VMTech
Discuss a project →

AI search poisoning campaign inserts phishing traps into answers

AI search poisoning campaign inserts phishing traps into answers

A large-scale disinformation campaign is poisoning answers from ChatGPT, Gemini and Google AI Overviews with fraudulent support phone numbers, email addresses and login pages for major companies. Vigilance Security researcher Ariel Simon said the campaign causes AI systems to present phishing traps as trusted answers when users seek routine information.

The reported targets include Delta, Lufthansa, Qatar Airways, Chase, Bank of America, Airbnb and TripAdvisor. Rather than relying on a single compromised service, the activity uses a broad publishing strategy intended to make false material visible to AI-powered search and answer systems.

False support details enter AI answers

Simon said attackers are flooding the web with carefully optimized posts, PDFs, reviews and fake support pages. The apparent objective is to influence generated answers so that a user looking for a company contact route is directed to attacker-controlled phone numbers, email addresses or credential-harvesting pages.

The campaign illustrates a risk beyond conventional search-result manipulation. An AI-generated response can package a fraudulent contact detail in a concise answer that appears authoritative, even when the underlying information has been planted across unrelated public sites.

Distribution spans common publishing platforms

The false content has been uploaded to social media and websites that permit file uploads, as well as web-hosting platforms including Google Sites, GitHub Pages, WordPress and Blogger. The campaign also uses fundraising, job-search and event platforms such as Posh.vip, onecause.com, bebee.com and raiselysite.com.

Reviews on Yelp and Apple Maps are among the other channels cited in the research. This distribution model gives attackers multiple places to repeat and optimize the same deceptive information, rather than depending on one domain remaining online.

Trust paths remain the point of failure

The wider ThreatsDay roundup also documented attacks that exploit familiar workflows: a fake Claude Max giveaway used a browser-in-the-browser Google sign-in window, while fraudulent OpenAI subscription invoices directed recipients to fake login pages. In each case, the attacker benefits when a routine-looking interaction is accepted without independent verification.

For businesses, the practical implication is to treat AI-generated support contacts and login destinations as leads to verify, not as final proof. Teams should use established official channels for account support, make verification procedures clear to staff, and reinforce that a plausible answer can still route a user into a phishing trap.

#cybersecurity#phishing#aisecurity#searchsecurity
Open analytics
On the site 2 views
min read 3 24.09.2026
Instagram

AI search poisoning campaign inserts phishing traps into answers

Open the post on Instagram ↗