The 'Just Because' Mindset is the Most Dangerous: Self-Defense in the Age of AI Scams
Introduction: I fell for it myself
I will be honest.
The other day, I 'fell for it'.
I have a habit of working with many tabs open while I work.
One night when I was a bit tired, I noticed a page open that said, 'Brain Training IQ Test: Takes about 5 minutes'.
The domain looked normal.
There was nothing visibly suspicious.
I answered the quiz and registered my email address.
I went to the payment screen for 199 yen to receive the results.
Thinking, 'It's safe if I use PayPal,' I made the payment, but at the same time, 1,990 yen was also deducted.
In the corner of the page, in text so small it was easy to miss, the explanation for automatic subscription registration and recurring charges was written.
'What kind of person falls for a scam?'
I, who have been working in IT for over 30 years, almost fell for it.
The answer is: 'A normal person who is tired and let their guard down for a moment.'
Chapter 1: The Structure of Gray-Zone Scams ── The '199 Yen' Trap
What makes this service clever is that it 'doesn't tell a lie'.
↓ These are similar tactics.
The subscription explanation is written. In the corner of the page, extremely small.
'Pay to see the results' is written. Although in English.
The mechanism for automatic registration is written. Inside the terms of service that no one reads.
I cannot definitively call it illegal.
However,it is intentionally designed to be difficult to see.
This type appears quite naturally from dynamic ads on social media or from tabs opened late at night when you are tired.
'199 yen is fine, I guess'
'Is this like a free fortune-telling?'
It skillfully guides you to make that judgment.
Multiple reports of similar damage have been made online.
There are cases where they respond to refund negotiations, but it is important to always check with PayPal or your credit card company to ensurethat automatic payments have not been left active.
The golden rule for advance preparation just in case:
Have a throwaway email address ready (do not use your main address carelessly)
Use PayPal or a pre-paid payment method for transactions (such as prepaid cards)
*1 The reason is described belowTake a screenshot the moment you feel something is off
Check automatic payment settings even for PayPal and credit card companies
*1 If you enter your credit card information directly, it takes time to notice if it has been misused, and the process for a chargeback (refund request) is cumbersome.
On the other hand, using PayPal means:
・You don't have to provide your card number directly to the merchant site
・You can request a refund in case of non-delivery or fraudulent transactions through the 'Purchase Protection' program
・In an emergency, PayPal can stop automatic payments
With prepaid options (Visa gift cards, V-Preca, etc.), you can control the maximum amount of potential damage because you cannot be charged more than the amount you loaded.
However, neither PayPal nor prepaid cards are a 'magic shield.'
The best practice is not to sign up for suspicious services in the first place.
Think of separating your payment methods as a habit to 'minimize potential damage.'
Chapter 2: Being Charged Without Knowing Even Though 'It's Clearly Written' — The Money Pitfalls of AI Tools
There is another issue where people are charged surprising amounts of money even though it's not a scam.
I will explain this using AI tools, specifically Claude, as an example.
Claude's Pro subscription (monthly) and charges for automated or programmatic usage are separate mechanisms.
Usage through the claude.ai chat interface is covered by the Pro subscription.
However, when you run Claude Code as a script or automation tool, or use the Agent SDK, it is billed separately (this will be even more clearly separated starting June 15, 2026).
A common pitfall is the case where you 'forgot to stop it even though you stopped using it.'
You left an API key created for testing purposes active
Someone on the team thought it was 'no longer in use,' but it was still running on another member's settings
Something running automatically in the background kept incurring charges
Even if the person thinks they are 'no longer using it,' charges will not stop as long as the API key remains valid.
You set it up on a whim, thinking, 'Yay, now I can use AI too!', and then forget about it.
Now that there are more of these 'casual engineers' lately,always invalidate API keys when you are done using themis the most important habit to prevent unexpected charges.
■ Things to do as countermeasures:
Immediately invalidate API keys when finished(You can delete them from the Anthropic management console)
If using it as a team, periodically audit who holds which key
Set a usage limit (Budget)(You can set it to stop once it exceeds a certain amount)
Since billing structures change frequently, make it a habit to check the official page regularly
Fundamentally, systems and tools have a 'lifecycle'.
Verify operation in a test environment → Deploy to production → Disable/delete when finished (disable test environments when not needed for production).
This procedure, which is 'obvious' to experienced engineers, is not known to many people today.
It is wonderful that AI tools have become something 'anyone can use.'
However, it also means that
the 'etiquette of starting'
and
the 'etiquette of ending'
are being put into production use without being known in the current environment.
Don't just stop at 'It worked!', learn how to 'stop' and 'clean up' as a set.
That is true literacy for safely mastering AI tools.
Chapter 3: AI Has Become a Fraudster's Partner — Inside an Investment Scam LINE Group
Last year, I happened to observe an investment scam LINE group from the inside.
Simply put, I was curious about the term 'investment' with AI, and wondered how they were doing it. Since my entry point was different from the start, I remained unharmed...
A 'teacher' holds regular lectures.
They talk about market analysis and
speak passionately on the theme of 'thinking about your family's future.'
There are dozens of members in the group.
'My life has changed thanks to the profits'
'I deposited money for investment'
they say, getting excited while posting screenshots as proof.

Looking back, the bank account screens, the securities company purchase screens, and the results screens were all the same. I remember feeling uneasy, wondering, 'Do dozens of people really use the same bank and the same securities company?'
It is believed that many of them were shill accounts highly likely to have been generated by AI.
Just by watching, you can't tell who is a shill and who is real.
One day, suddenly, the majority left all at once.
It was only because of that unnaturalness that the structure became visible.
An acquaintance's relative lost 20 million yen in this type of scam.
Not only was my entry point different, but I didn't have the funds to invest millions, so I wasn't a victim. It was a day I thought, 'Maybe not having money is a blessing.'
But since there was an article previously stating that many people who work in IT also fell victim to this, it is difficult to discern, isn't it?
Chapter 4: The Common 'Entrance' — Why Even Smart People Get Tricked
There is a structure common to all three stories.
'Just because'
'While physically and mentally exhausted'
'With a moment of carelessness'
the moment you operate, everything comes in.
The human brain has a characteristic where the quality of judgment drops when tired.
According to research by psychologist Daniel Kahneman, human thinking has
'a fast and intuitive mode (System 1)'
and
'a slow and logical mode (System 2)'
.
When you are tired, your brain tries to make decisions using only System 1 to save energy.
'It's only 199 yen, so it should be fine.'
'The domain looks normal, so it must be safe.'
These judgments are exactly the result of System 1 at work.
Furthermore, the phenomenon of 'Decision Fatigue' also comes into play.
Research shows that the quality of decision-making drops significantly after you have made many decisions throughout the day.
The evening, after working with many tabs open, is when this state is at its most severe.
And then there is the 'normalcy bias' at work.
'It won't happen to me.'
'It looks like a normal site, so it must be safe.'
This is a psychological tendency to interpret things in a way that is convenient for us.
Scammers intentionally target the moments when these three factors overlap.
Tired evenings, after making many decisions, and the illusion of 'looking normal'.
These are not coincidences; they are designed.
That is why the rule of
'Do not perform transactions involving money when you are tired'
is more effective than advanced knowledge.
Chapter 5: How to Protect Yourself — 'Habits' and 'Places' Over Knowledge
Many people think that countermeasures require 'advanced specialized knowledge,' but that is actually not the case.
What you need are 'the right habits' and 'knowing where to find reliable sources of information'.
Habits you should adopt:
1. Do not perform transactions involving money when you are tired (Have a rule of 'No decisions tonight')
2. If you feel something is suspicious, do not pay on the spot; make it a habit to check with AI or a search engine first.
For example, just asking an AI,
'Is this site official?'
'Are there any recent scam reports regarding this service?'
'What is the URL of the official website?'
can sometimes help you avoid dangerous sites. However, since AI is not always 100% accurate, you should also check the official website or official support information as a final step.
3. Do not link your primary credit card directly (Make it a habit to use PayPal or virtual cards)
Check if a new AI tool has 'multiple billing plans' first
◆ Official places to check when you feel something is 'suspicious':
IPA (Information-technology Promotion Agency) https://www.ipa.go.jp Information on the latest cyberattacks and scam techniques
National Consumer Affairs Center of Japan https://www.kokusen.go.jp Consultations and case studies of consumer damage
Consumer Affairs Agency https://www.caa.go.jp Information on violations of the Specified Commercial Transactions Act and malicious business practices
CCSI (Cybersecurity Media) https://ccsi.jp Security news available in Japanese
And finally.
Scam techniques change daily, and learning about them once is not enough.
Regularly acquiring the latest information and having a place to talk with people you trust is the most effective long-term security measure.
Continuously update your information and judgment skills through experts and reliable learning environments.
This is the 'art of protecting yourself' in the age of AI.
Conclusion
I understand why many people think, 'Security is a topic for experts.'
However, my own experience, my acquaintance's 20 million yen loss, and the surge in World Cup fraud domains are all happening in our 'everyday lives.'
Now that AI has become the infrastructure for fraud, we have entered an era where 'I didn't know' is no longer a defense.
Before learning complex things, I want you to start by simply knowing that 'these things are happening.'
That is why I wrote this article.
📌 Emergency alert regarding World Cup fraud is here (published simultaneously today)
📌 For those who want to learn security and AI literacy systematically Yumemi no Mori Academy offers courses that provide the 'knowledge to make decisions.' → [yumemitai.jp]
💬 Have you ever had a 'close call'? Please share your experiences of 'this kind of trick existed' or 'I almost got scammed' in the comments. The awareness of those who read them will lead to protecting someone else.
