Tech

When Trust Is the Product: Scammers and Silicon Valley Are Playing the Same Game

Published

on

Two stories dominating tech circles this week have almost nothing to do with each other on the surface. One is about criminals mailing fake credit cards to unsuspecting Europeans. The other is about a cuddly, Labubu-like mascot Meta built to represent its AI assistant. But look closer, and both are studies in the same discipline: engineering trust so people stop asking questions.

Start with the scammers. In Portugal, France, and Germany, fraud rings have been sending out convincing replacement credit cards through the mail, complete with real customer names printed on the plastic, paired with letters warning that a current card is about to expire. Scan the included QR code to “activate” the new card, and victims land on a fake banking site designed to harvest their real credentials. Georg Hauer, an advisor for digital banks, says the physical card itself is the con’s masterstroke: “The card is almost like a token that creates the trust that is needed in order to fall for the actual trick.” Thanks to cheap AI-assisted design tools, criminals can now mock up a passable replica of a real bank card for a fraction of what it used to cost — and Hauer expects the scheme to keep spreading to new countries precisely because the conversion rate per victim is so high.

Meanwhile, in the US, federal prosecutors in Alabama last week indicted two Romanian nationals for allegedly running old-fashioned skimming operations aimed squarely at SNAP food assistance recipients, whose Electronic Benefit Transfer cards still rely on magnetic stripes rather than chips. The FBI says EBT skimming has been rising steadily since 2021, and US Attorney Phillip W. Williams Jr. called it “a silent insidious theft that occurs by merely swiping a credit card at a point of sale.” Skimming fraud broadly costs Americans more than $1 billion a year, according to prosecutors. Gary Warner of the cybersecurity firm DarkTower notes that even chip-enabled cards remain vulnerable at non-bank ATMs and smaller merchants, where skimmers are sometimes rigged to force a chip read to fail, pushing the transaction back to the far less secure stripe. Mastercard has said it won’t fully retire the magnetic stripe until 2033 — a reminder that “old” technology has a long tail, and so does the fraud built around it.

Now consider Meta’s Muse. The AI agent’s mascot, a fuzzy, wide-eyed character named Jolly, dresses up in outfits, appears in Instagram ads doing bicep curls, and will soon get its own Tamagotchi-style physical gadget for the holidays. Muse is explicitly restricted to adults 18 and over, yet nearly everyone who has looked at Jolly has had the same reaction: it looks like a toy built for toddlers. “Oh my God, it looks like a Teletubby,” says Josh Golin of the children’s advocacy nonprofit Fairplay, who argues the rounded, soft shapes are textbook design language for appealing to preschoolers, adult-only branding notwithstanding.

Advertisement

Meta insists the cuteness is just good product design, not a dodge around its own age restrictions — the company says it checks birthdates and screens for underage users. But researchers who study AI companions see something more calculated at work. Julian De Freitas, a Harvard marketing professor who studies AI companions, points out that Meta is fighting an uphill battle for goodwill after settling social-media-addiction claims for as much as $16.7 billion this year. “These types of cute factors can make the product seem warm and less threatening,” he says. Jathan Sadowski, of Monash University’s Emerging Technologies Research Lab, is blunter: he argues design features like cuteness and frictionless interaction are “sly ways to make people drop their guard, stop asking critical questions, and slip into being passive users” — masking the fact that, by default, Meta trains its models on your conversations with Muse unless you opt out.

It’s a strange symmetry. The scam letter and the plush AI mascot are both, in their own registers, exercises in disarming skepticism. One borrows the visual authority of a bank to get a QR code scanned; the other borrows the visual language of a children’s toy to make an always-on surveillance product feel like a friend in your pocket. Neither depends on breaking any new technological ground — the letter scam runs on a laser printer and a mail slot, and Muse runs, in Meta’s own words, on making an AI agent feel less like “a corporate logo or entity.” The technology is almost beside the point. The real innovation, in both cases, is psychological.

Elsewhere in tech this week, the news was more mundane, if still telling about how central network infrastructure and browser habits have become to daily life. Wired’s testing lineup of mesh Wi-Fi systems for 2026 comes with an unusual asterisk: the FCC’s foreign-made router ban, announced in March, could bar companies without a “Conditional Approval” from selling new mesh systems in the US at all, though existing stock can still be sold and updated through 2029. Netgear, Eero, and Asus have already secured approval, a quiet reminder that geopolitics now shapes what shows up in your living room just as much as engineering does. And for anyone whose real enemy is not scammers or chatbots but their own 40 open browser tabs, a free extension called Tuck has emerged as a small, welcome fix — letting you “snooze” tabs the way Gmail lets you snooze email, no account or data collection required.

Taken together, the week’s tech stories tell a consistent story: whether the goal is stealing your savings or simply your attention, the winning strategy in 2026 rarely involves dazzling new technology. It involves understanding exactly how much trust people are willing to extend to something that looks familiar, official, or adorable — and building products, real or fraudulent, to exploit precisely that.

Advertisement

 

You must be logged in to post a comment Login

Leave a Reply

Cancel reply

Trending

Exit mobile version