Scam-Baiting Chatbots: What's Actually Live in 2026
Free: How to Keep Yourself Safe From Scammers
9 chapters. Reporting checklist. 30-second protection checklist. Read on the site.
Scam-Baiting Chatbots: What's Actually Live in 2026
Somewhere in the UK right now, a government-funded chatbot is on the phone with a scammer, playing the part of a confused pensioner who just can't quite find her card details. She's not real. She's never been real. And that's the point — while she stalls, the actual pensioners the scammer would otherwise be calling are having dinner, uninterrupted.
This isn't a pilot program anymore. It's written into national policy. The UK's Home Office named scam-baiting chatbots specifically in its Fraud Strategy 2026 to 2029, and Australia's largest bank has already deployed AI bots that are blocking thousands of scam calls a day. I've written before about whether this kind of AI-assisted scam baiting is actually ethical — this post is about the narrower question: what's actually running right now, who built it, and does it move the needle.
How a Scam-Baiting Chatbot Actually Works
The mechanics aren't complicated, which is part of why this scaled so fast. A chatbot is trained on real scam call and message scripts — hundreds of them, in some deployments — so it learns the shape of a scam conversation the way a language model learns the shape of any conversation. It's then given a persona: an age, an accent, an emotional state, a plausible amount of gullibility. When a scam call or message gets routed to it instead of a real person, the bot plays along. It asks the questions a real target would ask. It hesitates. It stalls for details. It sounds, to the scammer on the other end, exactly like someone slowly getting reeled in.
Every minute of that is a minute the scammer isn't spending on someone real. And because the bot is designed to keep the conversation going rather than end it, the interactions run long — sometimes tens of minutes — feeding back a transcript that can be mined for phone numbers, payment accounts, and scripts law enforcement and telecoms can use to block the next call before it connects.
Not sure if your message is real? Paste it into Cautellus and get a risk score before you reply.
Scan it free →Or: Get the Chrome extension to scan pages without leaving your browser.
What's Actually Deployed Right Now
The UK is doing it at the national policy level. The Home Office's Fraud Strategy 2026 to 2029 explicitly names AI-driven scam-baiting chatbots as a tool for gathering intelligence on criminal fraud operations, alongside faster interception of suspicious bank transfers. It's backed by a new £30 million Online Crime Centre, part of a £250 million commitment across the strategy's three-year run, built on three pillars the strategy calls Disrupt, Safeguard, and Respond. The scale of the problem behind that funding is blunt: the strategy cites roughly 1 in 14 UK adults and 1 in 4 UK businesses as fraud victims, costing the UK economy more than £14 billion a year.
Australia is doing it through a university spin-off, not a police department. Apate — named for the Greek goddess of deception — started as research out of Macquarie University's Cyber Security Hub, led by Professor Dali Kaafar, who trained the system on scripts pulled from more than 100 real scam calls. It grew into a company, Apate.ai, and Commonwealth Bank of Australia — the country's largest bank — has deployed its bots, giving them a spread of ages, accents, and personalities to sound convincingly human on the line. Kaafar has said the bots are being used by one telecom partner to intercept close to 10,000 scam calls a day, with individual conversations running as long as 54 minutes. He's estimated the bots divert around 600 hours of scammers' time per month, which — using Australia's own reported average scam loss figures — he translates to roughly $1.7 million in prevented losses monthly.
New Zealand is doing it through its official online-safety body, not a startup. Netsafe, which the New Zealand government has formally designated the Approved Agency under the country's Harmful Digital Communications Act, runs Re:Scam — a tool that's been around since 2017 in simpler form and got a real AI upgrade in 2024. Forward a scam email to Re:Scam's inbox and it builds a fake persona, then strings the scammer along in what's designed to be a never-ending conversation, burning their time on an inbox that will never actually pay. Netsafe has continued expanding its AI-assisted tools into 2026, including shifting parts of its scams helpline itself to AI-assisted triage so more people can get guidance quickly.
None of this is theoretical anymore, and none of it is one country's pet project — it's three different governments and government-adjacent bodies independently landing on the same idea within a few years of each other.
Where This Started: One Guy, a Scam Call, and 40 Minutes
Before any of this was policy, it was a hobby. Streamer Kitboga has spent years manually baiting phone scammers live on camera, using voice-changing software to play elderly, confused, or otherwise easy-sounding targets, keeping tech-support and gift-card scammers on the line for as long as he can stand it. Professor Kaafar's own account of how Apate started follows the same shape at a smaller scale — a scam call came in during a family lunch, he strung the caller along for 40 minutes while his kids laughed, and the idea for an AI version was born. The individual hobbyist version and the government-funded 2026 version are running the exact same play. What changed is that a bot can do it thousands of times simultaneously, without ever getting tired or slipping out of character.
Does It Actually Work?
The clearest wins are on volume and cost. A single AI bot can run dozens of simultaneous scam conversations, something no human scam-baiter could match, and it never has an off day. The Apate numbers — thousands of calls a day, hundreds of scammer-hours diverted monthly — are a real, measurable dent in one telecom's scam call volume, not a proof of concept sitting in a lab.
What it doesn't do is shut down the operations behind the calls. A blocked or wasted call is a loss of time and a bit of intelligence, not an arrest. And there's a genuinely uncomfortable wrinkle worth knowing: INTERPOL reported in 2025 that trafficking victims from 66 countries have been forced into scam centers under threat of violence, mostly across Southeast Asia but increasingly in West Africa and Central America too. Not everyone dialing a scam script is a trafficking victim, but a meaningful share are. An AI bot wasting a scammer's time doesn't touch the organization running the operation — it just makes one shift less productive for whoever's stuck making the calls. I go deeper on that tension, and the broader ethics of fighting deception with deception, in the ethics piece linked above rather than repeating it here.
What This Means for You
None of this replaces your own judgment, and it isn't supposed to. These systems mostly operate where a telecom, bank, or dedicated agency inbox can see the whole interaction end to end — a scam call routed through a partnered carrier, or an email forwarded to a service built for exactly that. A text that lands straight on your phone, a DM in your Instagram inbox, or a message on a dating app never touches any of this infrastructure. It's a background layer, not a replacement for checking a suspicious AI voice call yourself, verifying before you send money, or running something through Cautellus's scanner when it feels off. For the fuller landscape of where AI shows up on both sides of this fight — voice clones, chatbot detection, generated images — see our AI scams hub, and for how the defensive side of AI scam detection works more broadly, this breakdown covers what platforms like Meta and tools like ChatGPT and Claude actually catch.
If you want to try a lightweight version yourself, forwarding a scam email to a tool like Netsafe's Re:Scam is low-risk — you're not exposing anything, and the bot does the work. Actually engaging a live scam call or message as yourself is a different calculation entirely, and one worth thinking through before you try it.
Got something like this in your inbox? Drop it into the scanner — it takes 5 seconds and could save you thousands.
Check it now →Already been scammed? See where and how to report it.
FAQs
Is the government really building chatbots to fight scammers?
Yes, at least in the UK. The Home Office's Fraud Strategy 2026 to 2029 names scam-baiting chatbots specifically as a tool law enforcement will deploy to gather intelligence on criminal operations, backed by a new £30 million Online Crime Centre. Australia's version runs through a university-spun-off company working with the country's largest bank rather than a police agency directly, and New Zealand's runs through its government-designated online safety body.
How does a scam-baiting chatbot actually work?
It plays the victim. The bot is trained on real scam scripts, picks a persona (an age, an accent, a personality), and answers the way a genuinely confused, mildly interested person would — asking questions, stalling, going along with the pitch. Every minute the scammer spends talking to a bot is a minute they're not spending on an actual person, and the conversation itself becomes data on how that scam operation runs.
Does scam-baiting actually stop scams, or just waste time?
Both, but time-wasting is the bigger lever. Apate.ai's founder has reported bots diverting roughly 600 hours of scammer time per month for one telecom partner, translated into an estimated $1.7 million in prevented losses using Australia's own average-loss figures. It doesn't shut down a scam operation — it makes running one less profitable per hour.
Can I run my own scam-baiting bot at home?
You can forward a suspicious email to a tool like Netsafe's Re:Scam and let it handle the reply for you, which is low-risk. Actually engaging a live scam call or chat yourself is a different story — you're exposing your own number and information to a criminal, and there's no guarantee they don't just move on to someone else's grandmother in the meantime. The ethics and risk of that are covered in full in our piece on whether AI-assisted scam baiting is actually a good idea.
Does a scam-baiting bot mean I don't have to be careful anymore?
No. These systems intercept a fraction of scam volume, mostly on channels a telecom or agency can see end to end, like phone networks or a dedicated inbox. A text that lands directly on your phone or a DM in your Instagram inbox never touches any of this infrastructure. Treat it as one more layer working in the background, not a reason to skip your own checks.
Scammers spent years automating their side of this. Watching governments finally automate the other side is, if nothing else, deeply satisfying — right up until you remember the fight isn't over, it's just gotten a lot weirder.
Sources: UK Home Office — Fraud Strategy 2026 to 2029; Macquarie University — Pitting AI Against Phone Scams and The Lighthouse coverage of the Commonwealth Bank pilot; Thomson Reuters Institute — Conversational AI trained to bust scammers' business models; Netsafe NZ — Re:Scam and Approved Agency status; INTERPOL — globalization of scam centres, 2025; NPR — profile of scam-baiter Kitboga.
Think you've been targeted? Paste any text, link, email, or screenshot into Cautellus for instant AI analysis.
Scan something free →Want unlimited scans + the Chrome extension? See pricing.
Courtney
Founder, Cautellus · 20+ years in financial services
Two decades in financial compliance, digital security, and fraud prevention. Built Cautellus because the scam detection tools that exist were made for IT departments, not for real people getting weird texts.
Learn moreKeep reading
Support Our Mission
Cautellus is built to protect people from online fraud. Your contribution helps us keep building security tools and resources.