ZDNET’s key takeaways
- There’s a brand new rip-off involving ChatGPT.
- The rip-off begins with a sponsored Google hyperlink.
- The hyperlink results in a customized GPT that provides malicious data.
A brand new rip-off involving ChatGPT has emerged, and it’d lead you to put in malware in your laptop should you’re not cautious.
Over the previous a number of days, experiences have surfaced of customers encountering an odd interplay when utilizing ChatGPT. “Service Availability Discover,” the message reads. “We’re at the moment experiencing restricted availability on the first area. Please select one of many following choices to proceed:”
Additionally: This new cyberattack tips you into hacking your self. Right here’s spot it
The chat presents a proposal to improve to a Plus subscription or a hyperlink to a backup area. Right here’s how the rip-off works, why it’s so convincing, and what you are able to do to keep away from it.
(Disclosure: Ziff Davis, ZDNET’s guardian firm, filed an April 2025 lawsuit in opposition to OpenAI, alleging it infringed Ziff Davis’ copyrights in coaching and working its AI programs.)
Artie Beaty/ZDNETThe customized GPT rip-off
The rip-off begins while you search “ChatGPT” in Google. Like virtually each Google search, you’ll see sponsored outcomes, or paid advertisements, above the genuine search outcomes. In case you click on on what seems to be an actual hyperlink to ChatGPT, you’re taken to what seems to be the precise web site.
As an alternative, you’ve landed on a customized GPT, or a user-generated, specialised model of ChatGPT that’s tailor-made for particular duties. On this occasion, the duty is to spit out the provision discover response it doesn’t matter what’s entered.
What’s most convincing is that you just’re on the precise ChatGPT area and your account is logged in (should you had been earlier than). There’s nothing at first to point this isn’t genuine apart from the title “Plus 5.6.” In case you’re not acquainted with ChatGPT mannequin naming conventions, although, this wouldn’t stick out.
Additionally: I’m a tech professional, and an AI job rip-off virtually fooled me
In case you click on the hyperlink within the response (it’s a free web site hosted on Google Websites and clearly not a ChatGPT area), you’re offered with a pretend Cloudflare verification and directions to stick and run a command in Home windows/PowerShell. Working that command installs malware in your laptop.
I attempted the method myself and clicked on the primary consequence after a easy seek for ChatGPT. I landed on one of many scams. It doesn’t matter what I typed, I received the identical “restricted” response with a hyperlink. My editor right here at ZDNET tried the identical course of and received the traditional ChatGPT, so it doesn’t seem like all sponsored outcomes.
Google advised me it had deactivated a number of accounts related to the precise advert marketing campaign I noticed, however that, after all, doesn’t imply this challenge received’t pop up once more, so it’s good to bear in mind.
Easy methods to keep secure
Right here’s how one can keep away from this particular rip-off, and a few basic recommendation for staying secure on-line.
- Sort chatgpt.com straight into your browser as a substitute of looking for it.
- Keep away from clicking on (or a minimum of be extremely suspicious of) sponsored hyperlinks in Google. These advertisements have a historical past of being malicious, a lot in order that Google has even deployed Gemini to detect and block dangerous advertisements.
- By no means paste and run a command in your laptop should you’re not sure what it’s going to do, particularly if a hyperlink or pop-up tells you to.
Roman Oliinyk, CEO and founding father of PayCore Media Inc, a community safety specialist who has spent 10 years constructing data-leak safety programs for giant US firms, famous that an actual Cloudflare verify would by no means ask you to do something in your keyboard. “At most,” he mentioned, “it asks you to verify a field or press a button.”
Additionally: This easy ChatGPT trick helps you see scams earlier than you click on or reply
Oliinyk additionally really helpful treating sponsored outcomes as advertisements (which they’re) and treating a hyperlink from a chatbot as you’ll a hyperlink from a stranger.
I’ve reached out to each Google and OpenAI for remark. OpenAI hasn’t responded but, however a Google spokesperson advised me: “Malvertising has no place on Google. We’ve suspended a number of advertiser accounts to dam this marketing campaign and we constantly replace our defenses to cease new threats.”

