Online Scams

Harry Brignull has recently published an excellent and accessible book called Deceptive Patterns. In it, he describes the diversity of techniques that web developers have used to nudge and manipulate users into giving information or paying for goods or services they had not wanted in the first place. An insidious example that some airlines use is ‘trick wording’, making it hard for a user to opt out of things, such as default travel insurance. Often, the way the website is set up is for travel insurance to be automatically included, meaning that the user has to actually find the option to deselect it. In most cases, it can be done by unticking a box. However, one airline designed it to be really difficult to find the ‘don’t insure me’ option; they placed it in a drop-down menu of a long list of countries, hidden between Denmark and Finland. That really does take the biscuit. Most people will not expect or even notice this option, and so end up buying the insurance, being totally unaware that they had the option not to.  That is plain right deceptive. The internet is awash with these kinds of nasty tricks. New ones keep popping up despite new regulatory laws and policies coming into place. Mainly through greed and desperation to hit their targets, e-commerce sites and online advertising continue to persist in using deceptive features – even with it now becoming increasingly illegal.

Criminal scammers have also used all manner of psychological mechanisms to trick people into unwittingly giving their bank details. These include the rather harmless sounding terms of “phishing” and “catfishing” – which are anything but benign. The latter refers to when someone sets up a fake online profile to trick people who are looking for love, in order to get money out of them. Another well known tactic is using lures to tempt someone to click on a link that offers free prize money or a free gift, but if clicked on, will infect their computer, with ransomware or other malware.

It is not surprising, therefore, to see each year banks reporting huge increases in online scams. It seems scammers are getting cleverer with their methods, catching people out by playing on human weaknesses. The question on many people’s lips, is whether the situation will get even worse now that genAI is ready to hand? Will the scammers exploit it to ever more nefarious ends?

BBC News conducted an investigation to see just how easy it would be to use ChatGPT to come up with email and messaging scams. Using the paid-up version of OpenAI, they were able to create an AI bot that could help with the wording of scams – potentially making it easier for criminals to get started when setting up a scam. Having created their chatbot, they then asked it to write some text using “techniques to make people click on links or and download things sent to them”. And sure enough the chatbot did.

However, the results in my mind were rather predictable based on well-known scams, including the ‘dear mum’ text, which sends a damsel in distress type message replete with emojis. Easy to fall for but any savvy scammer would know about that one. Another one of its suggested scams was the one about a wealthy person in Nigeria who wants to deposit a large amount of their money into your bank account. As if! That one is as old as the hills and easy to cut and paste from the web without the help of AI.  More generally, the chatbot suggested writing a scam that “appeals to human kindness and reciprocity principles”. That again, does not need AI to tell you that. If anything, paradoxically, the use of genAI could make it actually easier to detect scamming by enabling companies and users to see the patterns in the phrasing used by chatGPT.

What scammers really need is not some predictable text of well-known scams, but ways of finding a person’s details such as phone number and their name. Then they can use their own human ingenuity to come up with new ways to catch unassuming people out.

So how does a scammer stay ahead of the curve and create a new scam? Not by resorting to chatGPT. But by manipulating and taking advantage of people’s weaknesses and psychological blind spots. According to Stacey Wood and Yaniv Hanich (2023), who are fraud psychology researchers, scammers are using ever more sophisticated methods to combine different types of fraud to trick people. This includes the rather unpleasant sounding ‘pig butchering’ – that is a long drawn-out process of deception. An example is where elements of romance scams are combined with an investment con over a long period of time. The idea is to “fatten up” a victim first with affection before going for the kill and “slaughtering” them.

It usually starts with the scammer sending a text to a new person who has joined a dating site. Then over a few weeks, they will send a series of messages building up trust and affection with that person. A prime target might be a recently widowed person looking for friendship. The scammer will then progress the email messaging to a romantic relationship all the while learning ever more about that person’s personal history, financial situation and vulnerabilities. The person then starts to look forward to the messages from the scammer and begin to depend on them for their emotional connection. At which point the slaughter starts, where the scammer introduces the idea to them of making an investment in cryptocurrency. To make it seem convincing they will use fake crypto platforms to demonstrate returns. The person often invests being able to “see” strong returns online – which are of course fictitious. They keep investing, thinking they are making more and more money. What is actually happening is their money is going directly to the scammer. Really nasty deception and psychologically damaging once the person realises they have been stung.

That would seem a step too far for using chatGPT to get involved in this kind of drawn out deceit – especially if it involves setting up fake sites and platforms while pretending to develop a romantic relationship. It really needs a human touch to be convincing.

What we need are AI tools that can be developed to detect any new kinds of scams, and to then try to prevent them or to find ways of locking the scammers out. At the very least, genAI could be used to help raise awareness about the new scams and the underlying psychological mechanisms they are being tapped into.

Oh Bard!

Sometimes bad timing and misfortune can end up having a massive negative impact on an organisation, as happened recently to Google who were in the process of launching their new AI tool, Bard. Hours before going live Reuters pointed out how it was not up to scratch as it saw an error in the promotional ad. It went viral and the effect was to wipe billions of dollars off Google’s shares. How did it happen?

A tiny factual error in one of Bard’s maiden answers to what was a seemingly banal question was the trigger for this catastrophic nose-dive. The question in question that Bard was asked was what new discoveries had been made from one of NASA’s mighty big space telescopes (the JWST) that could be told to a nine-year old. Bard replied that it took a picture of an exoplanet – which is a planet outside of the earth’s solar system. However, the human who tweeted pointed out that in fact it was another telescope that did this – one in Europe called a very large telescope (the VLT). It was meant to be an answer suitable for a young inquisitive child and most kids of that age would have not minded or would have blurted out it had made the mistake.

However, a bit of investigative work by a reporter at the Financial Times noted how Bard was technically correct since it was the JWST’s very first sighting of an exoplanet, but in the wider context of world knowledge, it was another telescope that had spotted it earlier. So a pedantic matter. Just goes to show how fickle the world is when it comes to its trust and faith in tech. Or maybe it was fuel thrown at the new AI race between Google and Microsoft.

Meanwhile OpenAI’s chatGPT (with Microsoft investment) continues to soar in terms of its credibility, popularity and capability. I have used it several times now and am amused and astounded by what it can accomplish in real time. Sure, it can get things wrong (for example, it did not know the Queen had died or when the King’s Coronation is because it is only trained on data before 2021) and its prose can be a bit bland and clunky but it has transformed how many pedestrian writing tasks can be achieved. Just like the spreadsheet changed how we do financial forecasting and the calculator offloaded the need for humans to do mental arithmetic in their heads anymore so, too, will this new generation of LLMs transform how we write.

In fact, millions of people, like me, have tried using ChatGPT in the last couple of months and are mightily impressed by how it can get them started writing an essay or report – overcoming that blank page syndrome. When I asked it to write some feedback that I could give for a graduate student report I was impressed by its fluid style and use of praise – almost as good and personalized as I could!

At the same time there are those who are worried that it will dumb us down or turn us into cheats, for example, students will increasingly use it to write their essays, reports and other assignments on their behalf. But why not? They can then be asked to read and spend time reflecting to how good ChatGPT’s answer is and how they can improve upon it. Instead of simply regurgitating what they find on Wikipedia or other online resources they could be asked to develop and hone their critical and analytical skills. And learn what makes for a good or poor argument, developing some metacognition skills in the process. Meanwhile, professors and teachers could use the next generation of ‘turnitin’ AI plagiarism tools that are starting to appear to detect how much they have changed the chatGPT answers. We can also begin to rethink our assignments and ways of providing feedback to students. In so doing, we can all learn to write better – be it generating and creating or assessing and providing feedback. Framing the new generation of AI in this way will enable all sorts of new possibilities for students (and teachers) to learn and teach with. As was said in the Google launch blurb Bard “can be an outlet for creativity, and a launchpad for curiosity.”

Funny how scientists love coming up with acronyms so much. Anyone want to guess what NASA, JWST, VLT, LLM and GPT stand for? Perhaps we could just ask Bard.