ToolNavs Find Useful AI Tools
Submit Sign in
Back to AI information
Hackers Are Poisoning AI Search: ChatGPT and Gemini Answers Stuffed With Scam Phone Numbers

Hackers Are Poisoning AI Search: ChatGPT and Gemini Answers Stuffed With Scam Phone Numbers

AI information • Admin • • 3 views

In September 2026, security researcher Ariel Simon and his team published a study called "Dark Sourcery" on Medium: hackers are using "generative engine optimization" (GEO) techniques to poison the answers of ChatGPT, Gemini, and Google AI Overview at scale, stuffing scam phone numbers, phishing email addresses, and fake login pages into the "authoritative answers" AI gives out.

The scale: 374 companies

The research team built a detection system that continuously analyzes the three AI platforms' answers about Fortune 100 companies, banks, airlines, software firms, and more, scoring the sources the AI cites. The result: real poisoning attacks found in queries related to 374 companies, including well-known brands like Delta, Lufthansa, Bank of America, Chase, Airbnb, and TripAdvisor.

One caveat: large model answers are inherently unstable. The researchers acknowledge that when the same query is run repeatedly, the "poisoning" — the AI citing the fake number — doesn't reproduce every time. The better-crafted the poisoned content, the higher the success rate.

How the poisoning works: marketing tricks repurposed for fraud

GEO started as a marketing concept: study the patterns of which sources AI chooses to cite, then optimize content so AI cites your brand more often. Attackers have ported the whole methodology to fraud:

First, make content "AI-friendly": repeat the fake number, use question-and-answer layouts, add phrases like "24/7," "updated 2026," and "call now" so AI can grab and cite it more easily.

Second, dodge spam filters: render the same number in dozens of variants — spaces, dots, emoji, Unicode lookalikes, words between digits. Filters see mutually distinct text; after tokenization, the AI understands the same number.

Third, manufacture "authority" through volume: copy the same script across Instagram, Tumblr, LeetCode, YouTube video descriptions, Medium, and other user-generated-content platforms, then upload it to file areas of government and university websites (mostly PDFs), plus Google Sites, GitHub Pages, and WordPress. Mix real and fake numbers, pair useful advice with the scam, add AI-generated "official-looking" images and fake likes and comments — and the AI treats citing the fake number as the result of "cross-validation across multiple sources."

Fourth, strike when people are anxious: refunds, canceled flights, locked accounts, money transfers. Anxious people are least likely to double-check on the official site — they just pick up the phone and call.

Why takedowns can't keep up

The researchers found the campaigns are clearly automated: same template, same number, same phrasing — hundreds of posts per day, per platform, per company, thousands of new posts network-wide every day. By the time one gets removed, a thousand new ones are already out.

Worse is the "zombie content": even after the original post is deleted, snapshots on archiving sites like archive.org remain indexed by search engines, so the poison keeps working. As an example, the researchers note that attacker posts targeting American Airlines filled more than ten pages of Google results on LeetCode within 24 hours.

The most awkward part: neither vendor owns it

The research team contacted every named company through bug bounty and security channels; most had no idea of the scale. The responses from Google and OpenAI are more telling: Google ruled that "AI-generated misinformation" falls outside its vulnerability rewards program, while OpenAI closed the report as "not reproducible" — even though it included real attack cases.

Both vendors' logic is the same: what was manipulated is the AI's "answer content," not a vulnerability in their own systems, so it doesn't count as a vulnerability. But that exposes a defense vacuum: the attacks are real, users are genuinely being scammed, and no vendor considers it their responsibility.

For ordinary users, the takeaway is blunt: when you see a customer-service number in an AI answer — especially in money-transfer or account-security scenarios — verify it on the official website or inside the official app first. The researchers cite a survey finding that 92% of users never verify AI answers — and that is precisely the premise the entire attack chain rests on.

Recommended Tools

More