AI Support Chatbot Scam

AI Support Chatbot Scam

A chatbot cannot unblock your account, and never needs your code.

What Is AI Support Chatbot Scam?

A support chatbot has no authority over your account. It cannot release a held payment or restore access, so it never needs your password or a one-time code to try, and anything that asks is not support. In this exercise a fast, friendly assistant reached from a sponsored search result offers to fix an urgent problem. You learn to read the address bar, notice that it never said what it was, and get help from the vendor's own site.

What You'll Learn in AI Support Chatbot Scam

AI Support Chatbot Scam — Training Steps

  1. Payroll Day

    Payroll at Harrowlen Consulting goes out on Friday and you submitted the file at half past eight, which leaves the bank a clear two days. Sixty one people, and nothing about it is usually interesting. At 09:38 a notice from Paystrel lands in your inbox.

  2. What the Notice Says

    The wording is the same every time a run bounces. It is worth looking at what a genuine notice from a payroll platform contains, because in a few minutes you are going to see something that looks very like one.

  3. Looking for Help

    Nothing in the product explains what VAL-204 means, and the validation report is sixty one rows with no flag against any of them. The bank cut-off is 15:00. You do what everybody does.

  4. The Search

    Two words, because that is what anybody types when a system has gone wrong and there is a deadline behind it.

  5. The First Result

    At the top of the page is a support assistant that answers in seconds, open twenty four hours, with the word Paystrel in its name. Underneath it, in ordinary type, is Paystrel's own help centre. You have eight minutes before the next thing on your list.

  6. Straight Through to Support

    It answers before you have finished reading the page. No queue, no ticket form, no hold music. You tell it what happened.

  7. What You Just Told It

    The three dots start straight away.

  8. It Says It Can Fix It

    Nine seconds, and it sounds like somebody who has seen this a hundred times. Your file is fine. The hold is a stale gateway session on the submitting account, and it can clear that from its end before the cut-off. It asks whether you would like it to.

  9. Read It Off Your Phone

    The box wants the six digits currently showing in your authenticator app. They are not sent to you and nothing triggered them. The app has been quietly generating a new pair every thirty seconds since the day you set it up, and the one on screen right now is the one that works.

  10. Verify and Release

    The box is already open and the cursor is already in it. Three fields: the address you sign in with, the password, and the six digits you have just read off your phone. It has been right about everything so far. It knew the submission number, it knew what VAL-204 meant, and it is the only thing this morning that has offered to actually fix it. The cut-off is at 15:00. You fill it in.

Security Framework Coverage

MITRE ATT&CK

  • T1566.002 Phishing: Spearphishing Link
  • T1598 Phishing for Information
  • T1111 Multi-Factor Authentication Interception

CIS Controls

  • CIS 14.2 Train Workforce Members to Recognize Social Engineering Attacks
  • CIS 14.3 Train Workforce Members on Authentication Best Practices

NIST CSF

  • PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind

EU AI Act

  • Art. 50 Transparency obligations for providers and deployers
  • Art. 4 AI literacy