
AI Misfires, QR Traps, and Spoofed Sites: Netcraft Sounds the Alarm on 2025 Cyber Threats
Netcraft has dropped a new set of findings, and it’s not exactly comforting. The company, known for exposing online scams and protecting big-name brands, has outlined how artificial intelligence (AI), search engine trickery, and quick-launch phishing kits are changing the threat landscape—fast.
The first half of 2025 has already seen more convincing scams, faster site impersonations, and a disturbing new use of QR codes in phishing attacks. If it feels like fraud is getting smarter, it’s because it is.
Chatbots Are Now Recommending Scam Links
One of the more jaw-dropping revelations? Large Language Models (LLMs)—the same AI chatbots people use to answer questions and solve problems—are being manipulated into suggesting phishing sites. Researchers ran natural language queries for 50 popular brands and received 131 web addresses in return. Here’s the kicker: 34% of those sites weren’t owned or controlled by the brands.
So what happens when a chatbot, which people generally trust, recommends a fake site? That trust transfers—right into the hands of scammers.
SEO Poisoning Now for Sale
Another tactic gaining ground is SEO poisoning. In short, hackers are boosting scam websites into Google search results using hacked websites and shady link-building marketplaces.
Netcraft traced a large operation using a platform called Hacklink, which allows bad actors to buy access to thousands of compromised sites. They inject code to trick search engines into ranking fake brand pages higher—sometimes above the real ones. And this isn’t just a rogue operation. It’s structured, repeatable, and frighteningly scalable.
QR Codes Are the New Trojan Horse
If you’ve scanned a QR code recently, you’re not alone. But you might want to think twice next time.
Netcraft is seeing a surge in something called “quishing”—phishing via QR codes. The scam is simple. The attacker creates a QR code that, when scanned, takes users to a fake website. Once there, they might be asked to enter credentials, banking info, or other private data.
Because QR codes are often used by legitimate companies—think menus, tickets, payment portals—people aren’t expecting fraud. That’s what makes it effective.
Smishing Targets Drivers—And It’s Working
Toll text scams have also taken off. Netcraft tracked a 200% spike in fake DMV-related URLs in just two weeks this summer. The method: send a fake text message to someone claiming they owe money for unpaid tolls. The link looks official. The urgency feels real. Victims click and hand over sensitive data.
It’s low-cost, low-effort, and delivers a decent hit rate. For scammers, that’s the perfect recipe.
Phishing-as-a-Service Goes Pro
Phishing has leveled up. There are now services that let criminals create and launch cloned versions of real websites within minutes. These platforms are drag-and-drop simple. Choose a target. Spin up a fake site. Start stealing login credentials.
Netcraft reports that these impersonation kits are enabling large-scale spoofing campaigns that move at breakneck speed. What used to take hours now takes minutes. And the result? More users getting fooled faster.
What the Industry Needs to Know
Netcraft’s CEO, Ryan Woodley, summed it up bluntly: “Attackers never stop innovating, so defenders can’t stop, either.”
His point? Security teams can’t keep relying on static tools and assumptions. They need updated intelligence, automation, and systems that reach beyond the company firewall. Netcraft’s own platform blends AI with rule-based threat detection to keep up.
This isn’t theory. These are real tactics being used right now against real brands. If your company has an online presence—and let’s face it, whose doesn’t—you’re in the crosshairs.
What This Means Going Forward
AI has created a double-edged sword. On one hand, it gives defenders new tools. On the other, it hands bad actors scalable methods to trick users at industrial speed.
Phishing links wrapped in QR codes. Chatbots recommending scam sites. Fake toll texts that look legitimate. All of it’s happening, and the bar for launching attacks has dropped lower than ever.
Staying protected now requires more than blocking a few URLs or setting up firewalls. It demands real-time intelligence, machine learning, and the ability to recognize spoofed content before users ever see it.
Netcraft’s latest research is a wake-up call—not just for IT departments, but for anyone whose name is on a website.