
Major AI Agents Are Being Spoofed - and It Could Put Your Site at Risk
Companies Mentioned
Why It Matters
Spoofed AI agents enable attackers to perform unauthorized transactions and data theft on high‑value web platforms, threatening revenue and consumer trust; adopting zero‑trust controls is critical to protect these sectors.
Summary
Radware research reveals that malicious bots are spoofing popular AI agents such as ChatGPT, Claude and Gemini, masquerading as legitimate agents that require POST permissions for transactional actions like booking or purchasing. The rise of genuine AI agents that can write to sites has shattered the long‑standing security assumption that bots only read, leaving finance, e‑commerce, healthcare and travel sites especially exposed. Because chatbots use disparate verification methods, spoofed agents can slip past defenses and exploit the same write privileges granted to trusted bots. Researchers recommend a zero‑trust approach for state‑changing requests, AI‑resistant CAPTCHAs, treating all user‑agents as untrusted, and strict DNS/IP validation to mitigate the risk.
Major AI agents are being spoofed - and it could put your site at risk
Comments
Want to join the conversation?
Loading comments...