Scams

AI Vibe-Coding Tools Used to Build Scam Sites

By Nick · Updated
AI-built scam sitebrand impersonationvibe coding

Definition

An AI-built scam site is a brand-impersonation website assembled quickly using consumer-facing AI app-building ("vibe coding") tools rather than hand-coded, then distributed through paid social advertising to reach victims who already trust the impersonated brand.

How It Compares

Traditional hand-built scam site AI-built ("vibe-coded") scam site
Build cost/time Requires developer time to write frontend and backend A web frontend built via a consumer AI app-builder, paired with a cloud-hosted database backend — assembled in a fraction of the time
Reuse across campaigns Each new domain typically means rebuilding A single project can be duplicated to spin up a "next" scam site on a new domain and a new backend, reusing the same template
Distribution Often cold-messaging (e.g. WhatsApp) Paid social ads, deliberately trading a cash cost for the trust the ad platform itself carries with the audience

The Evidence

An investigation into a scam impersonating the Brazilian cosmetics giant Grupo Boticário found it was built with Lovable (a popular consumer AI app-building tool) and hosted on Supabase for its backend, then marketed through Facebook Ads. The Lovable origin was confirmed directly from the page's own metadata: its Meta preview tag pointed to an image hosted on Lovable's platform.

The same template was found deployed a second time, on a different subdomain impersonating the same brand — two live sites, two separate Supabase backends, but a single shared Meta Pixel ID across both. That pattern is consistent with the scammer using the app-builder's project-duplication feature to spin up each "next" scam site from the same base, rather than building each one from scratch.

The use of paid Facebook Ads (rather than free, direct outreach like WhatsApp messaging) is itself a notable choice — it costs money to acquire each lead this way. The working theory: the most effective scams exploit trust, and running ads on a widely-used platform lets the scam inherit some of that platform's own trust with its audience, producing a meaningfully higher success rate than cold-messaging strangers.

What To Do About It

  1. Treat a shopping or investment ad from an unfamiliar domain as unverified, regardless of how polished the site looks or how well-known the brand it claims to represent — AI app-builders make polish cheap to produce.
  2. Check that the checkout domain matches the real brand's known official domain before entering any payment details, even if you arrived via what looked like an official ad.
  3. Look for tells in page metadata where possible — a preview image or asset hosted on a generic app-builder's own domain (rather than the brand's) is a signal the site wasn't built or operated by the brand itself.
  4. Report the ad to the platform (Facebook/Meta) in addition to the impersonated brand — ad-platform reporting can get the distribution channel shut down, not just the site.

Caveats & Edge Cases

This is a single-source cluster (one LinkedIn post) rather than a fully developed topic, but it's conceptually important: it's the natural bridge between scam-awareness content and AI/agent-security content — scammers using AI tools, as opposed to AI agents being the attack surface. Once an ai-security track exists on this site, this page should cross-link to it in both directions.

Think you've spotted a scam?

Send it to us and we'll investigate it for free — the findings help build pages like this one.

← Back to Security Research