AI-generated scams can exploit information people share and make fraudulent messages harder to spot. In a study of 1,009 Americans, security firm Beyond Identity found that 39 percent of respondents would fall for at least one phishing scam generated with ChatGPT. The findings also point to risks involving fake ChatGPT apps and passwords built from personal details.
Familiar details can make scams convincing
The most common AI-generated scam in the study involved social media posts asking people for personal information. Twenty-one percent of respondents fell for this type of request. Such posts may seek details like birth dates or answers to password recovery questions, which can later help someone try to access an account.
The results suggest that a request for personal information can be a security risk even when it does not look like a traditional password theft attempt. Details shared in one context may be useful in another, especially when they overlap with information used to recover or guess passwords.
Fake ChatGPT apps also drew interest
Nearly half of respondents, 49 percent, said they would have downloaded a fake ChatGPT app. Apps that are not from OpenAI may connect to ChatGPT through the OpenAI API, but the study's report warns that non-OpenAI smartphone apps can pose a security risk.
Some third-party apps may offer little beyond standard chat. OpenAI provides official ChatGPT apps for iOS and Android, so users considering an app should pay attention to who publishes it and what it actually offers.
Personal information can shape password guesses
Beyond Identity tested how AI tools could use details from a fictitious profile. Researchers supplied ChatGPT with information such as a birthday, a pet's name and initials. The system generated possible passwords by combining those details.
The report says 13 percent of respondents had used AI to generate passwords. That can raise security concerns depending on the model and how its vendor uses input data for AI training. The study also found that only 25 percent said their passwords included personal information. Among those who did, common choices included a birthday, a pet's name or their own name.
These examples show why familiar personal details can be risky password ingredients. If information is available from social media or elsewhere, it may give an attacker clues for constructing likely password combinations.
Past experience was linked to scam recognition
People who had successfully avoided scams in the past were more likely to identify AI scams: 61 percent could recognize them, compared with 28 percent of people who had been scammed and said they would fall for it again. The contrast suggests that recognizing warning signs matters, while also showing that prior experience does not guarantee protection.
More than half of respondents viewed AI as a general cybersecurity threat. Beyond Identity's findings offer reasons for that concern: AI can help produce persuasive phishing messages and generate password guesses from personal details. The study does not mean every AI-assisted message or app is malicious, but it highlights how ordinary information and familiar services can be used in scams.