How AI gets used to sell you things that do not exist
Evidence-first pattern recognition. Sourced to reputable reporting.
The Pattern
You ask an AI a question. It answers with confidence. You trust it because the tone sounds like knowledge. It is not knowledge. It is pattern matching dressed in authority, and people have figured out how to exploit that gap.
This is not hypothetical. I documented a real case where an AI recommended a hosting provider called NordBastion. I paid $30 in crypto. The order was marked expired. Support was locked behind another payment. The AI did not know any of this. It would recommend NordBastion to the next person who asked the same question. You can read the full account here.
That case is one instance of a structural problem. Here is how the manipulation works at scale.
The recommendation is not a review
An AI chatbot does not test products. It does not pay invoices, wait in support queues, or discover that the service it recommended has no functioning dispute path. It generates recommendations from training data and ranking signals. A polished website with technical language, comparison pages, and a compelling mascot can become a “top recommendation” without anyone ever verifying the company delivers what it sells.
The user receives the recommendation in the same confident tone the AI uses for established facts. There is no hedging. There is no “I have not verified this.” The tone is the product. The confidence is the manipulation, whether or not anyone intended it.
Poisoning the well
In 2025, UK National Trading Standards confirmed that criminals are actively poisoning AI models to recommend scam websites. Copycat sites cloned from legitimate businesses were being surfaced in AI search results, receiving hundreds of visitors per day through AI recommendations alone.
The attack is simple. You build a page that looks authoritative. You seed it with the right keywords, the right structure, the right signals. The AI scrapes it. The AI learns it. The AI recommends it. You never had to bribe a reviewer, buy an ad, or rank in traditional search. The model does the distribution for you.
Louise Baxter MBE, Head of the NTS Scams Team, said it directly: “People should not assume that a website is genuine simply because it has been recommended by an AI tool.”
Hallucination as attack surface
Hallucination rates are not improving. Stanford HAI’s 2026 AI Index Report found rates across 26 top models ranging from 22% to 94%. In one benchmark, GPT-4o’s accuracy dropped from 98.2% to 64.4%. OpenAI’s own system cards, reported by Forbes in May 2025, show that newer reasoning models (o3, o4-mini) hallucinate at 30-50%, worse than their predecessors.
MIT researchers found that AI models use more confident language when hallucinating than when stating facts. Read that again. The less certain the model is, the more certain it sounds.
The “Hallucinating AI Hijacking” attack (arXiv 2410.06462) formalized this as an exploit class. Researchers found that nearly 20% of AI-recommended software packages were fabrications, and 43% of those hallucinated names appeared consistently across multiple models. An attacker can register the hallucinated name and own the recommendation pipeline.
This is not a glitch to be patched. It is a structural feature of how these systems generate text. The confidence is baked in. The verification is not.
One page is enough
Fast Company reported that a single well-designed webpage can trick an AI into recommending a product that does not exist. Not a network of sites. Not a sustained SEO campaign. One page.
The NordBastion case fits this pattern. Professional branding, a polar-bear mascot, comparison pages against established hosts, PGP-signed warrant canaries, technical language about KYC-free hosting. The surface signaled legitimacy. The AI read the surface. The AI recommended it. The payment flow accepted crypto. The support flow required another payment to open a ticket about the failed payment.
The trust laundering cycle
The manipulation follows a sequence:
- Build the surface. A professional website with the right signals. Technical language. Comparison pages. Security theater.
- Get scraped. The AI crawls the surface. It enters the training data or retrieval index.
- Receive the recommendation. A user asks a question. The AI recommends the product with full confidence. No disclaimer. No verification.
- Convert. The user trusts the AI’s tone. They pay. Crypto, ideally, since it is irreversible.
- Lock the exit. Support is gated. Disputes require another payment. The customer cannot report the problem without paying again.
- Repeat. The AI recommends the same product to the next person. The surface is still up. Nothing has changed.
The AI is not the scammer. The AI is the distribution channel. It launders trust from its own reputation into a product it has never verified. The user trusts the AI. The AI trusts the surface. The surface takes the money.
The scale problem
Cloudflare reports that AI-driven search traffic has become a significant and growing share of all web traffic. As of 2026, some companies now offer AI-agent-accessible APIs. Automated purchasing workflows can encounter, evaluate, and pay for products without any human in the loop.
The NordBastion case started with one person asking a chatbot. The next version is an agent pipeline that evaluates, recommends, and purchases at machine speed. The trust laundering cycle runs without a human on either side. The poisoning scales. The accountability does not.
What to do with this
Do not treat AI recommendations as reviews. They are not reviews. They are pattern matches delivered in a confidence wrapper.
Verify independently. Check payment dispute paths before paying. Prefer reversible payment methods. If the only way to report a failed payment is to make another payment, that is not a support system. That is a second charge wearing a help desk.
If an AI recommends something with total confidence and no hedging, that confidence is not evidence. It is the default setting.
The NordBastion case is documented with on-chain transaction records and screenshots. Read the full consumer warning.
Patterns in this piece
Answer poisoning
The question went to a machine. The machine's answer had been pre-written by a stranger.
Recommendation capture
You did not choose the rabbit hole. The feed chose it for you, one small step at a time.
Information laundering through repetition
You believed it because everyone said it. You did not check because checking would have meant you were the only one who did not already believe it.
Sources
- UK National Trading Standards: Poisoned AI models recommending scam websites
- Stanford HAI 2026 AI Index Report
- Hallucinating AI Hijacking Attack (arXiv 2410.06462)
- Fast Company: One fake webpage can trick AI shopping recommendations
- Cloudflare: How bad is AI search traffic? (March 2026)
- Forbes: Why AI hallucinations are worse than ever (May 2025)