New Zealand
Kiwis warned to be wary of scams in AI search results


Published by Ben Goldson
22 Sep 2026
As AI tools increasingly become an inescapable part of life, cybersecurity company ESET is sounding the alarm over the potential dangers cropping up.
Speaking to rova, ESET manager for New Zealand operations Scott Leman says they’ve found people are routinely being directed to high-risk websites.
“We've got a whole lot of research showing that the likes of ChatGPT are giving users bad links. It could be that they’re being sent to a site which might steal their information, it might tell them to download an application filled with malware and spyware, or all sorts of things. AI can't be fully trusted, but lots of people are going and trusting it, and potentially getting themselves into trouble.
Leman points out that as with any internet use, you need to keep your wits about you.
"AI is a fantastic tool to find information, but you need to be checking that it’s coming from a trusted location, and it hasn't been poisoned by a cybercriminal trying to cause you harm. It's the same as when you're Googling something, or just clicking on any link that might come through social media. Maybe it's normally a .co.nz site, and the link is something a little bit different, or maybe there are obvious spelling errors in the domain name. Even just feeling "hey, this doesn't look right", is usually a good sign that it's bad.”
Along with the potential for being directed to malicious websites, AI is also reshaping the wider world of cybersecurity, which Leman says presents opportunities for both the good guys and the bad.
“AI is becoming a productivity tool. Hackers can get it to design a genuine-looking email they can then send out to trick people. We're seeing AI scouring social media to create targeted campaigns, based on things like the restaurant that people might have been to the night before. We're also seeing recently these reports of AI itself actually going out and, by its own intuition, attacking companies and breaching them. What we're seeing is the requirement for good AI to be defending against the bad AI. We're using AI-based tools to do threat hunting, then going out and responding at machine speed to defend against an AI that's attacking at machine speed.”
With this multitude of threats now looming over innocent computer-users, Leman is urging people and businesses not to be complacent about this new reality.
“There's a misconception that, "I'm a small operator, who's going to attack me?". But cybercriminals don’t discriminate, especially when you can do these things at scale. Anyone who is making payments to someone or has any computers in their business could be at risk.
“Anyone who’s running a business needs to make sure that they’re getting solutions that are going to protect against these new attacks. It's no longer good enough to have a basic antivirus, or tell your people not to click on things. You almost have to assume that people are going to click on the wrong thing at some point, and as soon as that happens, you need to be able to respond quickly. We're also seeing plenty of attacks that don’t even use virus files. They're using things like phishing campaigns, where someone will type in their work credentials, and that's allowing the cybercriminals to then log in as them and do things like sending off fake invoices or changing the bank account number on an invoice.”
Leman recommends having AI-based security, with AI monitoring devices 24/7 to pick up any suspicious activities that are happening on a device, and then stopping it as quickly as possible.
Image credit: Boitume on Unsplash

Published by Ben Goldson
22 Sep 2026