Chatbot Scams: Helping Customers Tell Your Real Bot From a Fake
Customers can tell your real bot from a fake once you say publicly where the official bot lives and what it will never ask for. That’s it. Chatbot scams feed on people not knowing those two facts, so a small business with a website chat can cut impersonation risk with a few plain, visible rules. No security team needed. Just clear wording, placed where visitors already look.
How Do Chatbot Scams Imitate a Company’s Support?
A fake chatbot borrows a company’s name, logo and tone, then shows up in a chat window or message the company has no control over. The usual flavours of chatbot impersonation: lookalike pages with an embedded chat, unsolicited messages posing as support, and links that quietly lead away from the real domain.
What is AI chatbot phishing after? Passwords, card details or one-time codes, collected under the pretext of “verification” or “fixing a problem”. Small firms get hit too, because customers cannot check what they were never told.
Why Safer Internet Day Is a Good Moment to Review Your Bot
It hands you a ready-made excuse to tell customers how your official chat works. Safer Internet Day falls on 10 February 2026, and according to the official Safer Internet Day page, celebrations take place every February with a global day of focus on the second Tuesday of the month. People expect online safety messages around then. So yours won’t come across as alarming.
A short notice on the site or in a newsletter does the job.
Tell Customers Where Your Official Bot Lives
Say on your site that the official bot is available only on the company’s own website. Then put that sentence where people look when they’re unsure: the contact page, the help or FAQ section, the footer, and the widget’s welcome message.
Tell customers to check the address bar and to type your domain themselves instead of following links from messages. Give the assistant one name and one look, and stick to them. Once the genuine version is familiar, a different name, colour scheme or avatar becomes an obvious warning sign.
What a Safe Chatbot for Customers Never Asks For
A genuine support bot answers questions. It never requests secrets. Say so explicitly, and spell out what falls under that promise:
- passwords or login PINs
- full card numbers, expiry dates or security codes
- one-time codes sent by text message, email or an authenticator app
- answers to security questions or scans of identity documents
Publish the list on the site and repeat it in the bot’s greeting, so it turns into the customer’s own test for how to spot a fake support bot. The rule is simple: any chat asking for these things under your company’s name is not your company.
Keep Personal and Payment Data Out of the Bot’s Sources
A bot that answers only from uploaded documents and pages cannot reveal what was never uploaded. So feed it public-grade content only: your offer, opening hours, policies and guides. Customer lists, invoices, order exports and internal credentials stay out.
Review each file before upload, and do it again whenever content changes. I’d recommend a written rule on what never belongs in sources - it makes that review quicker for whoever maintains the knowledge base.
Give the Bot a Clear Answer About How You Contact Customers
Add a page or document to the sources that says exactly how the company reaches customers, so the bot can repeat it on request. What goes in? The official email domain, the official website address, what you never send or request, and where to report a suspicious message. With that in place, the assistant can answer “Is this message really from you?” in your own words.
This goes for every type of organisation, including charities whose chat handles donor and volunteer questions. Keep the wording short. The same text then works for visitors who prefer speaking to typing, because it sounds natural when read aloud.
Teach Staff What to Say When Someone Reports a Suspicious Chat
When a customer reports a fake chatbot, every employee should give the same short, calm reply from a ready script:
- Thank the customer and confirm that the official bot exists only on the company website.
- Ask for a screenshot and the address of the suspicious chat, without requesting any secrets.
- If data was shared, advise changing the password and contacting the bank.
- Pass the report to the person responsible for the site.
- Update the public notice if the pattern repeats.
Put together, these habits make a fixed set of rules: one official location, a public never-ask list, clean sources, a clear contact answer and briefed staff. Will they remove fraudsters from the internet? No. But they make chatbot scams far easier for your customers to recognise and for your team to handle.
FAQ
How can customers spot a fake support bot?
Website address first: does it match the company’s real domain? A chat that arrives through an unsolicited link deserves suspicion. And any request for passwords, card numbers or codes is a warning sign.
What should a customer do after sharing data with a fake chatbot?
Change the affected password immediately, along with any other account that uses the same one. If payment details were given, contact the bank or card issuer without delay. Then report the incident to the company through its official website.
Can a small business stop chatbot impersonation completely?
No, because anyone can copy a logo and a name. Clear public rules about the official bot and what it never asks for make fakes easier to recognise, though.
Related posts
What a Chatbot Privacy Notice Should Tell Your Customers
A chatbot privacy notice tells visitors who runs the chat, what they may type into it, why those messages get processed, who…
AI Act Chatbot Disclosure: Telling Customers They Talk to a Bot
The AI Act chatbot disclosure rule is pretty simple. When people talk to a chatbot, they have to be told there’s a…
What Is a RAG Chatbot and How It Answers From Your Documents
A RAG chatbot is a bot that first searches your own documents for the passages that fit a question, and only then…