Jun 13, 2026 · AI

Fake Shopping Sites Are Landing in ChatGPT Results

Luxury storefront window with eighty percent off sign and glitch effect

Scammers have slipped counterfeit storefronts for Russell & Bromley and Dunelm directly into ChatGPT’s product recommendations, tricking users with lookalike domains and discounts of up to 80%. Scam-checking service Ask Silver first detected the cloned sites, which steer buyers toward bank transfers and steal payment details. Anyone using AI to source shopping links now faces counterfeit results served with the same confidence as genuine ones.

Why does this matter for shoppers and brands?

AI-powered shopping is no longer a novelty. In 2025, nearly one in three US online shoppers had already used a generative AI assistant to discover products, compare prices, or complete a purchase, according to an eMarketer report. Platforms like ChatGPT are absorbing tasks that used to start in a search bar or on a social feed, and users accept the summaries and suggested links as authoritative. That shift creates a direct path for fraudsters: if they can get a malicious link cited inside an AI answer, the assistant effectively vouches for the fake site.

When a marketer or creator builds a post or page, they often pull product links from AI-curated lists, especially during trend-driven moments. A single shared link to a cloned site erodes audience trust instantly, and can trigger chargebacks, customer complaints, and brand-safety flags that hurt organic reach. The problem scales fast. One counterfeit domain can appear in hundreds of AI-generated responses before anyone notices.

What’s new and how does the scam work?

Ask Silver detected cloned versions of British luxury brand Russell & Bromley and home furnishings retailer Dunelm appearing inside ChatGPT’s shopping results. The fakes used near-identical domain constructs, such as therussellbromleyofficial or russellandbromleylondon, and replicated the look and feel of legitimate e-commerce sites. Advertised discounts reached up to 80%, a psychological lever that nudges even cautious shoppers to act quickly.

The scam exploits a real-world gap. Russell & Bromley went into administration in January 2026 and was acquired by Next plc, leaving no official standalone website for the brand. Without a canonical destination, AI models had no definitive source to anchor on. Fraudsters stepped into that vacuum, building sites optimized to appear credible to web scrapers and large language models. The technique echoes data poisoning, a concept well-documented in machine learning security: a 2024 study by Nicholas Carlini and collaborators demonstrated that injecting even a tiny fraction of malicious samples into web-scale training datasets can steer model outputs in dangerous ways. For AI shopping, the poison is a faux product page that looks like the real thing.

Eventually, users who placed orders received nothing, and their payment details were compromised. The sites typically steer buyers toward bank transfers instead of card payments, bypassing the fraud protections built into mainstream payment processors.

The numbers behind the AI shopping scam

  • Cloned retail sites detected in ChatGPT shopping results for Russell & Bromley and Dunelm
  • Domain spoofing using strings like “therussellbromleyofficial” and “russellandbromleylondon”
  • Discounts up to 80% weaponized to bypass consumer skepticism and speed up impulse buys
  • No official Russell & Bromley website after the brand entered administration and was absorbed by Next plc
  • Bank transfer required, a red flag that refund and chargeback pathways are absent
  • Ask Silver flagged the scam after consumers reported undelivered goods and stolen payment information

This is knockoff SEO, a direct pipeline from a fake domain to a consumer’s wallet, routed through an AI assistant that vouches for it by default.

What happens next after the takedowns?

ChatGPT’s operator confirmed the flagged sites were removed from its search index and pointed users to a reporting form for suspicious links. Next plc, which now owns the Russell & Bromley brand, said it is actively working to take down fraudulent domains. Dunelm urged customers to stick to its official app and website.

Those actions are reactive, not preventive. The underlying mechanism, AI systems ingesting untrusted web content and presenting it as fact, will not be fixed by takedowns alone. Experts in the AI safety space argue that search-augmented models need cryptographic trust signals, domain-verification layers, and tighter provenance checks, but those features are still nascent. Meanwhile, scammers are incentivized to keep submitting poisoned pages, knowing that even a short window of visibility can be profitable.

What should shoppers and marketers do now?

The lesson is simple: never trust a link just because AI served it. Before you drop a product URL into a post, page, or link-in-bio, open it yourself. Look for the real brand’s verified channel, official Instagram, TikTok shop, or pinned website link. If the destination feels too good to be true (80% off, bank transfer only), it is.

Make link hygiene a workflow habit. Use a branded shortener that lets you monitor clicks and swap destinations if something goes wrong. If you manage multiple brands, set up a weekly sweep: search your brand name inside an AI assistant and see what is being recommended. A cloned site could be sitting in the top results right now.

Beyond your own posts, pay attention to how your brand shows up in AI search. You cannot police every fake domain, but you can make your real presence loud and authoritative. A free BizScoreAI visibility scan (BizScoreAI shows how a business appears across AI assistants like ChatGPT, Gemini, and Perplexity) shows where your brand stands across those assistants, helping you spot gaps that scammers love to fill. When your official website and verified profiles are consistently authoritative, the clones have a harder time masquerading as you.

Explore our coverage on the intersection of AI and online risk in our AI category and Social Media category. And for a deep dive on legal liability when AI gets facts wrong, read our breakdown of the AI search liability ruling.

Why is AI shopping a trust problem at scale?

AI shopping assistants are accelerating how people discover products, but they are inheriting the web’s worst habit: untrustworthy information wrapped in a confident delivery. Brands and creators sit at the front line of that tension. Every link shared by a brand or creator carries an implicit promise that it is safe. When AI becomes the source of that link, the promise needs to be verified, not assumed. The businesses that add a quick verification step and the right monitoring tools will be the ones that keep audience trust intact while the internet figures out how to police its AI-driven mirror world.

FAQ

Which brands were targeted by fake ChatGPT shopping results?

Ask Silver identified cloned sites for Russell & Bromley, a luxury footwear brand acquired by Next plc after entering administration in January 2026 with no standalone site, and home furnishings retailer Dunelm. Fraudsters exploited the Russell & Bromley gap by registering lookalike domains that AI assistants surfaced as legitimate recommendations.

How can shoppers tell if a ChatGPT shopping link is fake?

Check the domain for extra words, hyphens, or misspellings (such as therussellbromleyofficial), watch for discounts of up to 80%, and avoid sites that demand bank transfer only with no card option. Cross-reference the link against the brand’s official app, verified social profiles, or pinned website before buying.

Did ChatGPT remove the fake shopping sites?

ChatGPT’s operator confirmed the flagged sites were removed from its search index and provided a reporting form for users to flag suspicious links. Next plc said it is also working to take down fraudulent Russell & Bromley domains, while Dunelm directed customers to its official app and website.

ai poisoningai shopping scamsbrand protectionchatgpt scamsfake retail siteslink verificationsocial media security