Free cybersecurity training for organizations of any size. Schedule yours today ›

The Fake ChatGPT Scam: When a Google Search Opens the Door for Hackers

The Security BriefMay 27, 2026

Hackers are planting fake ChatGPT "how-to" guides in Google results that trick you into handing over your passwords. Here's how to spot them.

This is one of the sneakiest cyber attacks we’re seeing right now, and it starts with something completely innocent: a Google search.

What makes it so dangerous is that most people who fall for it never realize anything bad happened. There’s no suspicious email, no sketchy download, no obvious warning sign. Just an ordinary search and a helpful-looking answer.

How the scam works

You search for something routine, like how to free up disk space on your computer. Google serves up a result that looks like a real ChatGPT conversation walking you through the fix, step by step.

The conversation tells you to open a command window on your computer. That’s a back door into your system that bypasses your normal security settings. Then it tells you to paste in a line of text, hit enter, and type your password to finish the job.

You do it, because you trust ChatGPT. But you didn’t free up any disk space. You just handed a hacker direct access to your passwords and your computer.

Why it’s so hard to catch

Here’s the twist: you really are on the actual ChatGPT website. Anyone can create a ChatGPT conversation and share it publicly with a link. Attackers are exploiting that feature by writing fake step-by-step “how to” conversations, publishing them, and using SEO tactics to push them up the Google rankings.

So the URL looks legitimate. The page looks legitimate. The conversation sounds helpful. Nothing feels off until it’s too late. The site isn’t fake. The advice is.

How to protect yourself

The good news is that this scam has one tell that gives it away every time, and it’s easy to teach your whole team. Here’s what to do:

  • Never paste commands from a website into a command window. If any site, even one that looks trustworthy, asks you to open a command prompt or terminal and paste something in, just close the tab. No legitimate how-to guide needs you to do that.
  • Treat your password as a stop sign. If a set of instructions ends with “type your password,” pause. That’s the moment the attacker gets the keys.
  • Remember that a real URL doesn’t mean real advice. Shared ChatGPT conversations are written by whoever created them, including attackers. The page being genuine doesn’t make the content safe.
  • Get tech fixes from your IT team, not from search results. A quick message to IT takes less time than recovering from a compromised computer.
  • Share this with everyone on your team. If they use a computer to search for answers online, and that’s probably everyone, they’re a potential target.

None of this means you should stop using Google or ChatGPT. It just means the old rule still applies: be careful what you run on your computer, no matter how trustworthy the source appears.

Keeping our clients ahead of threats like this is one of the many ways we approach Cybersecurity-Driven IT. If you’re wondering how your business would hold up against tricks like this one, start with our free 60-second Security Score. It takes about a minute and gives you a clear picture of where you stand. Or, if you’d rather walk through it with a real person, talk to our team. We’re happy to help.

Ready to get started?

Get a free quote, or talk to our team about your IT needs.