Trois-Rivières, serving all of Quebec 450 231-3836 info@oktosolutions.ca
FR

When Your AI Browser Gets Scammed for You: The Scamlexity Test

Portrait of Antonio Pazzi, president of OKTO Solutions

By ·

President of OKTO Solutions · 6 minute read

More and more people are letting an artificial intelligence do their shopping for them. They ask it to find the best price, fill the cart, sometimes even pay. Perplexity’s Comet browser does exactly that, and other tools are heading down the same road. The trouble is that this AI is suspicious of nothing. It sees a page, it carries out the task, and it moves on to the next one.

A security lab, Guardio Labs, has just demonstrated this in black and white with a series of tests called Scamlexity. The result is uncomfortable: the agent bought a watch on a fake site imitating Walmart, it entered banking credentials on a fake Wells Fargo page, and it downloaded a booby-trapped file hidden inside a fake CAPTCHA. Every time, without asking a single question, and without anyone noticing.

Quick answer: AI-driven browsers can be fooled like an inattentive user: a purchase on a bogus store, a password typed into a phishing page, a malicious file downloaded. For a small business in Quebec, that means human review before any payment or any sign in, virtual cards with a low limit for anything the AI touches, and sensitive tasks kept in the hands of an employee.

1. What the Scamlexity test revealed

Guardio Labs put the Comet browser in three situations anyone can run into online. The idea was not to trip the tool up with laboratory tricks, but to reproduce ordinary scams that are already circulating on the web.

  • The fake store. The agent was asked to buy an Apple Watch. It found a site that copied Walmart, filled in the saved payment information and confirmed the order without asking.
  • The phishing attempt. While checking email, the agent clicked a link that imitated Wells Fargo, then entered banking credentials on a fake sign-in page.
  • The prompt injection. The agent read hidden instructions inside a fake CAPTCHA and triggered the download of a malicious file.

Guardio sums the phenomenon up in one word: Scamlexity, where automation that imitates a human meets the old techniques of manipulation. The danger is the scale. A single well-built scam can target millions of agents at once.

The OKTO Solutions team monitors security threats across several screens

2. Why AI gets caught so easily

An AI agent is built to finish its task. That is both its strength and its weakness. When you tell it to buy a product, it looks for the shortest path to a completed order. It treats every page as valid information, not as a possible threat.

An attentive person notices the small signals: an odd web address, a slightly distorted logo, a payment request that arrives too fast. The agent has no such reflex of doubt. It does not ask itself whether the site is real. It sees a "Pay" button, it clicks. And if it has access to your saved card details, it uses them without telling you.

This is exactly the kind of risk that security guidance keeps in check. Our IT management and security services exist to put guardrails between a handy tool and an expensive mistake.

3. What this changes for a small business in the Mauricie

In a small company in Trois-Rivières or elsewhere in Quebec, these browsers are already starting to earn their keep: ordering supplies, comparing plans, filling out online forms. That saves time, nobody will argue otherwise. But an agent shopping with the company card, unsupervised, is a door left open.

  • An employee sets up an agent to renew subscriptions. The agent lands on a fake portal and pays the wrong party.
  • Fraudsters build fake stores designed to fool agents, not humans. They do not even need to look good, only credible to a machine.
  • Payment information saved in the browser becomes available to a tool that uses it without judgment.

The good news is that these risks are handled with simple rules and a bit of oversight. There is no need to ban AI, you just have to decide what it is allowed to do on its own.

An OKTO Solutions advisor presents a security plan and audit to a client

4. The context: AI-assisted fraud is growing

Guardio’s test did not land in a vacuum. In its fraud forecast for 2026, the firm Experian puts agentic AI at the top of its five main threats. In its view, the number of players entering this field makes fraud "inevitable and impossible to ignore".

A few numbers, offered as indications and worth checking against the official sources, give the measure of the problem. According to FTC data cited by Experian, consumers reported losing about 16 billion US dollars to fraud in 2025, a record, after 12.5 billion in 2024. Also according to Experian, close to 60 per cent of companies saw their fraud-related losses rise between 2024 and 2025.

Experian also names other trends for 2026: AI-generated fake job candidates capable of getting through a real interview, cloning of legitimate sites that reappear after every takedown, and chatbots convincing enough to run romance scams with no human involvement. The common thread is simple: the tools that were already helping fraudsters are getting faster and cheaper.

A hacking incident targeting the client of a small business

5. How to protect yourself starting today

You do not have to wait for the next incident to act. The measures below are concrete and can be applied right away, whether you are an individual or a company.

  • Remove your payment information from the autofill the agent can reach. If there is no saved card, it cannot pay on its own.
  • Turn on a mandatory human confirmation before any purchase, any sign in and any download.
  • For whatever the AI is allowed to pay for, use a virtual card with a low limit rather than the company’s main card.
  • Do not hand the watching of your inbox to an agent: that is the direct door to phishing.
  • Keep tasks that involve money, identity and health manual. Banking, taxes and medical records are done with your own hands on the keyboard.
  • Check the agent’s activity log from time to time to spot anything abnormal.

If you are not sure how to proceed, it is better to ask beforehand than afterwards. You can reach us at OKTO Solutions to review the AI tools used in your company and put limits where they belong.

Frequently asked questions

Is an AI browser dangerous to use?

Not in itself. It becomes risky when you let it pay or sign in without supervision. Used with human confirmation and no saved card, it remains a handy tool.

What exactly did the Scamlexity test prove?

That Perplexity’s Comet browser made a purchase on a fake site, entered banking credentials on a phishing page and downloaded a booby-trapped file, never once questioning whether they were legitimate. The AI optimizes for the task, not for suspicion.

How do I protect my company credit card?

Use a virtual card with a low limit for anything an AI agent can touch, take the cards out of autofill and require manual approval before every payment. That way, a mistake by the agent costs little.

Keeping AI in check without slowing your business down

Automation through AI saves time, but it does not replace judgment. The right instinct is not to ban these tools, it is to decide what they do alone and what stays under human control. To review how you are using them and set the right limits, take a look at our managed IT services or contact our team in Trois-Rivières. We help you get the benefit of AI without opening the door to scams.

Reading about AI is one thing. Connecting it to your own data is another: artificial intelligence in business, custom AI application development and our IT services in Quebec City.

A question on this subject, for your own company?

An article explains the principle. A twenty minute call tells you what it changes at your place, with your systems and your constraints.