More than 45,000 fake ChatGPT cyber attacks

NGUYỄN ĐĂNG |

Kaspersky warns that fake AI service cyberattacks such as ChatGPT and Gemini are increasing, posing many worrying cybersecurity risks.

In the context of AI developing at a dizzying pace and expected to continue to help businesses improve productivity, Kaspersky experts warn about the risks of overconfiding in AI and lack of verification. These gaps are being exploited by cybercriminals to carry out attacks without relying on technical vulnerabilities, but only taking advantage of user trust.

How do bad guys take advantage of users' overconfidence in AI agents?

Recently, experts from the Kaspersky GReAT research group discovered 92,000 fake AI services attacks in 2026. Nearly half of them (49%) faked the ChatGPT application, 18% faked Claude and 18% faked Gemini.

These are all legitimate applications and play an important role in the process of working with AI agents, and are also tools used from the beginning in the software development environment. However, bad actors take advantage of trust in these applications to spread fake versions to attack those who use them.

In addition, cybersecurity experts also discovered more than 15,000 samples of malware disguised as AI agent software. These malware groups include Trojans, spyware, exploitation codes, malware download codes, malware installation codes and backdoor malware.

Although disguised as AI software, they all have the harmful function of a real malware. Just running a fake application, users can unintentionally create conditions for attackers to steal internal information and set up remote control over the device.

Mr. Sojun Ryu, a security research expert at Kaspersky GReAT, also pointed out another risk related to the development and application of AI: open source components.

The supply chain attack targeting Axios in March 2026 shows that cybercriminals are increasingly targeting software components trusted by many to be able to access a larger number of victims.

Axios is one of the most widely used JavaScript libraries in the world, with more than 100 million downloads per week and integrated into more than 170,000 software packages. The attacker first infiltrates the Axios project manager's computer, then accesses the project's account on the source code repository, and then releases versions containing malware.

Recommendations

In the context that productivity is increasingly becoming a decisive factor in operating efficiency as well as profitability of businesses, Mr. Ryu gave many recommendations to help businesses maintain productivity while still ensuring safety.

Businesses need to establish clear security boundaries between external content and internal resources used to develop software. At the same time, businesses need to strengthen security not only for the integrated development environment (IDE), but also for extensions, workspaces and access rights granted to AI agents.

In addition, he said that businesses need to strictly control how software is put into the development environment, and monitor all activities taking place in the system. The goal is not to increase the required approval steps, but to help the safe process become the simplest and most effective choice for users.

NGUYỄN ĐĂNG
RELATED NEWS

Vietnam in Top 12 countries most targeted by ciber attacks

|

According to Kaspersky, Vietnam is in the group of 12 countries in the world most targeted by targeted cyber attack groups in the first half of 2026.

EU tightens management of ChatGPT and Roblox under DSA Act

|

The European Union is preparing to impose strict surveillance regulations on ChatGPT and Roblox under the DSA Digital Services Act.

ChatGPT has a new health feature, connecting to Apple Health

|

OpenAI deploys ChatGPT Health to allow AI to connect health records to provide closer feedback to each user.

Trailer truck fire on Ho Chi Minh City - Long Thanh - Dau Giay expressway

|

Dong Nai - A tractor-trailer traveling on the Ho Chi Minh City - Long Thanh - Dau Giay expressway (Nhon Trach ward section) suddenly caught fire.

Collecting rocks overflowing into the Gianh River due to blasting, clearing the flow

|

Quang Tri - Businesses have mobilized human resources and equipment to handle the volume of limestone falling into the Gianh River area and reduce dust when mining stone.

Line disguised as a spa treating bone and joint diseases, deceiving nearly 300 people

|

Nghe An - A line disguised as a spa facility, subjects advertised bone and joint disease treatment to deceive nearly 300 people, transacting more than 9 billion VND.

5 fishing boats caught fire in Nghe An, damage of about 6 billion VND

|

Nghe An - The fire at the fishing port in Quynh Phu commune caused 3 fishing boats to be burned down, 2 other boats damaged, and estimated damage of about 6 billion VND.

Vietnam in Top 12 countries most targeted by ciber attacks

NGUYỄN ĐĂNG |

According to Kaspersky, Vietnam is in the group of 12 countries in the world most targeted by targeted cyber attack groups in the first half of 2026.

EU tightens management of ChatGPT and Roblox under DSA Act

NGUYỄN ĐĂNG |

The European Union is preparing to impose strict surveillance regulations on ChatGPT and Roblox under the DSA Digital Services Act.

ChatGPT has a new health feature, connecting to Apple Health

QUANG MINH |

OpenAI deploys ChatGPT Health to allow AI to connect health records to provide closer feedback to each user.