Fraudsters Exploit AI Shopping Assistants to Promote Fake Online Stores
A new and concerning fraud pattern has emerged in the United Kingdom that has direct implications for the future of e-commerce globally. Consumer protection advocates are warning that criminals are actively exploiting AI-powered search and recommendation systems — most notably ChatGPT — to direct unsuspecting shoppers toward counterfeit online stores. The case, reported by British newspaper The Guardian and flagged by UK fraud detection service Ask Silver, represents what may be one of the first documented instances of AI shopping fraud at scale.
The targeted fake shops closely imitate well-known British retailers. According to Ask Silver, consumers are being directed to fraudulent websites mimicking British shoe and bag brand Russell & Bromley, as well as home furnishings retailer Dunelm. Shoppers who place orders and pay in advance do not receive the goods they purchased. In addition to financial losses, their payment data may be harvested and either sold or misused for further fraud.
The Details: How the Attack Works
The mechanism behind this emerging threat is being described as AI Poisoning. In this context, criminals attempt to manipulate the data foundation of large language models (LLMs) by injecting manipulated or fraudulent content into sources these models draw upon when generating answers and recommendations. As AI assistants like ChatGPT increasingly become starting points for product discovery and purchase decisions — a trend often described as Agentic Commerce — the attack surface for this type of manipulation grows accordingly.
The fake shops involved in the reported cases share characteristics that security experts have long associated with traditional e-commerce fraud:
- They appear credible and professional at first glance
- They offer products at suspiciously high discounts
- They convincingly replicate the visual identity of legitimate retailers — a task made significantly easier with the help of modern AI tools
- They require upfront payment, after which no goods are delivered
What makes this iteration particularly dangerous is the trusted context in which these links appear. When a consumer asks an AI assistant for product recommendations and receives a seemingly authoritative response with source links, the psychological barrier to clicking and purchasing is considerably lower than when encountering an unfamiliar result in a traditional search engine.
Why This Matters for E-Commerce Operators
While the documented cases come from the UK, the authors of the original report are explicit: it is only a matter of time before similar fraudulent recommendations surface in other markets, including Germany and the rest of Europe. Any region where AI shopping assistants are gaining adoption is a potential target.
For shop operators and e-commerce managers, this development signals a meaningful shift in the threat landscape. Brand protection is no longer limited to monitoring search engine rankings or policing marketplaces. As AI-driven discovery becomes a mainstream part of the customer journey, the integrity of the information these systems surface becomes a business-critical concern.
Established brands face a specific risk: their reputation and recognizable visual identity become assets that fraudsters can exploit to create convincing imitations. Smaller or niche retailers are not immune either — any brand with enough online visibility to appear in AI-generated recommendations can potentially be spoofed.
Practical Guidance for Online Retailers
While no definitive technical countermeasure against AI Poisoning has been established at this stage, e-commerce operators can take several proactive steps to reduce exposure and protect their customers:
- Monitor your brand in AI outputs: Regularly query AI assistants using your brand name and product categories to identify whether fraudulent domains are being referenced alongside or instead of your official store.
- Strengthen brand signals: Ensure your official website has strong, consistent, and well-structured content that AI systems can clearly identify as the authoritative source. Structured data markup, verified business profiles, and canonical signals all contribute to this.
- Communicate directly with customers: Proactively inform your customer base — via newsletters, social media, and on-site messaging — about your official domain and the risks of imitation sites. Make it easy for customers to verify authenticity.
- Work with fraud detection services: Engage with brand protection and fraud monitoring services that are beginning to track AI-surfaced content alongside traditional search and marketplace channels.
- Report fraudulent domains: If you discover fake shops impersonating your brand, report them to domain registrars, relevant consumer protection agencies, and directly to the AI platforms involved where reporting mechanisms exist.
Outlook: A Growing Challenge for the Industry
The rise of Agentic Commerce — where AI systems not only recommend but increasingly initiate and complete purchases on behalf of users — makes the stakes of AI Poisoning even higher. If a fraudulent shop can be surfaced in a conversational AI response today, tomorrow it could appear in the output of an autonomous shopping agent executing a transaction without a human review step in the loop.
This case underlines a broader truth for the e-commerce sector: the shift toward AI-mediated discovery requires a corresponding evolution in trust infrastructure, brand monitoring, and consumer education. Regulators, platform providers, and retailers will need to collaborate to establish standards for source verification and accountability in AI-generated commerce recommendations.
For now, the most important action for any online retailer is awareness. Understanding that AI shopping assistants are becoming a new vector for fraud — and beginning to monitor and respond accordingly — is the first step toward protecting both brand integrity and customer trust.