← Back to library
SecurityOpen4 min read · 15-minute move

Fake ChatGPT and Claude Downloads Hit Small Businesses 33,000 Times This Year: Build the 15-Minute Safe Download List

Kaspersky counted more than 33,300 attacks on small businesses where malware was dressed up as a popular AI tool, almost five times last year's number. One bookmarked list of official links closes the door.


What happened. Kaspersky's 2026 small-business threat report counted more than 33,300 attacks in the first four months of the year where malware posed as a popular AI tool. That is almost five times the 2025 figure, and 39% more than attacks disguised as office and collaboration software. The most-copied names at the start of the year were ChatGPT (42%), Claude (24%), and DeepSeek (20%). Source: Securelist, Threat landscape for SMBs in 2026.

How the trap works. Someone on your team searches "ChatGPT desktop app" or "Claude download." The top result is an ad or a lookalike site. The installer looks right. Malware delivered this way usually goes after the passwords and logged-in sessions saved in the browser: bank, email, payroll, CRM.

Why it lands on small companies. Your team wants these tools, and most small companies have no approved place to get them. Attackers copy whatever is popular, so the lure changes every time a new AI product trends.

The 15-minute move.

  1. Write the safe list. One line per AI tool your company uses, with the official web address. For most teams that is chatgpt.com, claude.ai, gemini.google.com, and copilot.microsoft.com. Desktop and phone apps come only from the download link on those sites or from the Apple, Google, or Microsoft app store.
  2. Send it and pin it. Post the list in your team chat and have everyone bookmark the links. The rule in one sentence: "AI tools get installed from the safe list. If it is not on the list, ask first."
  3. Ban two sources. Search ads and links in emails or DMs. Nobody installs an AI tool from either one.
  4. Look back six months. Ask each person which AI apps and browser add-ons they installed recently and where they got them. Anything that came from outside the list gets uninstalled and the computer gets a full antivirus scan.
  5. If something looks wrong. From a different device, change every password that was saved in that browser, starting with email and banking. Turn on two-step login for both.

Paste this to write the list and the team note. Use your business AI workspace:

I run a small business. My team uses these AI tools: [LIST THE TOOLS]. Write a one-page Safe Download List: the official website for each tool, where the official desktop and mobile apps are downloaded from, and one line on how to spot a fake version of each. Tell me to verify every address myself before I send it. Then write a short, friendly message to my team explaining the rule: AI tools get installed from this list only, never from a search ad or an emailed link, and ask first if a tool is not listed. Plain language. Under 150 words for the message.

Human checkpoint. Open every address on the list yourself before you send it. AI can get a web address wrong, and this is the one document where that matters.

What it's worth. A stolen browser session can hand over your bank and email in one afternoon. The list costs 15 minutes and works for every AI tool that trends next.