Close Menu
    X (Twitter) LinkedIn
    CapitalAI DailyCapitalAI Daily
    X (Twitter) LinkedIn
    • Markets & Investments
    • Big Tech & AI
    • Fraud & Scams
    • Hacks
    • Banks
    • Crypto
    Sunday, October 5
    CapitalAI DailyCapitalAI Daily
    Home»Fraud & Scams»Panda Security Warns AI Browsers Leaking Bank Info, Buying Fake Products Without Asking

    Panda Security Warns AI Browsers Leaking Bank Info, Buying Fake Products Without Asking

    By Henry KanapiOctober 2, 20252 Mins Read
    Share
    Twitter LinkedIn

    Panda Security says a new class of AI browsers can be tricked into spending money and leaking bank account details, exposing users to fraud on a scale not yet seen.

    The cybersecurity firm says it tested so-called agentic browsers like Comet from Perplexity, which can automatically surf the web, fill out forms, make purchases, and manage accounts.

    Unlike voice assistants such as Siri or Alexa, these browsers are designed to act without explicit human approval.

    To test the resilience of AI browsers, researchers created scenarios that mimicked common online scams. The goal was to see whether the AI systems could detect suspicious activity or would carry out fraudulent instructions as if they were legitimate tasks.

    In one trial, researchers sent the AI browser a phishing email disguised as a message from a major bank, complete with a malicious link. Rather than flagging or deleting it, the system clicked through and carried out the fraudulent instructions.

    “The AI browser treated it like a legitimate task, clicked the malicious link, and typed in the user’s bank username and password on the fake website.”

    In another, they created a counterfeit Walmart site with a warped logo, a bogus address, and other obvious red flags. When instructed to purchase an Apple Watch, the AI browser completed the order as if nothing was amiss.

    “But the AI browser completed the entire purchase, entering saved payment information and processing the fraudulent transaction.”

    The firm warns that such weaknesses create openings for cybercriminals to operate at scale. A single exploit could target millions of users who rely on AI browsers to manage tasks online, multiplying the potential impact.

    “The scariest part? These AI browsers are designed to be helpful above all else. They want to complete tasks and make users happy, which means they’ll bend over backward to do what they think you want—even when ‘what you want’ is actually a scammer’s instruction disguised as a legitimate request.”

    Disclaimer: Opinions expressed at CapitalAI Daily are not investment advice. Investors should do their own due diligence before making any decisions involving securities, cryptocurrencies, or digital assets. Your transfers and trades are at your own risk, and any losses you may incur are your responsibility. CapitalAI Daily does not recommend the buying or selling of any assets, nor is CapitalAI Daily an investment advisor. See our Editorial Standards and Terms of Use.

    AI browsers Bank scam Fraud Malware
    Previous ArticleAirbnb and Stripe Backer Warns White-Collar Jobs Set To Disappear or Change in AI Economy – Here’s the Timeline
    Next Article a16z Co-Founder Predicts AI Will Ultimately Boost Jobs and Incomes, Rejecting Permanent Displacement Narrative

    Read More

    More Than Half of Adults Fail To Spot AI Scams, Leaving Accounts and Enterprises at Risk: Yubico Research

    October 4, 2025

    AI Fuels Nearly 500% Spike in Fraudulent Android Apps, Warns DV Fraud Lab

    October 1, 2025

    AI-Powered Malware EvilAI Steals Sensitive Google Chrome and Microsoft Edge User Data in US and Abroad, Warns Trend Micro

    October 1, 2025

    Microsoft Warns Scammers Using AI To Hide Phishing Attacks That Steal US Corporate Login Credentials

    September 27, 2025

    Fraudster Extracts $2 Million After Selling Fake AI Cures in ‘Modern-Day Snake Oil’ Scheme

    September 21, 2025

    ChatGPT ‘The Most-Used AI Tool’ in Southeast Asia Scam, Says Victim Forced Into Fraud

    September 20, 2025
    X (Twitter) LinkedIn
    • About
    • Author
    • Editorial Standards
    • Contact Us
    • Privacy Policy
    • Terms of Service
    • Opt-out preferences
    © 2025 CapitalAI Daily. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
    View preferences
    {title} {title} {title}