AI is being deployed to turn scammers’ time against them
Artificial intelligence is accelerating many forms of online fraud, but it is also becoming a tool for disrupting the people who run scams. A growing anti-cybercrime approach uses conversational AI to impersonate plausible targets, diverting scammers into phone calls and online exchanges that consume their time while collecting information about their operations.
Australian company Apate is among the organizations pursuing that strategy. For the past two years, it has been developing a system designed to redirect phone scammers to AI bots that can keep a conversation going without surrendering money or sensitive information. The premise is straightforward: every minute spent trying to persuade a synthetic victim is a minute a scammer is not using to reach a real person.
That premise matters because large-scale fraud operations can rely on automated dialing and high-volume messaging. A single convincing conversational exchange may not eliminate a scam network, but it can interfere with the efficiency that makes such networks difficult to combat. It can also produce intelligence that helps banks, telecommunications providers and investigators recognize active campaigns.
Creating convincing but non-vulnerable targets
Apate founder and chief executive Dali Kaafar describes the goal as building “perfect victims” from a scammer’s perspective: targets that appear persuadable enough to keep the interaction alive, but that never actually fall for the fraud. The bots are intended to give callers hope that a payment, account detail or other outcome may be within reach, allowing the system to hold their attention.
The company says its platform is used by banks and supported by telecommunications companies, and that it operates about 350,000 bots. According to Kaafar, those bots do more than answer phone calls. They can also enter scam chat groups and reply to text messages, extending the same delaying and intelligence-gathering approach across different channels.
The system uses varied personalities, language abilities and user profiles so that its responses do not become repetitive or easy to identify. Some bot personas might use WhatsApp while others do not. Some may answer a call and others may end it and suggest they will return later. That variation is central to the tactic: an anti-scam bot does not need to win an argument; it needs to remain credible long enough to drain attention from potential victims.
Intelligence is as important as delay
Time-wasting is only one part of the model. Apate says it has collected more than 250,000 pieces of real-time information about fraudsters, including scam URLs, money-mule accounts and bank details. Such information can be useful because fraud operations often depend on a changing web of phone numbers, payment routes, links and messaging accounts.
In theory, intelligence gathered during live interactions can make defensive systems more responsive. A bank may be able to identify a suspicious payment destination; a telecom provider may recognize a recurring number or pattern; a platform may be able to act on a scam link. The article does not detail how every item is verified or shared, so the scale and operational impact of the data should be treated as the company’s account. But it illustrates why defenders are interested in conversational systems that can both engage and observe.
This model differs from traditional public-awareness campaigns, which ask people to spot warning signs and refuse suspicious requests. Education remains important, but it places much of the burden on individual users. AI decoys seek to move some of that burden back toward the attackers by confronting them with targets that are available around the clock and can engage at scale.
A contest over realism
The usefulness of the approach depends on a difficult question: can bots remain believable to professional scammers? Fraudsters adapt quickly, and many have experience guiding anxious or distracted people through scripted interactions. If they can easily identify a bot, the deterrent effect diminishes and the operation may reveal information about its own methods.
That is why persona design, language variation and imperfect human-like behavior matter. An overly polished voice or a repeated response pattern can be as suspicious as an obvious refusal. Effective decoys must be convincing enough to encourage continued engagement, while still staying within firm safety boundaries: they cannot provide real credentials, transfer money or create new risks for legitimate people.
There are also broader questions about where and when deceptive defensive systems should be used. They may collect valuable intelligence, but organizations deploying them need controls for handling data, collaborating with authorities and avoiding unintended interactions with real users. The article highlights the technology’s potential but does not provide a complete account of its governance or independent effectiveness testing.
An emerging defensive use for generative AI
The rise of AI-enabled fraud has made it easy to frame the technology solely as an amplifier of cybercrime. Scam operations can use automation to widen their reach, and realistic text and voice can make manipulation harder to detect. The use of AI decoys offers a counterpoint: the same ability to conduct natural-seeming conversations can be redirected toward defense.
Rather than trying to stop every malicious call before it reaches anyone, these systems aim to alter the economics of scams after contact is made. If a fraudster cannot quickly distinguish a bot from a prospective victim, each false lead may lower the productivity of the operation. At sufficient scale, that could make high-volume scam campaigns more expensive and less rewarding.
It is too early to treat the tactic as a substitute for enforcement, stronger platform safeguards or consumer protection. But it demonstrates a shift in cyber defense from passive filtering toward active engagement. In that shift, AI is not only screening suspicious activity; it is attempting to occupy the people behind it.
The next test is measurable impact
The strongest case for conversational anti-scam systems will depend on evidence of results: fewer successful scams, shorter campaign lifetimes, more useful intelligence and a clear accounting of false positives or unintended consequences. Companies, banks and telecoms will also need to determine how these systems fit with existing reporting and fraud-response processes.
For now, Apate’s work shows how AI can be used to turn a scammer’s core resource—time—into a vulnerability. As cybercriminals increasingly automate outreach, defenders are beginning to automate the act of keeping them busy.
This article is based on reporting by Wired. Read the original article.
Originally published on wired.com








