LIVE · cybersecurity feed
Live wire
ai

AI chat bots are sliding into League of Legends friend requests

Chat bots are sending friend requests in Riot immediately after ending your game. What are the scammers up to now?

zeroday.news ·

Players of Riot Games' *League of Legends* are reporting a surge of AI-powered bots sending friend requests through the game client immediately after matches, initiating flirtatious conversations, and ultimately attempting to funnel users to paid subscription platforms like OnlyFans. This activity aligns with a broader trend of AI-assisted social engineering migrating from dating apps to gaming platforms.

The scam typically begins with a friend request in the Riot client from an unfamiliar account moments after a game concludes. The initial message often includes generic flattery, such as "you played really well last game" or "I liked your playstyle," designed to appear as a genuine compliment. When asked about their identity, these accounts frequently claim to have been on the opposing team, despite name mismatches, and often present themselves as women seeking a duo partner. Profiles associated with these accounts are frequently blank, showing no match history, overview data, or a very low account level, consistent with disposable accounts created for outreach.

After a brief exchange, the bot directs the conversation off-platform, typically to Discord, citing an imminent departure. Once on Discord, the persona shifts into a more elaborate romance or flirtation script, involving hours of rapport-building and a steady stream of suggestive photos. These images have been found to be recycled across various unrelated websites and videos, indicating a large-scale operation rather than individual interaction. One user reported that when they paused replying, the bot sent new images of the model looking concerned, asking "Why are you not replying?", suggesting automated image generation tied to the script. Attempts to "jailbreak" the bot by prompting it to reveal its instructions were unsuccessful, as it maintained its persona, indicating built-in guardrails or a simpler, scripted flow with some AI-generated text.

The primary goal of this particular scam appears to be driving paid subscriptions to OnlyFans-style pages, often featuring a fabricated AI persona. While some underlying OnlyFans accounts may be legitimate, the conversations are highly likely managed by paid chat operators or AI systems using shared scripts and media libraries. However, more malicious variants have also been reported, where clicking a link from these bot accounts can lead to Discord account hijacking or credential harvesting.

The prevalence of these bot requests immediately after matches has led to speculation that operators are monitoring publicly available match data through third-party tracking sites and APIs to identify and target recent game participants. Riot's client architecture, which exposes local endpoints like the friends list API to third-party tools, may inadvertently facilitate this. Some affected players have found that enabling the client's "streamer mode," which hides recent match and online status information, appears to reduce the frequency of these bot requests, suggesting the targeting relies on visible activity signals.

Because the scam starts with a low-cost, disposable Riot account and quickly moves the conversation to Discord, the *League of Legends* client friend request serves as an initial filter. This allows operators to generate contacts cheaply, discard accounts easily after single use, and operate outside the reach of Riot's in-game reporting tools once the conversation shifts off-platform.

To protect themselves, players are advised to treat any unrecognized Riot client friend request as suspicious, especially those arriving immediately after a match. Verifying if the account was actually in their last game before accepting is recommended. Enabling privacy settings like streamer mode can limit visible activity data. Skepticism is warranted for anyone quickly attempting to move the conversation to Discord. Reverse image searches on any profile or personal photos sent early in a conversation can reveal recycled images, a strong indicator of a bot or catfishing operation. Players should also be wary of AI-typical conversation patterns, such as scripted responses, instant replies, grammatically flawless but emotionally generic language, or consistent evasion of voice or video calls. Finally, players should never send money, gift cards, cryptocurrency, or payment details to contacts met exclusively through in-game or Discord interactions.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
malwarehigh

Living off the coding agent: Two tales of tunnels and LaunchAgents

Agent-parented reverse tunnels and LaunchAgents can expose a local admin app to the internet. Endpoint still needs to treat that as high severity even when the activity looks like vibe-coded ops, not confirmed malware.

security

Meta ordered to pay $942 million over harm to children

A new court ruling not only fined Meta to the extent of $942 million but also ordered it to improve its age assurance tools.

breachcritical

Metabase SQLi zero-day exploited in customer data-theft attacks

A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. [...]

icshigh

Ex-NSA Chief Urges Disconnecting Water Controllers from Internet

Following suspected cyberattacks on water systems across at least 12 US states, likely perpetrated by Iran, a former NSA chief has strongly advised that industrial control systems like programmable logic controllers (PLCs) should not be connected to the internet. He emphasized the need for higher cybersecurity standards to defend these critical infrastructure components, noting that Iranian actors have a history and capability for such attacks.

breach

Unlimited Technology Systems breach impacts 3.8 million people

Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025. [...]

nation-state

Water utilities group partners with DEF CON offshoot for Water Watch Center

The National Rural Water Association and a group of cybersecurity experts have formed a program to help cash-strapped utilities face the increase in threats to their systems.