Sinister AI bot steals your log-ins with eerie phone call – simple list of rules saves you from becoming instant victim
All recommendations within this article are informed by expert editorial opinion. If you click on a link in this story we may earn affiliate revenue.
AI BOTS are stealing victims’ log-ins by tricking them with fake information and spoofing banks.
But there are simple ways you can protect yourself from these evil scammers.
Two-factor authentication (2FA) which provide one-time passwords are usually regarded as a safe way to protect against phishing and theft.
But, they are "not a magic bullet," warned anti-virus experts .
"Even with 2FA, personal accounts remain vulnerable to one-time password bots," it added.
"Sites usually send a verification code in the form of a text, email, push notification, instant message, or even a voice call.
"The code can be generated in a special app directly on the user’s device, although, sadly, few people bother to install and configure an authenticator app."
ONE-TIME PASSWORD BOTS
These AI bots pretend to be legitimate organizations including banks to make their victim reveal a one-time password (OTP).
Firstly, they steal the victim’s login credentials — including a password.
The AI bot then calls the unsuspecting victim to get their OTP.
The crafty way this is achieved is with a pre-recorded social engineering script.
"The unsuspecting victim keys in the code right there on their phone during the call; the code is relayed to the attacker’s Telegram bot [and] the scammer gains access to the victim’s account," said Kaspersky.
HOW AI BOTS START
Fraudsters launch their AI bot scams by initially buying a subscription in crypto which costs about $420 a week.
The bots are given the intended victim’s name, number, and banking details.
Create strong and unique passwords for all your accounts.
"Scammers can’t attack you with OTP bots unless they know your password, so generate complex passwords and store them securely," it said.
"If you receive a message with a link to enter personal data or an OTP, double-check the URL.
READ MORE SUN STORIES
"A favorite trick of scammers is to direct you to a phishing site by substituting a couple of characters in the address bar."
Just as importantly, don't ever share your one-time passwords with anyone - and never enter them on your phone keypad during a call.