Malicious chatbot
In plain terms
A chat window that replies like an advisor — patiently, never losing its temper — and that gets you to hand over, question by question, what you'd never have put in a form.
Definition
A malicious chatbot is an automated chat interface, presented as support or an assistant, that collects information or steers the user toward a fraudulent action over the course of the conversation.
How it works
A form announces what it wants, which leaves time to weigh the request as a whole. A conversation doesn't: it breaks the request into pieces. Each question seems harmless and justified by the last one, and the sum never appears on screen at once. The exchange also builds a relationship — patience, apologetic phrasing, apparent competence — which makes refusing socially costly, as it would with a person. These agents show up on fake support sites, in ads for an assistance service, or built into apps presenting themselves as assistants. The decisive request comes late, once the exchange has already gone on for a while: a verification code, remote access, a payment to "finalize" something.
Warning signs
- Support reached through a received link or an ad rather than the official site
- Progressive questions sliding toward authentication information
- Request for a code received by SMS, whatever the pretext
- Offer to install a remote-access tool
- Impossible to reach a human agent or an official channel
- Gentle but constant pressure to finish now
How to verify
Reach support through the service's official site, typed in yourself or opened from a bookmark: genuine support is reachable without being steered there. The decisive test doesn't depend on the tone of the exchange: no support service ever asks for a verification code, a password, or unsolicited remote access.
What to do
Treat a conversation like a form whose end you can't see: before each reply, ask whether you'd have written it in a form field. Never hand over a code or remote access, no matter how good the exchange feels.
If it already happened
Change the affected passwords from another device and revoke active sessions. If a remote-access tool was installed, disconnect the device and have it checked. Contact your bank if a payment went through, then file a police report.
Frequently asked questions
- How do you tell a genuine agent from a fraudulent one?
- Not from the conversation itself, where the two look alike. By the path taken: genuine support is reached from the official site you open yourself. An agent reached through a link or an ad has no established legitimacy, however good it sounds.
- It knew my case number — isn't that proof?
- No. That kind of information comes from an earlier data breach or a message you received. It makes the exchange credible without proving anything — that's even its main use.
Related attacks
Official sources
Also known as: fake assistant, fraudulent chatbot, fake automated customer service.
This article is part of the AI and synthetic content family. Last updated: 2026-09-03.