Post

Tech and Security – Kiwis Warned as AI Search Results Direct Users to Scam Sites – New Data

Tech and Security – Kiwis Warned as AI Search Results Direct Users to Scam Sites – New Data

Source: ESET New Zealand

14 Sept 2026

Kiwi consumers and businesses are being warned they could unwittingly hand over passwords, financial information or download malicious software after new cybersecurity data found ChatGPT search results routinely directing users to high-risk websites already classified as unsafe.

The use of AI assistants has surged in NZ, with four out of five New Zealanders now using the technology and ChatGPT becoming the country’s most downloaded free iPhone app last year.1

Local experts say the new findings from ESET, Europe’s largest cybersecurity company, have raised concerns about the growing reliance on AI tools to find products, software and information online, with users assuming links provided in an AI response have already been checked for safety.

The sites identified included fake online stores, cryptocurrency scams and imitation login pages, while researchers monitoring ChatGPT results over the past 30 days also found responses linking to malicious computer code capable of stealing information or compromising a user’s device.2

Scott Leman, ESET NZ country manager, says the findings challenge the assumption that a website or download is safe simply because it has been provided by an AI assistant.

“Kiwis are increasingly using AI to tell them where to buy something, what software to download or which website to visit.

“The risk is that we start placing blind faith in the answers these tools provide. Someone asks an AI tool for help, follows the link it provides and ends up on a fake login page, scam website or malicious download.

“Because that recommendation has come from a tool they trust, they may be less likely to question whether the destination itself is genuine or safe.

“What this data shows is that users cannot assume a link is safe simply because ChatGPT has provided it.”

Leman says the growing use of AI as a search and recommendation tool means links it generates should be treated with the same caution as those received through email, text messages or social media.

“If the destination is a fake Microsoft login page or an imitation retail site, the consequences can be very real.

“A user could enter their username and password, provide financial information or download something harmful without realising they have been directed to a fraudulent site.”

The findings come as ESET data also shows over a third (35%) of cyber threats detected across its New Zealand user base in July were phishing-related.3

Phishing attacks seek to trick people into following a link, opening a document, scanning a QR code or entering sensitive information into a fake website designed to appear legitimate.

Leman says the combination of AI-generated online risk and AI’s increasing ability to accelerate cyber attacks represents a significant change in the threat environment.

“We have reached a tipping point. AI isn’t simply making phishing emails more convincing, it is also changing the way people find and trust information online.

“An AI-generated answer is not automatically a security endorsement of the website, application or download it recommends.”

Leman says AI is also allowing newly discovered security weaknesses to be weaponised far more quickly, dramatically accelerating the process of analysing newly released security updates and identifying the flaws they are designed to fix.

“For years businesses could reasonably assume that when a new security weakness was discovered there would be some time to understand it, fix it and protect themselves.

“That breathing space is disappearing. AI can now analyse a newly released security patch, work backwards to identify the flaw it was designed to fix and help turn that information into a working attack extremely quickly.

“In one recent test involving a browser security update, an advanced AI model was able to analyse the patch and produce a working exploit in less than an hour. That is work which historically required specialist expertise and considerably more time.”

Leman says the rapidly accelerating pace is shown in analysis from the Zero Day Clock, a global project tracking software vulnerabilities confirmed as exploited in real-world attacks.

Its data shows the median period between public disclosure of a security flaw and its exploitation has fallen from 771 days in 2018 to zero days in 2026.4

A zero-day median means attackers are typically exploiting these weaknesses by the time they become publicly known, leaving organisations little or no opportunity to install a security update before attacks begin.

“The significance for businesses is that the window they have to install a security update before attackers can act on the underlying flaw is becoming extraordinarily short.”

Leman says the threat is compounded by AI also making phishing scams more convincing and increasingly difficult for users to identify.

“For years people were told to look for obvious warning signs such as spelling mistakes, poor grammar or an email which simply didn’t sound right.

“Those clues haven’t disappeared, but they are becoming much less reliable. AI can create a polished email in seconds, write it in natural language and tailor it to a particular company, employee or situation.

“That means someone can be presented with something which looks completely legitimate and still be handing an attacker the keys to their account or business.”

Leman says another misconception is that installing antivirus software alone provides protection against these attacks.

“Antivirus remains an essential first line of defence, but not every modern cyber attack involves a virus.

“If someone receives what looks like a genuine Microsoft 365 message, follows a link and enters their username and password into a convincing fake login page, the attacker may then have legitimate credentials.

“There may be no virus file for antivirus software to find because the criminal is effectively walking through the front door using the user’s own key.”

Once inside an email account, an attacker may be able to monitor conversations, access files, impersonate the account holder or use the compromised account to target others.

Leman says once an attacker gains legitimate access to an email account, a relatively simple phishing attack can quickly escalate into significant financial loss.

“An attacker could see that an invoice is about to be paid and then send another email from the genuine account saying the bank details have changed.

“The customer has little reason to suspect anything is wrong because the message has come from the same email address and may even form part of an existing conversation. By the time either side realises what has happened, the money may already be gone.”

Leman says the accelerating threat environment is particularly challenging for SMEs, which often lack dedicated security teams able to continuously monitor suspicious activity.

“AI is creating a race between attackers and defenders. Attackers are using it to move faster, identify vulnerabilities and develop convincing attacks, but defenders are also using AI to analyse activity, uncover threats and respond more quickly.

“For newly discovered vulnerabilities, automated patching is becoming increasingly important. The faster attackers can turn a vulnerability into an attack, the less time businesses have to close that gap.

“For smaller businesses, continuous monitoring and rapid response are becoming increasingly important, particularly as the window to detect and contain an attack gets shorter.

“As attacks accelerate, the ability to detect and respond is becoming just as important as trying to prevent them in the first place.”

“When attackers were moving at human speed, delays were already a problem, as AI increasingly allows attacks to operate at machine speed, businesses and consumers can no longer assume they will have time on their side.”

Notes

1. InternetNZ, Aotearoa Internet Insights 2025. (n.d.). https://internetnz.nz/new-zealands-internet-insights/new-zealands-internet-insights-2025/

2. ESET global telemetry, 30-day monitoring period. Researchers analysed URLs and other content appearing in ChatGPT outputs, categorising detections including links to potentially unwanted applications (PUA URLs), URLs already blocklisted by ESET security systems and malicious scripts either produced or referenced in responses.

3. ESET New Zealand threat telemetry, July 2026. Phishing-related threat categories accounted for 34.9% of all threats detected across ESET’s New Zealand user base during the month.

4. Zero Day Clock. (n.d.). Zero day clock. https://zerodayclock.com/

MIL OSI