AI Tool Safety
Fake AI tools, malicious extensions, and why AI-generated scams are harder to spot
Fake 'premium AI tool' phishing sites
You search for 'ChatGPT free' or 'Midjourney alternative' and land on a site that looks identical to the real product. It asks for your Google/email login to 'sign in.' That login goes directly to a scammer.
π© Red flags:
- β’URL is not the official domain (e.g. 'chatgpt-pro.net' instead of chat.openai.com)
- β’Offers a 'free premium' version of a paid tool
- β’Asks you to log in with Google/Apple without the real OAuth screen
- β’Download links for 'desktop app' from unofficial sites
β Rule: Always go directly to the official URL. For AI tools: chat.openai.com, claude.ai, midjourney.com, gemini.google.com. Bookmark these.
Malicious browser extensions posing as AI tools
Extensions labelled 'ChatGPT for Chrome,' 'AI Writer Pro,' or 'YouTube Summary with AI' often appear in search results and are even available on the Chrome Web Store. They ask for permission to 'read all site data' β then harvest your passwords, cookies, and banking sessions.
π© Red flags:
- β’Extension requests permission to 'read and change all data on all websites'
- β’Very few reviews, recent upload date
- β’Developer is a personal Gmail account, not a company
- β’Advertised as 'free premium access' to a paid AI service
β Rule: Only install AI extensions from verified developers with thousands of reviews. Most legitimate AI tools work in a browser tab β you don't need an extension. When in doubt, don't install.
AI-generated scam messages are harder to spot now
Traditional phishing emails were obvious: broken English, generic greetings, odd formatting. AI lets scammers generate fluent, personalised, grammatically perfect messages in any language. The old 'it looks weird' heuristic no longer works reliably.
π What to check instead:
- βCheck the sender's actual email domain (not just the display name)
- βHover over links before clicking β does the URL match what you'd expect?
- βVerify unexpected requests through a different channel (call the person/organisation directly)
- βTreat urgency as a red flag regardless of how professional the message looks
β Rule: Content quality is no longer a reliable signal of legitimacy. Switch to sender verification and URL checking as your primary filters.