The podcast episode discusses a data breach affecting chat GBT users' personal data, the emergence of Kauai GPT as a free AI tool bypassing safety controls, and the potential replacement of humans by AI in Southeast Asia's scam centers. Scammers are utilizing AI for various fraudulent activities, such as impersonating lawyers and weaponizing Black Friday shopping. Social media giants are now liable for financial scams under new EU laws. The episode also touches on the challenges posed by AI in combating human trafficking and the exploitation of legitimate technology, such as Starlink devices, by scam centers. Concerns are raised about the ethical use of AI and the responsibility of users in ensuring its proper utilization.
Transcription
7562 Words, 44966 Characters
(upbeat music) Welcome to Fraudology Podcast, where we dive into the science and study of online fraud from the perspective of an e-commerce fraud fighter. I'm Karees Hendrick. Welcome back to the Fraudology Podcast. I have a handful or more of news articles to share with you today. I just knew things happening in the world of fraud that I think everyone would be interested in learning. I certainly found them interesting. But first, I just wanted to say thank you. Thank you for listening to the podcast. Thank you for sending me screenshots of your Spotify wrapped when I'm in the top three that means the world to me. And thank you for reaching out every once in a while and just telling me that you appreciate the podcast. I had two people today reach out. It's like they knew I needed to hit. There's just been a lot going on in my life the last month or so. And lots of stress and drama and all the things that I think we all deal with from time to time. And it was really nice to get two messages today. One from a new listener and one from a long time listener. I'm not going to call her old. But a long time listener sharing her wrapped screenshot with me from Spotify and saying that the podcast actually changed her life, which was really cool. And I don't know if it was hyperbolic or not, but it has really-- I appreciate it. So thank you, that's how I'm starting this out. I guess we did celebrate the Thanksgiving holiday in the US last week or a week and a half ago, two weeks ago now. And so maybe I'm still on a gratitude high, but I just wanted to start out by saying, thank you. I really-- I mean, I just sometimes feel like a girl that talks to herself and do a microphone in her home office and don't know if anyone listens or cares or finds it interesting. So it's really humbling when I hear from you and that it is interesting and hits home and all the things. So again, thank you. So I'm going to go through a little bit of the topics of the news articles I'm going to share today. Just in case you want to skip through or anything else. But one is the chat GBT had a data breach. And so users' personal details had been exposed. I found that very important. As well as in the realm of AI, especially after the conversations I had with Matt and Frank last week, which if you didn't listen to that episode, you have my permission to stop this one and go back and listen to that one. It was really good. It's just three fraud geeks geeking out about fraud in AI. And I really enjoyed it. I love talking to Frank and Matt individually, so getting to talk to them at the same time was really fun. I learned a lot. I've already heard from a few of you that have listened to the podcast already that have learned a lot as well. So yeah, definitely listen to that. I think it's actually these articles about AI, as well as the conversation I had with Matt and Frank, actually spurred me to or inspired me to decide that January is going to be the month of AI for fraudology, where I'm going to have guests talking about AI. We're just going to deep dive into it. AI liability, agentic AI liability. We'll talk about crypto and also some of these AI servers and what they're doing or what they can allow. How fraudsters are using AI to learn all the parameters of what we're doing. Matt talked about that last week, but I had another conversation with a friend of mine yesterday about that very topic. And I am going to have him on the podcast. So lots of things to talk about and to look forward to in January. This next article is called Kauai GPT. It's a free worm GPT clone using deep seek, Gemini, and Kimmy K2 models. So I'll go into this more, but it's an open source tool that allows fraudsters to get around some of the-- it's a jailbreak version of deep seek, Gemini, and Kimmy K2-- that allows fraudsters to bypass some of the safety features that those models have to try to not allow fraudsters to use open source AI tools for bad. So we'll dive into that in a minute. Then I've had another AI article where it says AI may replace people in Southeast Asia's Schium complexes, and that could undercut the drive to stop them. If there's no human trafficking aspect, will we still want to stop them as much? That's kind of what that article asks. This one is about AI bots weaponizing Black Friday shopping. Now there's a new one to watch. So we'll talk about that. So lots of AI. I also found this interesting. Scammers are using AI to impersonate real lawyers. This Bureau of Investigative Journalism finds dozens of Fiverr profiles advertising cheap legal advice with stolen credentials. And then I have another story of how fraudsters have been using-- I don't know if we even call them fraudsters, but people have been using tools like Fiverr and AI tools to take on multiple jobs. And there was a story I learned recently from another fraud fighter that happened in a company recently that I think you will find interesting. Another article, this is really-- it goes to something that Frank McKenna said years ago to me, where he said we were going to start to have instead of narco states, we would start to have fraud states, state countries that are sponsored by cyber criminals to look the other way, and paying off their politicians and other things, kind of like narco states in South America. But this article is titled-- it's in the Guardian, and it's titled "Age of the Scam State." How an illicit multi-billion dollar industry has taken a route in Southeast Asia. So we'll talk about that a little bit. There's several stories, sorry guys, but another story-- but I think they're all really important and fascinating. This next one is social media giants are liable for financial scams under the new EU law. Let's talk about that some more and how that's going to work out. You can guess what all of the social media companies are saying about that. But I think that's a great idea. The $300 backdoor, how compromise T-Mobile and Verizon staff are fueling a black market for digital identity theft. And then I'm going to stop there. If we have time, we'll go into some more sophisticated refund fraud, and a fraud news story that I think is-- just not news story, but just a fraud story of a fraud scheme. They think it's good, but we'll see how we're doing on time. And if we have time, we'll go on those. If not, we'll talk about those next-- in the next week's episode. OK, so starting with the very first article I mentioned, GBT users, personal details are exposed in data breach, open AI reveals. Stolen data includes user names, email addresses, and location data. Open AI has confirmed that a security breach has compromised chat GBT users' personal data. The incident occurred on the 9th of November when attackers gained unauthorized access to third-party data analytics provider, mixed panel. Details stolen include user names, email addresses, location data, operating system, and the browser they use. Open AI said that only the users with accounts to access the company's API interfaces are impacted by this cyber attack. So only the companies that are paying for it, I guess. No chat API requests API usage data, passwords, credentials, API keys, payment details, or government IDs were compromised or exposed, they said. The company said that it is conducting a security investigation and has removed mixed panel from its production services. No evidence has been found of the stolen data being misused. Though open AI warned that hackers could use it as part of a phishing or social engineering attacks, we encourage you to remain vigilant for credible looking phishing attempts or spam. The firm said the security and privacy of our products repair amount and we may remain resolute in protecting your information and communicating transparently when issues arise. So I agree with them that this data that has been exposed, which includes usernames, email addresses, location data, operating system, and the browser that they use could be used for sophisticated social engineering or phishing attacks. So something to be aware of. And also, it's a good reminder that the data we share with chat GPT or other generative AI tools, they see that as their data as soon as you share it. I mean, my podcast editors use chat GPT to create the show notes for the episodes. So if you look at the notes in Spotify or Apple to find out what the podcast episode is about for the last year or so, those have been written by chat GPT. And also the episode titles usually come from chat GPT. They feed the transcript of the episode into chat GPT. And then they ask it for a two-paragraph summary and three title options. And then I pick from there. Why am I telling you this? Because I was really nervous. Recently, I had reason to be nervous. And I guess I kind of shared it a little bit on the end of my episode with Frank and Matt. But a reason to be nervous about the things I talk about on this podcast, going public, and being used in chat GPT as answers without sourcing me, without saying that it came from fraudology podcast or even worse. Because it's already happened. Someone taking information that I provide in the podcast and using it to fuel a persona that they then monetize on quite heavily to help companies solve problems. That really happened. So I was nervous about that and asked my editors if they're using the paid version or not. And they said they are. And then I asked, are you feeding the models with this data? Have you unchecked that box? And they had. But I was nervous about it because all that information that goes into chat GPT or any of these other tools can be used as open source information for anyone. And while I'm not under the illusion that this isn't a public platform, I know it is. But I don't want it to be used to make something else smart or another company a lot of money. Now, if they source it and say this came from the fraudology podcast, that's different. But if they're using it as just facts and data that's feeding the data model, then I don't think that that's as fair. This next article is about Kauai GPT. And it's a free worm GPT clone using deep seek Gemini and Kimmy K2 models. So those are generative AI models. This I thought was interesting because they found a way to get around some of the safety controls. It says a new open source tool called Kauai GPT has surfaced on GitHub, which is free open source code that you can get and download and use. Positioning itself as a cute but unrestrictive version of artificial intelligence. It describes itself as a worm GPT Kauai version referencing the infamous malware oriented AI, though the developers insist their project is intended for fun and educational purposes, of course. That's how they get around things. How it works, unlike standard chat bots that require paid subscriptions or API keys, Kauai GPT is completely free to use. It does not rely on its own massive supercomputer to think, instead it acts as a clever wrapper or middle man. And that's wrapper spelled with a W. The software connects to powerful existing AI models specifically deep seek Gemini and Kimmy K2 and delivers their answers to the user. The tool uses a technique called reverse engineering on API wrappers to access these models without needing official credentials. This allows users to run the program easily on Linux systems or mobile devices using TermX without registering for an account or paying fees. The most controversial aspect of Kauai GPT is its claim to be a worm GPT clone. The original worm GPT was a tool designed specifically for cyber criminals to write malware and phishing emails without safety filters. Kauai GPT achieves similar unrestricted results by using prompt injection. Standard AI models like Gemini have safety guard royals to prevent them from generating harmful content, but Kauai GPT bypasses these rules by feeding the models a special jail break script hidden in the background. This tricks the AI into ignoring its safety guidelines, allowing it to answer questions it would normally refuse. The developer notes that the worm GPT tag is used primarily to describe this jail broken behavior rather than implying the tool is malicious software itself. The code for Kauai GPT is obviscated, meaning it is scrambled and unreadable to humans. In the cyber security world, this often raises red flags because it can hide viruses or spyware. Addressing these fears directly in the projects, read me the developer, Mr. Sands, Defense of Decision. They state, I want to avoid recoding and renaming which ends up selling Kauai GPT tools under my name. The creator emphatically denies that the tools contain any remote access Trojans, rats, spyware or malware, arguing that the obfuscation is strictly to protect their intellectual property from copycats who might try to sell the product the free tool for profit. Tools currently hosted on GitHub and has generated over 200 stars indicating a growing interest from the community. It requires a simple installation process involving Python and Git. However, the creators include a strong disclaimer. All risks or consequences that you have done are your own responsibility. While they pitch Kauai GPT as a project made for fun, the ability to bypass AI safety filters places the responsibility of ethical use entirely on the user. So that's scary and that it's out there. I think it's just important for us to know that even if some of these models and tools have safety filters that there are ways to jailbreak them and get around them and use their, have their models answer questions or provide responses to prompts that generally wouldn't usually be provided. Still talking about AI. AI may replace people in Southeast Asia's scam complexes and that could undercut the drive to stop them. AI-driven automation of labor isn't just coming for legitimate businesses. Hundreds of thousands of workers hailing from over 50 countries are currently trapped within Southeast Asia's sprawling scam centers according to estimates by the United Nations. We've talked about this at length with human trafficking going on with pig butchering scams in Southeast Asia. But humanitarian experts think these workers may soon be replaced by artificial intelligence. In some scam centers, messages initiating contact between scammers and potential victims are already being crafted and sent by AI. Says Lingley, a researcher and co-author of scam inside Southeast Asia's cybercrime compounds. Time is ticking because large language models may eventually replace even the subsequent steps of pig butchering scams, she says. Pig butchering refers to a common scam variant where criminals build up relationships with their victims before defrauding them. Like how a farmer might fadden up a pig before slaughtering it. That is what the fraudsters call their own crime is pig butchering. Yet experts fear that automation might make it more difficult to bust crime syndicates as foreign governments lose interest in fighting the problem when their citizens are less at risk from human trafficking. Governments throughout Asia and beyond have pressured Southeast Asian countries like Thailand, Cambodia, and Myanmar to crack down on job scams, human trafficking and scam centers. This pressure often comes after a high profile incident such as when Chinese actor Wang Jing was kidnapped in Thailand in January or when a Korean tourist was found murdered near a Cambodian scam compound. This outrage over the scam industry has pushed countries like the US, UK, and South Korea to call action to take down to criminal syndicates. Mounting international pressures have pushed Cambodia and Myanmar to crack down on these criminal gangs leading to the arrest of thousands. Governments and other NGOs may withdraw from the fight against scam centers if their citizens are less at risk from human trafficking. Lee says this change will also make it more difficult for law enforcement agencies to identify informants who can divulge inside information. Yet Stephanie Barud, a criminal intelligence analyst from Interpol isn't so sure that AI will lead to a drop in human trafficking. Instead, criminal networks will use their well-established trafficking networks for other purposes. We cannot really say that AI will end trafficking. It will simply reshape what we are seeing, Barud says. Scams syndicates are turning to other private sector products like stablecoins and fintech apps to facilitate crimes as Jacob Sins, an expert on transnational crime and human rights in Southeast Asia. Traditional financial institutions like banks have a clear interest in eradicating scam activity from their platforms. Every time someone gets scams, that's money leaving their platform and customers lose trust in them. So it's a lose-lose for banks. Cryptocurrency exchanges now trying to clean their reputations and legitimize themselves as a responsible financial actors also don't want anything to do with scammers he adds. Social media messaging apps, however, are a different story. Criminal activity drives an enormous amount of traffic on these platforms. Sim says adding that a large number of both trafficking and scam victims have been recruited on Facebook. Not anything we didn't already know, right? When it comes to fact-checking or content moderation, we're seeing a big rollback in terms of the strictness of platform or policies and guidelines. It says, "Homeral Suria," I probably said that wrong. "A visiting fellow at the ISEAS Yusof Eshak Institute in Singapore." She cites the WhatsApp, which relies on users to report false information or content that is against community guidelines. They don't do their own sampling or vetting, but are shifting to their responsibility to users. We aggressively fight fraud and scammers because people are platforms don't want this content and we don't want to either set a meta-spokesman to respond to or request for or for comment. A scam activity becomes our persistence and sophisticated so-to-our efforts. The spokesperson added that since the start of 2025, meta has detected and disrupted close to eight million accounts on Facebook and Instagram, associated with criminal scam centers. From January to June, the company banned over 6.8 million WhatsApp accounts linked to scam centers. If social media platforms want to effectively tackle fraud, they need to use tactics that generate false positives which they don't want to happen. Tech firms don't want to be more aggressive than they need to be with regards to cracking down. As this may prevent some users from accessing the platform, this reminds me of an article I read a couple weeks ago on the podcast just about how there was a whistleblower from meta that came out saying that meta was not doing enough, not even close to what they could or should be doing to keep scams off of their social media platforms. Scams centers are also weaponizing internet service providers and October investigation by AFP uncovered that over 2000 Starlink devices satellite internet service provided by Elon Musk's SpaceX were being used by scam centers in Myanmar. This highlights how easily legitimate technology can be exploited by scam operations, underscoring the need for clearer licensing, proper user verification, and cooperation with regulators. Says Joanne Lann, a coordinator from the IAS EAS Yusuf Eshak Institute. Whoo, don't say that fast 10 times. SpaceX swiftly disabled the devices when evidence of Starlink receivers in scam centers was uncovered. So really notes it may be difficult to stop tech from being co-opted by criminals. Many commercial businesses don't know that their products are being used by scam operations, but their response is what matters. In other words, how would this business deal with their bag clients? I think it's more important. So I think that's an interesting thing that they pose that if as more scam centers go towards AI, which we know they're using for deep fakes already and other things, but as they're using large language models to communicate with victims, is there going to be as much human trafficking? And if there's less human trafficking, will governments care as much about reducing the scam centers? I thought it was an interesting question to pose and just to think about. Now let's talk about AI bots weaponizing Black Friday shopping. And now there's a new one to watch is what cybernews.com says. AI and is enabling bad bots to multitask and multiply while tech savvy shoppers trying to snag deals via agentic browsers are opening themselves to new threats, experts have warmed. So here are the key takeaways from this article. AI bots dominate Black Friday shopping, hoarding limited stock deals before human shoppers can purchase. Advanced bots now blend inventory hoarding with account takeover tactics using compromised credentials. New AI shopping assistance expose users to embedded malicious instructions and fraud risks. And you should protect accounts with unique passwords to factor authentication and automated breach monitoring tools. So reading this article, they talked about the term Black Friday and how it was first coined by US cops back in 1960 or around the 1960s to describe the chaotic traffic and crowds in shopping precincts generated on the day after Thanksgiving. Today could equally be used to describe the criminal activity that mirrors the retail frenzy during events such as Amazon Prime Day, Cyber Monday, and Black Friday. And while the annual round of suspicious fishing emails and fake SMS texts for personal deliveries hasn't gone away, the most concerning threat this year are automated, scalable, remarkably good at mimicking human behavior and are largely being driven by AI. Why bad bots are everywhere? Bad bots are automated software tools that mimic human shoppers to exploit online stores. Instead of browsing or buying legitimately, they engage in high-speed high-value actions that give criminals an unfair advantage and cause real harm to both retailers and consumers. Just a couple of years ago, attackers would have needed specialized scripts or custom bot frameworks to carry out these types of attacks. However, researchers are now warning of AI enhanced tools that can mimic human behavior with precision. According to impervas 2025 bad bot report, retailers are being overwhelmed by these automated systems with a third of all retail traffic, now coming from bad bots. Advanced AI-driven bots account for nearly 60% of this traffic. And overall, bots now make up more than half of all internet activity overtaking humans for the first time. For retailers, defending against bots is no longer an edge-case problem, but a default position. Imperva research found that retail sites collectively experienced over half a million AI-driven attacks each day between April and September of 2024. For shoppers, they're growing numbers translate into two major consequences. One, an inflated scarcity of desirable products as bots hoard inventory and heightened exposure to account compromise. They're calling this the GrinchBot 2.0. The most visible impact comes from so-called GrinchBots, automated systems that buy up limited stock items, such as consoles, toys, and electronics, the instant they appear online. And oftentimes if they're on sale, that makes them even more desirable, because it's the only time a year those will go on sale. By the time a human shopper reaches the page, the inventory has already been hoarded by automated buyers who then resell it at inflated prices. Shaila Rana, professor of cybersecurity at Purdue Global, describes how highly evolved these bots have become. She notes that they are no longer just targeting concert tickets or sneaker drops, but increasingly use residential IP addresses to appear authentic and even solve capsa using AI. The bots use residential IP addresses looking to look like real shoppers. They solve capsa with AI. We've even seen chat GPT getting better at solving these. And the result here is that people can't buy what they need and resellers mark up prices more and more and more. Tim Burke, founder and CEO of Quest Technology Management, has observed entire checkout flows being completed in milliseconds. He explains that bots are now attacking APIs directly and imitating legitimate traffic so closely that retailers often fail to detect what's happening until the stock is already gone. By the time a retailer becomes aware, what's happening the products are already sold through resell terminals, he says. And then there's the issue of credential stuffing. A second major bot related threat is credential stuffing, a process in which attackers use stolen user names and passwords from various breaches to test them across hundreds of retail sites. Many consumers reuse passwords, especially during the Black Friday period when they sign up for multiple accounts and bots know this, exploiting it relentlessly. One's inside an account criminals can make unauthorized purchases using stored credit cards, drain loyalty points, redirect shipments to different addresses, or lock the legitimate owner out completely. Clayton Leab Broughton, a senior industry expert at TrueColor, emphasizes how damaging this can be. Scammers deploy these automated tools to test thousands of stolen user names and passwords, combinations across retailer sites. While deals scraping hurts your wallet, info harvesting hurts your identity. Former FBI cyber agents Andre McGregor and Jason Troopy, now co-founders of public safety resource four semestrics, warn the criminals are blending physical and cybercrime more than ever. According to their data, organized retail crime incidents rose by 57% between 2022 and 2023. And their experience credential attacks are now the most common method targeting retailers, making up more than 30% of all attacks. During busy shopping season, these activities blend seamlessly into normal user behavior, allowing criminals to exploit the seasonal chaos with ease. According to Quest Burke, bots this year are becoming more sophisticated, blending automation and account takeover tactics. Attackers no longer rely solely on stolen credit cards. They are also using compromised customer accounts to make orders that appear legitimate, then laundering the goods through gray market resale or return fraud schemes, Burke's, and explained. We're also noticing seasonal abuse of affiliate and vendor portals. Attackers compromise the small partners credentials using targeted access to impersonate legitimate business traffic and then move deeper into the retail ecosystem. And then there's the new kid on the block that we're going to be talking a lot about in January. And that is agentic shopping assistance. Perhaps keen to land the best deals and outmaneuver bots, tech savvy shoppers are starting to use AI agents to browse compare and buy products. However, these agent-based AI systems should be treated with cautions, threat, researchers warn. While some retailers are already offering agentic shopping assistance to customers, this has left them facing a new security quandary as they can no longer distinguish between legitimate agent-driven interactions and the malicious automation design to mimic them. It's actually not true that they can't find them. There are fraud providers that can identify agentic AI browsers and bots and can look at patterns, just like Matt and I talked about last week's episode. According to threat researcher Jerome Sugara at Fraud Prevention Specialist Data Dome, for retailers the distinction matters most at the account layer where they need to verify identity and amid rising automation. A data dome study conducted across 11 major e-commerce sites revealed that most work incapable of identifying genuine customers from malicious agents, leaving 64% of retailers open to mass fake account creation. The study also found that a third of retailers had no MFA in place or multi-factor authentication. Leaving account creation flows dangerously open. This vulnerability enables the creation of fake accounts at scale and allows them to pass verification unnoticed. I know a lot of retailers don't like MFA and think that it's a conversion killer, but it actually provides a sense of security to your users. That's what a lot of studies have shown in surveys that I've seen. David Mitten, Founder and CEO of Security as code startup ARCJET, advises shoppers to approach emerging AI-powered browsers such as OpenAI's Atlas with caution. I don't use them. I don't think that they are secure. They're interesting toys definitely play around with them, but don't add your credit card details he warns. According to Mitten, while Amazon and Shopify have robust protections in place for the majority of retailers, it has become a real problem. He points to research from meta that warns some autonomous agent setups may be inherently insecure. They've come up with these three components, and if you have all three of them, it's impossible to have a secure system. Detailing some of the methods used in Agente AI, he says malicious actors are increasingly embedding harmful instructions inside web pages, white text on a white background or even embedded in images, for instance, so that an AI agent inadvertently executes actions that the user never intended. Rogue shopping agents have consequences for users. This is a very robust article about what E-commerce merchants should be aware of right now. If an attacker plants these instructions in the way Mitten has suggested, an AI agent could purchase products that user, the user didn't intend to buy by multiple items or send the items to a fraudulent address. And because the AI is acting autonomously, the user may not even notice the money has been withdrawn for that amount of account. If an AI browser is tricked by malicious prompts, it could also auto fill and submit personal data, leak passwords stored from the session, and reveal email, payment, or address verification. These browsers may do things that you don't understand and you don't know. It's going to be very untrustworthy, he warns. The threat from agents in bad bots is something many retailers will need to address as they must strengthen bot detection and develop mitigation strategies, given that bots are increasingly mimicking human movements and behaviors. So then tell shoppers how they can protect themselves, things like using a unique password for every service or ideally a password manager to automate this process for you and to factor authentication. When used together, this will rule out 95% of all possible tax against you. The security expert also encourages shoppers to check whether their credentials have been exposed using services like have I been poned, noting that most password managers now provide automatic breach alerts. Shoppers also need to approach Black Friday deals with a skeptical mindset, manually entering URLs, rather than following ads or links reduced exposure to fake sites. Monitoring account activity during an after Black Friday helps catch unauthorized logins and purchases early before attackers escalate their access. So you see, those are pretty comprehensive article on a lot of the types of AI that are impacting e-commerce merchants right now. I thought that that was really a good thing to cover. Now to talk about how scammers are using AI to impersonate real lawyers, the Bureau of Investigative Journalism found dozens of fiverr propels advertising cheap legal advice with stolen credentials. Scammers are using one of the world's biggest freelance platforms to pose as real solicitors or lawyers, as we call them in the US, including employees at major fashion brands, investment banks, and the financial conduct authority. The Bureau of Investigative Journalism, TBIJ, has identified dozens of fiverr listings offering legal services while impersonating genuine UK lawyers, which is a criminal offense. The steel names and registration numbers from the solicitor's regulation authority, unique identifiers that confirm a lawyer is qualified and regulated, and pair them with AI generated headshots. Many of the profiles offered to draft data protection policies, tendencies, agreements, and other contracts hooking in potential customers with advertised prices as low as $10, or $761 in pounds. Some of the fake solicitors admitted in messages to TBIJ that they used AI in their work. TBIJ found and alerted 30 people and companies to fake profiles using fiverr to trade on their names and credentials. We also reported the accounts to action fraud and the SRA, which has since published a scam alert about fiverr. The regulator has recorded a sharp rise in bonus law firms and in bogus law firms and impersonation scams, publishing more than 1,400 alerts this year. Scammers are using one of the world's biggest-- we already read that part. Why is it saying this again? Ellie went on fiverr looking for a low-cost legal option last month. He found someone claiming to be a specific solicitor and using a real SRA number, but became suspicious when their responses to his questions felt like a chatbot, and the account owner refused to speak over the phone. The next day, Ellie looked up the solicitor and called his firm, which informed Ellie the profile was fake. Joseph, in quotation marks, the solicitor Ellie thought he was speaking to only learned his identity had been stolen thanks to Ellie. Screenshots shared with TBIJ confirmed the account used Joseph's real name and SRA number. So if they Google that lawyer, they can find them online. And oh, OK, they're legit. The person was clearly pasting everything into GPT Joseph said after chatting with the fake account. He added that if the imposter issued a certified document in his name, it would have been legally worthless. The solicitors have been impersonated, who have been impersonated on Fiverr include members of staff at the financial conduct authority, a big four accounting firm, and a global investment bank. Marcus Denning, a senior lawyer at MKLA in Australia told TBIJ that these scams adversely affect the level of public trust in regulated legal professions. Of the people and companies who reported to TVJ's findings, all confirmed that the accounts were impersonating them. Several firms added that they were investigating the fake profiles and had made their own reports to the SRA, action fraud, and Fiverr. When TBIJ contacted the Fiverr profiles posting as a prospective client, many claimed to be working abroad or listed in time zones outside the UK despite advertising themselves as UK-based. They quoted rates of 50 to 150 pounds to draft an NDA. Less than a UK-based lawyer would be likely to charge, but several times the rock bottom prices they initially advertised. So they'll advertise it for 10, and then when you talk to them, they'll say, oh, I actually, it's 20 or 30. Paul Hampson, director of SEL, solicitors, which represents victims of scams, told TBIJ that the rise in generative AI is fueling legal scams. Previously impersonating a legal professional would have required specialist knowledge. The jargon and legal know-how is very niche and to the profession, but generative AI can produce entire documents and certificates that look credible to the untrained eye. Ellie who works in tech said he only spotted the scam because he was very cautious online. That's probably why I didn't fall for it because I immediately felt something was wrong. Fiverr's community standards ban impersonation, misrepresentation, and the use of AI-generated profile pictures. But that's really hard to enforce. Many of the fraudulent accounts profile pictures did not match the lawyers they were impersonating and showed typical signs of generative AI use, including unnaturally smooth facial features, blurred, texturalist backgrounds, and distorted or smudge edges around hair and clothing. While this violates Fiverr's terms of service, sellers are free to use AI to complete work for their clients. And Fiverr does not proactively check listings. In fact, the platform advises buyers to state clearly if they do not want generated AI-generated work. Several of the fake account owners denied using AI in their legal work. One wrote to TBIJ, "I am a qualified UK solicitor. How will you expect me to be using AI to draft contracts?" Fiverr also does not screen legal services providers, including advertising buyers to verify details themselves. Advances in generative AI have made it possible to ask chat bots to draft complex legal documents, leading to even some lawyers making serious errors. In June, the high court ordered lawyers to stop misusing AI after dozens of fictitious cases were cited. The technology also nails fraudsters to create plausible legal service schemes. The majority of the profiles TBIJ identified remain live at time of publication, even though many law firms flagged them to Fiverr and requested that new year removed. Several solicitors in Fiverr did not respond after they reported the fake profiles. Joseph said the account impersonating him was eventually removed after he contacted the company, but Fiverr never acknowledged taking it down or apologized. In September, Fiverr announced it was becoming an AI first business, so the company would expand its use of artificial intelligence to improve fraud detection. A Fiverr spokesman told TBIJ that the company uses a combination of automated detection, manual review, and user reporting to remove listings that breach its policies, but declined to comment on the fraudulent listings we identified. Some lawyers run genuine accounts on Fiverr. Colin Gorge, one such solicitor, told TBIJ that the platform is crowded with AI-generated legal listings, prompting some clients who find him through the website to request video calls to verify his identity. One even left a review saying Colin's great and the best thing of all, he's actually legitimate. Experts say impersonation schemes are becoming more common as generative AI follows allows fraudsters to create convincing identities at low cost with little effort. I had a great thought. Sam Gregory, an expert on deceptive AI who has testified before the United States Congress, said fraudsters can now create personalized impersonations of verified professionals, like regulated UK lawyers, and deploy them on platforms where potential victims are actually actively seeking no services. Open AI chief executive Sam Altman in July said that he anticipated a significant impending fraud crisis as the internet becomes even more saturated with AI-generated content. Gee, thanks, Sam Altman. Fraud is the most common type of crime in England and Wales, accounting for over 40% of all offenses according to the National Crime Agency. In the first half of 2025, a record 217,000 cases of fraud or suspected fraud were recorded by CFS, and anti-fraud nonprofit, more than half of these involved identity fraud. And that's just in the first half of 2025. Simon Miller, director of policy at CFS, said AI has turned fraud into a service industry, making scams faster, slicker, and harder to detect, and allowing criminals to impersonate everyone from loved ones to solicitors. Tom, in quotation marks, the lawyer for a firm targeted by Fiverr fraudsters said platforms like Fiverr are a high-risk environment for fraud, and said it was absurd and unscrupulous that the company appeared to take no responsibility for fake listings. He added that regulators and consumer protection systems had been pretty hollowed out in recent years. The SRA regulates lawyers, but they struggle to manage non-lawyers who are effectively cybercriminals operating outside their jurisdiction. Tom noted several other lawyers at his firm were victims of identity theft in the past year. These criminals look for reputable firms and pick people at random. A few things about this article that I'm struck by. The first thing is Fiverr specific. I knew the founder of the trust and safety team for many, many years. She worked at Fiverr for maybe 10 years since the very beginning of the platform. We've been spoke at a conference in 2017 together, I think, or the '16, where she explained why they called it Fiverr because most services were $5 back then. It's an interesting idea. Being able to elicit some little different types of work from people all over the world, and in some cases, it can be significantly cheaper. There are podcast editors and podcast producers on Fiverr that you could pay to edit the podcast for you, and then, you know, you'd upload it to your feed and everything else. There's so many different types of options on Fiverr as far as what you can purchase from someone. The fact that these people are impersonating lawyers and getting away with it because of chat GPT, it doesn't surprise me. But what I was going to say is the founder of the trust and safety team at Fiverr, and this might be unrelated, but she left fairly recently. I'm actually going to look her up on LinkedIn and just see when she left. This may not have anything to do with it, but she was really good at her job. Yep, left in January of 2023. So that's-- she started there in 2025, so she was there for over seven years. She ran a tight ship, and so the fact that they're not catching it now could possibly be this, you know, why this problem is surprising. I also heard from a fraud fighter recently that their company had caught an engineer that was feeding the code that they needed to work on to someone on Fiverr. And that person was more than likely feeding it through to chat GPT or something like that. And then-- or GitHub or whatever they were doing. And then they were coming back with code. And oftentimes it was broken code that wouldn't work. And the engineer would provide that in their work. And they also found out that this particular person was doing this to a couple of different companies. So they had, you know, at least two full-time employment offers, and they were just basically acting as a middleman for their work that they needed to be doing, sending it to Fiverr, getting it back from Fiverr, submitting it to their employer, and eventually their employer realized that the submissions were garbage, and that the person who accepted this job didn't have any qualifications to be an engineer. So I don't know if we call out fraud. I mean, I think it is job fraud. But I thought that was really interesting that that's happening in real life. There's other types of jobs scams as well, but that's one where, you know, they just hire someone else to do it. There was another fraud fighter that was on the call with us. It was one of my group calls that said that their company caught one person working three full-time jobs because they were signed up to attend a conference three times with three different companies. All the companies were in the same industry. So when they were supposed to go to a conference, they were listed three times, but with three different companies. And that's when they realized, oh, no, wonder you've been slacking off in not attending meetings and not working because you have two other full-time jobs. So it's something to be aware of, for sure. All right, I have not even gotten through all of the articles that I said I was going to. And so we're definitely not going to get to the refund fraud piece, and we're already at an hour. So there's three more fraud news stories I was going to read today. But we're at 15 minutes, and I don't want to take up any more of your time. There's just so many things going on in the fraud world. So I'm going to stop it there, but I will pick back up next week and read the rest of the fraud news. And then we'll dive into some of those fraud stories about refund fraud, as well as a fraud story about a guy. It's just too crazy to be true. His name is Monty Millions, or that's what he called himself. And he committed synthetic identity luxury car fraud. And then he targeted his own judge when the judge was investigating his case, and he was being tried. This guy made up a really serious allegation against the judge to try to get him disbarred and off the bench. But he didn't make the allegation. His stepfather did or his daughter did. So anyway, it's a crazy story. It's fascinating and involves a lot of different types of fraud layered up on the top of each other. So that's always interesting. So we'll dive into those things next week, something to look forward to. Again, I'm just going to hand this episode the same way I started it. Thank you for listening. Thank you for your support. And for just being really awesome people, I really I rarely meet a fraud fighter that I don't think is awesome. That's a pretty rare event. So thank you guys for listening. And I will look forward to talking with you more next week. [MUSIC PLAYING]
Podcast Summary
Key Points:
Open AI confirmed a data breach exposing personal data of chat GBT users, including usernames, email addresses, and location data.
Kauai GPT is a free AI tool bypassing safety controls to provide unrestricted responses from deep seek, Gemini, and Kimmy K2 models.
AI may replace humans in Southeast Asia's scam complexes, potentially affecting efforts to combat human trafficking.
Scammers are using AI for various fraudulent activities, including impersonating lawyers and weaponizing Black Friday shopping.
Social media giants face liability for financial scams under new EU laws.
Summary:
The podcast episode discusses a data breach affecting chat GBT users' personal data, the emergence of Kauai GPT as a free AI tool bypassing safety controls, and the potential replacement of humans by AI in Southeast Asia's scam centers. Scammers are utilizing AI for various fraudulent activities, such as impersonating lawyers and weaponizing Black Friday shopping. Social media giants are now liable for financial scams under new EU laws.
The episode also touches on the challenges posed by AI in combating human trafficking and the exploitation of legitimate technology, such as Starlink devices, by scam centers. Concerns are raised about the ethical use of AI and the responsibility of users in ensuring its proper utilization.
FAQs
Usernames, email addresses, location data, operating system, and browser details were compromised.
Kauai GPT bypassed safety filters of AI models like deep seek, Gemini, and Kimmy K2 using reverse engineering and jailbreak scripts.
AI-driven automation may replace human workers in scam centers, potentially hindering efforts to combat human trafficking and scam syndicates.
Social media giants may face liability for financial scams under new EU law, but there are concerns about the effectiveness of content moderation and fact-checking on these platforms.
Scam centers in Myanmar exploited over 2000 Starlink devices for internet access, emphasizing the need for clearer licensing, user verification, and cooperation with regulators.
The risks of using tools like Kauai GPT include potential misuse for malicious purposes, bypassing safety filters of AI models, and responsibility for ethical use falling entirely on the user.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.