{"id":239,"date":"2026-06-13T03:12:32","date_gmt":"2026-06-13T03:12:32","guid":{"rendered":"https:\/\/localseobot.ai\/blog\/fake-shopping-sites-chatgpt-russell-bromley-dunelm\/"},"modified":"2026-07-19T07:21:31","modified_gmt":"2026-07-19T07:21:31","slug":"fake-shopping-sites-chatgpt-russell-bromley-dunelm","status":"publish","type":"post","link":"https:\/\/localseobot.ai\/blog\/fake-shopping-sites-chatgpt-russell-bromley-dunelm\/","title":{"rendered":"Fake Shopping Sites Are Slipping Into ChatGPT Results: The Russell &#038; Bromley and Dunelm Scam"},"content":{"rendered":"<p>Ask Silver has detected counterfeit storefronts for British retailers Russell &amp; Bromley and Dunelm appearing inside ChatGPT&#8217;s shopping results, using near-identical domain names, fake discounts up to 80%, and bank-transfer payments to steal money and card details from shoppers who trusted the assistant&#8217;s recommendation.<\/p>\n<p>The scam exploits a specific gap: Russell &amp; Bromley entered administration in January 2026 and was acquired by Next plc, which took down the standalone website, leaving AI models with no authoritative site to anchor on and clearing a path for lookalike domains to surface as legitimate answers.<\/p>\n<h2>What Ask Silver Found<\/h2>\n<p>Ask Silver identified cloned versions of Russell &amp; Bromley and Dunelm inside ChatGPT&#8217;s shopping answers. The fakes used near-identical domain constructs such as <em>therussellbromleyofficial<\/em> and <em>russellandbromleylondon<\/em>, and replicated the look and feel of legitimate e-commerce sites down to product pages and branding.<\/p>\n<p>Advertised price cuts reached up to 80%, a psychological trigger calibrated to push even cautious shoppers into a fast decision. Buyers who placed orders received nothing, and their payment details were compromised. The sites steered customers toward bank transfers rather than card payments, deliberately bypassing the fraud protections and chargeback rights built into mainstream card processors.<\/p>\n<h2>Why Did the Scam Work?<\/h2>\n<p>The fraud exploited a real-world gap. Russell &amp; Bromley entered administration in January 2026 and its brand and assets were acquired by Next plc, which folded the label into other channels and took down the standalone website. That left shoppers still searching for the brand but no official destination for an AI model to anchor on.<\/p>\n<p>Fraudsters stepped into the vacuum. With no canonical site to outrank in the model&#8217;s trust hierarchy, lookalike domains built to appear credible to web crawlers and language models had an unusually clear path into the results. The absence of an authoritative source is exactly the condition that makes a clone plausible.<\/p>\n<h2>How Were the AI Results Poisoned?<\/h2>\n<p>The underlying technique echoes data poisoning, a well-documented concern in machine learning security. A 2024 study by Nicholas Carlini and collaborators demonstrated that injecting even a tiny fraction of malicious samples into web-scale datasets can steer model outputs in dangerous directions. The fraud here is a practical analog: build pages optimized to look like the real thing to scrapers and models, get them indexed, and wait for the assistant to surface them as if they were legitimate.<\/p>\n<p>This is not knockoff SEO playing for a search ranking. It is a direct pipeline from a fake domain to a consumer&#8217;s payment, routed through an AI assistant that presents the link with the same confident tone it uses for genuine results. The assistant rarely shows a source-audit trail, so the user has little signal that one recommendation is real and another is a trap.<\/p>\n<blockquote>\n<p>This isn&#8217;t just knockoff SEO; it&#8217;s a direct pipeline from a fake domain to a consumer&#8217;s wallet, routed through an AI assistant that vouches for it by default.<\/p>\n<\/blockquote>\n<h2>How Have the Companies Responded?<\/h2>\n<p>The platform operator confirmed that the flagged sites were removed from its search index and pointed users to a reporting form for suspicious links. Next plc said it is actively working to take down fraudulent domains, and Dunelm urged customers to stick to its official app and website.<\/p>\n<p>Those steps are takedowns after the fact, not prevention. The root mechanism, AI systems ingesting untrusted web content and presenting it as authoritative, is not fixed by removing individual domains. AI safety researchers point to cryptographic trust signals, domain-verification layers, and tighter provenance checks as the structural fixes, but those capabilities are still early. As long as a short window of visibility is profitable, scammers are incentivized to keep submitting poisoned pages.<\/p>\n<h2>How Can Shoppers and Brands Protect Themselves?<\/h2>\n<p>For anyone who acts on AI-sourced links, the working rule is simple: never trust a link just because an assistant served it.<\/p>\n<ul>\n<li><strong>Open and inspect every link before you act on it.<\/strong> Check the domain for extra words, hyphens, or misspellings. <em>therussellbromleyofficial<\/em> is not <em>russellandbromley.com<\/em>.<\/li>\n<li><strong>Treat the red flags as disqualifying.<\/strong> Discounts around 80%, bank-transfer-only payment, missing returns or contact pages, and sloppy fine print are not coincidences. They are the pattern.<\/li>\n<li><strong>Cross-check against verified channels.<\/strong> Find the brand&#8217;s verified social profile or official app listing and confirm the link matches what is listed there.<\/li>\n<\/ul>\n<p>If you own a brand, the defensive move is to make your real presence loud and authoritative so clones have less room to impersonate you. Assert your official domains everywhere, keep verified profiles current, and periodically query AI assistants for your own brand name to see what they recommend. A clone could be sitting in those results right now, and you would rather find it before a customer does. Where you control links, a branded shortener with click monitoring lets you spot and reroute traffic if a fake starts spreading under your name.<\/p>\n<h2>What Does This Mean for AI Shopping?<\/h2>\n<p>AI shopping assistants are accelerating product discovery while inheriting the web&#8217;s oldest problem: untrustworthy information delivered with total confidence. The Russell &amp; Bromley and Dunelm clones show how a gap as ordinary as a brand losing its website can become an attack surface the moment an AI model has nothing authoritative to cite. Until provenance and verification are built into these systems, the safeguard is human: verify the link, distrust the too-good discount, and never let an assistant&#8217;s confident tone stand in for your own check.<\/p>\n<h2>FAQ<\/h2>\n<h3>What did Ask Silver find inside ChatGPT&#8217;s shopping results?<\/h3>\n<p>Ask Silver found cloned storefronts for Russell &amp; Bromley and Dunelm, using lookalike domains such as <em>therussellbromleyofficial<\/em> and <em>russellandbromleylondon<\/em>, with advertised discounts up to 80% and bank-transfer-only payment to steal funds and card details.<\/p>\n<h3>Why were the Russell &amp; Bromley clones able to appear in ChatGPT results?<\/h3>\n<p>Russell &amp; Bromley entered administration in January 2026 and was acquired by Next plc, which took down the standalone website. With no canonical site for the AI model to anchor on, lookalike domains had an unusually clear path into the shopping answers.<\/p>\n<h3>What is the scammer&#8217;s underlying technique?<\/h3>\n<p>The technique mirrors data poisoning documented in machine learning research, including a 2024 study by Nicholas Carlini and collaborators. Fraudsters build pages optimized to look authentic to scrapers and models, get them indexed, and wait for the assistant to surface them as legitimate recommendations.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"headline\":\"Fake Shopping Sites Are Slipping Into ChatGPT Results: The Russell & Bromley and Dunelm Scam\",\"description\":\"Ask Silver found counterfeit Russell & Bromley and Dunelm storefronts inside ChatGPT shopping results, using lookalike domains and 80% discounts to steal payments.\",\"datePublished\":\"2026-07-19T07:21:31.035Z\",\"publisher\":{\"@type\":\"Organization\",\"name\":\"LocalSEOBot\"}},{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What did Ask Silver find inside ChatGPT's shopping results?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Ask Silver found cloned storefronts for Russell & Bromley and Dunelm, using lookalike domains such as therussellbromleyofficial and russellandbromleylondon, with advertised discounts up to 80% and bank-transfer-only payment to steal funds and card details.\"}},{\"@type\":\"Question\",\"name\":\"Why were the Russell & Bromley clones able to appear in ChatGPT results?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Russell & Bromley entered administration in January 2026 and was acquired by Next plc, which took down the standalone website. With no canonical site for the AI model to anchor on, lookalike domains had an unusually clear path into the shopping answers.\"}},{\"@type\":\"Question\",\"name\":\"What is the scammer's underlying technique?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"The technique mirrors data poisoning documented in machine learning research, including a 2024 study by Nicholas Carlini and collaborators. Fraudsters build pages optimized to look authentic to scrapers and models, get them indexed, and wait for the assistant to surface them as legitimate recommendations.\"}}]}]}<\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ask Silver found counterfeit Russell &#038; Bromley and Dunelm storefronts inside ChatGPT shopping results, using lookalike domains and 80% discounts to steal payments.<\/p>\n","protected":false},"author":0,"featured_media":269,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-239","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-news"],"_links":{"self":[{"href":"https:\/\/localseobot.ai\/blog\/wp-json\/wp\/v2\/posts\/239","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/localseobot.ai\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/localseobot.ai\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/localseobot.ai\/blog\/wp-json\/wp\/v2\/comments?post=239"}],"version-history":[{"count":1,"href":"https:\/\/localseobot.ai\/blog\/wp-json\/wp\/v2\/posts\/239\/revisions"}],"predecessor-version":[{"id":577,"href":"https:\/\/localseobot.ai\/blog\/wp-json\/wp\/v2\/posts\/239\/revisions\/577"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/localseobot.ai\/blog\/wp-json\/wp\/v2\/media\/269"}],"wp:attachment":[{"href":"https:\/\/localseobot.ai\/blog\/wp-json\/wp\/v2\/media?parent=239"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/localseobot.ai\/blog\/wp-json\/wp\/v2\/categories?post=239"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/localseobot.ai\/blog\/wp-json\/wp\/v2\/tags?post=239"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}