users should not treat an AI-generated recommendation as a security check.
“What this data shows is that users cannot assume a link is safe simply because ChatGPT has provided it.”
Leman says links generated by AI should be approached with the same caution as any other online destination, particularly where a site asks for login credentials, payment information or a download.
“An AI-generated answer is not automatically a security endorsement of the website, application or download it recommends.”
The warning is particularly relevant as AI tools are increasingly used for product comparisons, software recommendations and general information searches. That shift can make AI search scams harder to recognise because the unsafe destination may appear within an otherwise useful and credible-looking response.
Phishing Risk Adds to AI Search Scams
The findings also sit within a broader phishing threat. ESET data showed 35% of cyber threats detected across its New Zealand user base in July were phishing-related. These attacks are designed to persuade users to follow a link, open a document, scan a QR code or enter sensitive information into a website that appears legitimate.
For businesses, AI search scams can create a pathway to more serious compromise if an employee enters a username and password into a fake login page. An attacker using legitimate credentials may then be able to monitor email conversations, access files, impersonate the account holder or target customers and suppliers from a genuine account.
Leman says this can create direct financial risk where criminals monitor business correspondence and intervene around payments.
“The customer has little reason to suspect anything is wrong because the message has come from the same email address and may even form part of an existing conversation. By the time either side realises what has happened, the money may already be gone.”
AI Is Shrinking the Time Available to Respond
These risks are emerging as artificial intelligence also accelerates other areas of cyber attack. Leman says AI can analyse newly released security patches, identify the weaknesses they were designed to address and help attackers develop working exploits more quickly than was historically possible.
That pressure is reflected in data from the Zero Day Clock, a project tracking vulnerabilities confirmed as exploited in real-world attacks. Its analysis shows the median period between public disclosure of a security flaw and exploitation fell from 771 days in 2018 to zero days in 2026.
“The significance for businesses is that the window they have to install a security update before attackers can act on the underlying flaw is becoming extraordinarily short.”
Why AI Search Scams Are Harder to Spot
Traditional phishing awareness has often focused on obvious warning signs such as spelling mistakes, poor grammar or awkward wording. AI is weakening the value of those signals because it can produce polished, natural-sounding messages quickly and tailor them to a particular company, employee or situation.
This means AI search scams need to be assessed through the destination and behaviour being requested rather than the quality of the wording alone. Users should remain cautious when a site asks for credentials, financial details or downloads, even if the link appeared in response to a legitimate AI query.
Leman also warns that antivirus software alone cannot address every form of modern cyber risk. If a user voluntarily enters credentials into a convincing fake login page, there may be no malicious file for traditional antivirus software to detect.
SMEs Face Growing Pressure as AI Search Scams Evolve
Smaller businesses can be particularly exposed because they may not have dedicated security teams monitoring activity continuously. As AI search scams, phishing techniques and vulnerability exploitation become faster, the ability to identify suspicious activity and respond quickly becomes increasingly important.
Leman says automated patching, continuous monitoring and rapid response are becoming more important as attackers and defenders both use AI to increase the speed of their operations.
“As attacks accelerate, the ability to detect and respond is becoming just as important as trying to prevent them in the first place.”
Technology PR and Public Education Around AI Search Scams
Cybersecurity companies increasingly need to explain complex digital risks in language consumers, business owners and decision-makers can understand. Clear media relations can help translate technical developments such as AI search scams, phishing, credential theft and vulnerability exploitation into practical information for a wider audience.
Impact PR works with technology and cybersecurity organisations on media strategy, public education and reputation-focused communications. Our technology public relations specialists help businesses turn technical issues into credible stories relevant to mainstream, business and specialist media. This can support awareness of new risks, explain why they matter commercially and help organisations communicate clearly when technology changes faster than public understanding. Strong communication is particularly important where a technical issue has direct consequences for consumers, employees or business continuity. As AI search scams continue to develop, accurate and accessible communication will remain important in helping audiences understand the changing cyber threat environment.