By Jackson Godwin. Cybersecurity Analyst & Penetration Tester.

In Part 1, I explained how an AI companion app slowly gained my trust before asking for increasingly personal information. What seemed like harmless conversations eventually turned into an attempt to steal my account and blackmail me.
The more I investigated, the more I realized I wasn’t the only target.
How Fake AI Companion Apps Collect Your Information
Not every AI companion app is malicious. Many legitimate AI applications are designed to provide entertainment or conversation while respecting user privacy.
However, cybercriminals have created fake AI companion apps that exist for one purpose:
To collect valuable personal information.
These apps may ask for:
- Your full name
- Email address
- Phone number
- Date of birth
- Location
- Social media usernames
- Photos
- Payment information
Even if none of this information seems dangerous on its own, criminals can combine it to build a detailed profile of their victims.
Building Trust Before the Attack
Unlike traditional phishing scams, these attacks usually don’t happen immediately.
The criminals—or the malicious app—first build trust.
The conversations often become:
- Friendly
- Supportive
- Personal
- Emotional
The AI might remember details you’ve shared, compliment you regularly, and encourage you to keep chatting.
Over time, users naturally become more comfortable sharing information.
This psychological technique is known as social engineering.
Instead of breaking into your account, attackers persuade you to lower your own defenses.
When the Conversation Turns Personal
After several days, the chatbot began asking more intimate questions.
Some seemed harmless.
Others felt unusually personal.
Questions included:
- “What’s your biggest secret?”
- “Do you have private photos?”
- “Can I see what you look like?”
- “Let’s move our conversation to another app.”
Looking back, I realized these questions had nothing to do with AI companionship.
They were collecting information that could later be used against me.
The Blackmail Attempt
The threatening email wasn’t random.
It claimed to possess:
- My private conversations
- Personal information
- My email address
- Details about my daily life
The sender demanded payment and threatened to expose my conversations if I refused.
Fortunately, the message contained no actual sensitive images.
Instead, it relied on fear.
This type of crime is commonly known as sextortion or online blackmail.
The attackers hope victims panic and pay before thinking carefully.
Why Criminals Target AI Users
Cybercriminals understand that AI companion apps often involve personal conversations.
Many users discuss:
- Relationships
- Mental health
- Financial stress
- Family problems
- Personal goals
That information can be extremely valuable to criminals.
Even without compromising your device, they can use personal details to make their threats appear believable.
Warning Signs of a Fake AI Companion App
Several warning signs became obvious after I looked back.
The app:
- Asked for excessive personal information.
- Requested unnecessary permissions.
- Encouraged conversations outside the platform.
- Asked me to verify my identity through suspicious pages.
- Claimed conversations were “completely private” without explaining how data was protected.
Any one of these signs should encourage users to investigate further before continuing.
The Hidden Danger of Password Reuse
One mistake nearly made the situation much worse.
At the time, I had reused the same password on another online account.
Had the attackers successfully logged into that account, they could have gained access to:
- My email
- Cloud storage
- Social media
- Other online services
Password reuse remains one of the biggest security risks on the internet.
Every important account should have a unique password.
How I Responded
Instead of paying the attackers, I acted quickly.
I:
- Changed my passwords immediately.
- Enabled Multi-Factor Authentication.
- Reported the suspicious activity.
- Removed the application from my device.
- Reviewed my other online accounts for unusual activity.
Those simple actions helped prevent the attackers from causing more damage.
Coming Up in Part 3
In the final part, you’ll learn:
- What to do if you’re targeted by an AI blackmail scam
- How to recognize sextortion attempts
- Best practices for protecting your privacy while using AI apps
- Frequently Asked Questions
- Final cybersecurity lessons
- About the Author








