top of page

ChatGPT Search Poisoning Hit 374 Brands, Exposing a Trust Gap in AI Answers

7 days ago
12 min read

ChatGPT search poisoning reportedly affected at least 374 companies after attackers planted fraudulent contact details across sources retrieved by ChatGPT, Gemini, and Google AI Overview. Vigilance Security says the targets included Delta, Lufthansa, Bank of America, Airbnb, Chase, Qatar Airways, and Tripadvisor.

The operation, which Vigilance calls “Dark Sourcery,” turns an AI assistant’s helpful answer into the delivery mechanism for a scam. A user asks for an airline reservation number or bank support page. The system can then return a fraudulent phone number, phishing link, or fake login page as trusted guidance.

That distinction matters. Conventional phishing asks the victim to trust an unsolicited message. This campaign reportedly waits for users to approach ChatGPT or Google with a legitimate question, then exploits the authority they assign to the answer.

The findings expand earlier evidence that fraudulent support information can penetrate AI-generated search results. They also create a verification problem. Vigilance published examples and described tens of thousands of malicious pages, but the full dataset and testing methodology were not publicly available for independent examination.

The immediate contest is therefore not hackers against individual brands. It is automated content pollution against the retrieval and verification systems behind AI answers. The winner determines whether an assistant provides a company’s real support channel or routes a customer toward a criminal call center.

The 374-brand campaign moved scams inside the answer

The campaign’s central innovation is placing fraudulent information inside an AI-generated response, where users can mistake synthesis for verification.

Vigilance Security disclosed its findings on September 23, 2026. According to the company’s campaign research, attackers distributed carefully formatted posts, PDFs, reviews, and support pages across the public web.

Those documents associated well-known company names with phone numbers, email addresses, login pages, or software instructions controlled by scammers. Search and retrieval systems could subsequently collect those associations when answering customer-service questions.

Vigilance Vice President of Research Ariel Simon said the researchers found tens of thousands of malicious pages. The team connected the activity to at least 374 targeted businesses spanning airlines, banks, travel companies, technology vendors, and other large organizations.

That figure should be treated as a research finding, not a complete census. Vigilance has not publicly released a machine-readable list of every page, query, brand, and model response used to produce it. Independent researchers therefore cannot yet reproduce the entire count.

The evidence described in follow-up reporting is still concerning. Vigilance researchers reportedly called several numbers returned through the poisoned information. The people answering offered to change flights or unlock bank accounts before requesting credit card details.

Researchers also observed complaints from people who said fraudulent numbers in chatbot answers had led them to disclose payment information. Those reports support the campaign’s basic threat model, although they do not establish how many victims lost money.

The affected brands were not accused of supplying the false information. Their names functioned as bait because customers already search for them during urgent or financially sensitive situations.

An airline customer dealing with a canceled flight wants immediate help. A bank customer facing a locked account wants reassurance. Both situations reduce the time a person spends examining a phone number or domain.

Traditional search poisoning exploits the ranking system that orders links. AI answer poisoning goes one step further by extracting the attacker’s claim and presenting it in a newly generated response.

That can remove familiar warning signs. Users may never see a suspicious page design, an awkward headline, or a strange search result. They see the assistant’s interface, followed by what appears to be a direct answer.

The reported campaign consequently creates two victims. Consumers face fraud, while the impersonated company inherits complaints, support costs, reputational damage, and incident-response work for infrastructure it never controlled.

This is what changed. Fraudulent contact information has circulated online for years, but AI assistants can now package it as personalized guidance without requiring the victim to visit the attacker’s original page.

How ChatGPT search poisoning turns GEO into a fraud channel

ChatGPT search poisoning abuses source selection, not necessarily the underlying model or a direct prompt-injection vulnerability.

Generative engine optimization, or GEO, means structuring online material so an AI answer system is more likely to retrieve and reuse it. Answer engine optimization, or AEO, describes a closely related practice focused on concise answers, entity associations, and machine-readable phrasing.

Legitimate publishers use these techniques to make accurate information easier for answer engines to understand. Attackers can apply the same logic to fake support data.

A malicious page might repeat a brand name beside a fraudulent number. It might use question-and-answer formatting that closely matches a likely customer query. It could also label the number as “official,” “toll-free,” or intended for urgent reservations.

The attacker benefits when that material appears across several locations. Repetition can make a false association look corroborated, even when every occurrence belongs to the same campaign.

Earlier research from Aurascape documented this mechanism through airline support queries. Its poisoning investigation found fraudulent numbers distributed through compromised websites, uploaded PDFs, YouTube descriptions, Yelp reviews, and cloud-hosted files.

Some poisoned content appeared on government, university, and established publishing domains. Those domains can carry stronger trust and visibility signals than a newly registered scam website.

The attacker does not always need to compromise the entire site. An exposed upload feature, abandoned page, comment field, review system, or poorly controlled document repository can provide an indexable surface.

Freshness also helps. Support queries change frequently, particularly around travel disruptions, refund policies, software updates, and account-recovery procedures. Recently published text can appear relevant even when its origin is unrelated to the company being impersonated.

This explains why Gemini AI poisoning and similar attacks are difficult to reduce to one technical flaw. An answer can be wrong because the retriever selected poisoned sources, because the model merged claims incorrectly, or because safeguards failed to recognize risky contact details.

The Dark Sourcery campaign reportedly differs from classic prompt injection. In a prompt-injection attack, malicious content gives the AI instructions intended to override its normal behavior.

Here, the false content can look declarative rather than instructional. It tells the system that a particular phone number belongs to a bank or airline. The assistant can repeat that statement while behaving exactly as designed.

OpenAI acknowledges that retrieved content requires caution. Its guidance on generated links says third parties can lie to ChatGPT or insert malicious instructions, and advises users to inspect destinations before trusting them.

That warning addresses part of the risk, but phone numbers create a harder interface problem. A number does not expose its ownership through a recognizable domain. Once the user begins a call, a convincing operator can supply the missing layer of social engineering.

AI synthesis can also hide the disagreement among sources. A traditional results page lets users compare an official company domain against forums, PDFs, and unfamiliar sites. A generated paragraph can compress those sources into one confident recommendation.

Citation links do not automatically solve that problem. Ten citations may look stronger than one, yet all ten can repeat the same planted information. Effective verification must measure source independence, ownership, and relevance rather than citation quantity alone.

Google AI Overview scams expose the difference between retrieval and verification

An AI system can retrieve a plausible answer and cite supporting pages without verifying that the contact detail belongs to the named organization.

Google AI Overview scams illustrate that gap because the generated summary occupies one of the most prominent positions in Search. Users can treat that placement as an endorsement, especially when the response uses direct language.

Previous investigations found fake airline support numbers appearing in AI Overviews. Reports also described consumers receiving fraudulent contact information when searching for financial and travel services.

Google told WIRED that its anti-spam protections are highly effective and that it shows official customer-support numbers where possible. The company also said it was strengthening scam protections and encouraged users to verify phone numbers through additional searches, according to coverage of AI Overview scams.

That response identifies the central tension. Google presents AI Overviews as a faster route to useful information, yet the recommended defense asks users to perform the comparison that the summary was supposed to simplify.

Google has reported broader progress against search abuse. Its 2025 scam protection report said new systems detected 20 times more scam pages and reduced scams impersonating official sites by more than 70 percent during 2024.

Those figures cover Google Search protections broadly. They do not provide an independent measurement of the Dark Sourcery campaign, nor do they show the error rate for support numbers generated by AI Overviews.

OpenAI describes a similar selection model for ChatGPT search. Automated systems consider intent, relevance, and recency, while responses can include inline citations and additional sources.

Relevance, however, is not identity verification. A page can be highly relevant to the words “Bank of America support number” while containing information that Bank of America never published.

The same weakness appears across products because the web lacks a universal, authenticated registry for every company phone number, refund portal, software package, and account-recovery page. Official websites provide strong evidence, but organizations often distribute support across regional domains, apps, contractors, and partner systems.

Attackers exploit the ambiguity. They focus on queries where users expect multiple channels and rapid changes. Airlines, online travel services, banks, and software companies fit that pattern.

The platforms also face a precision problem. Blocking every unfamiliar number would make assistants less useful. Allowing a number because several indexed pages repeat it can reward attackers who manufacture consensus.

This tradeoff separates AI search safety from ordinary content moderation. The system must evaluate not only whether text is abusive, but whether a specific real-world relationship is authentic.

A phone number may be harmless in one context and fraudulent in another. A legitimate call center can support several brands through a disclosed outsourcing agreement. A scam operation can imitate that pattern by associating one number with many unrelated companies.

Google, OpenAI, and other answer providers therefore need entity-aware checks. When a response supplies a high-risk contact detail, the system should compare it with first-party records rather than infer legitimacy from general web repetition.

The verification burden should also change with the requested action. A mistaken restaurant recommendation is inconvenient. A false bank login page or account-recovery number can lead directly to financial loss.

The 374-company figure is serious, but important questions remain

The available evidence establishes a credible attack pattern, while leaving the campaign’s scale, success rate, and product-by-product impact unresolved.

Vigilance says it detected at least 374 affected companies and tens of thousands of malicious pages. Follow-up security reporting names prominent targets and describes test calls to fraudulent operators.

However, the public research does not provide a complete denominator. It does not show how many brands the researchers tested before finding 374, or how often each AI product returned poisoned information across repeated queries.

Generative search results can vary by date, location, account state, query wording, and product version. A fraudulent number appearing once is still a safety failure, but it differs from a number appearing reliably for most users.

The phrase “affected company” also needs careful interpretation. It can mean attackers published pages impersonating a brand, an AI system retrieved those pages, or a user actually received the fraudulent information.

Those stages should not be collapsed. The first measures attacker intent, the second measures platform exposure, and the third measures consumer harm.

Public disclosure would be stronger with anonymized query logs, timestamps, screenshots, source URLs, model versions, geographic settings, and repeated-test results. Researchers could then distinguish persistent poisoning from transient output.

The campaign name also belongs to Vigilance, not to an independently attributed criminal group. The currently available reporting does not identify a single operator responsible for every malicious page.

Several groups may be applying similar tactics because the cost of publishing optimized content is low. Shared numbers, hosting infrastructure, templates, or payment flows would provide stronger evidence of coordinated control.

There is another uncertainty around the term GEO. It accurately describes content designed for generative retrieval, but some of the underlying tactics resemble older SEO poisoning, review spam, domain compromise, and technical-support fraud.

The novelty is primarily in the delivery layer. An AI assistant can select, rewrite, and endorse the planted data within a conversational answer.

That makes this more than a rebranding exercise. Traditional SEO poisoning still places a suspicious destination between the search interface and the fraud attempt. Generated answers can remove that pause.

Still, not every incorrect number proves deliberate AI manipulation. Models can hallucinate contact details, combine digits from separate sources, or repeat outdated information. Investigators need to separate intentional poisoning from ordinary factual error.

The difference matters for mitigation. Hallucination calls for stronger grounding and uncertainty handling. Coordinated poisoning requires abuse detection, infrastructure mapping, takedowns, and source-reputation controls.

Companies should also avoid overstating what their monitoring can prove. Testing a handful of prompts does not establish that every customer sees the same answer. Conversely, a clean test today does not prove that poisoned content never appeared yesterday.

The responsible conclusion is narrower than the most alarming version of the story. Vigilance has reported a large, active campaign that deserves platform and brand investigation. The disclosed evidence does not yet quantify total exposure or losses.

Banks, airlines, and software vendors now have an AI answer problem

Companies can no longer protect their support identity only through websites, advertising controls, and conventional search monitoring.

A targeted business may have secure systems and accurate contact pages while still appearing in a poisoned AI response. Its security team does not control every review, uploaded PDF, compromised university page, or chatbot retrieval result.

That expands brand protection into an unfamiliar environment. Teams must monitor what assistants say, which sources they cite, and whether unfamiliar phone numbers or domains recur across queries.

Priority queries should involve account recovery, reservations, refunds, payments, software downloads, and technical support. These topics combine urgency with requests for credentials or financial information.

Monitoring also needs geographic and linguistic coverage. Airlines and banks operate through regional contact channels, while attackers can target travelers or customers who expect a local number.

A useful test does more than ask one assistant for “customer service.” It varies phrasing, product, location, urgency, and the requested action. The team can then compare every returned number, email address, URL, and download instruction against authenticated company records.

Repeated indicators deserve escalation. One suspicious number appearing beside several unrelated airline names can reveal a shared criminal call center. A domain cited across multiple fake software-support answers may expose a broader phishing operation.

Customer complaints should feed the same process. A report that “the chatbot gave me this number” is threat intelligence, not merely a support issue.

Companies also need a fast correction path with AI providers and search engines. Existing abuse-reporting systems often focus on a harmful webpage. This threat may require removing the page, correcting an answer, reassessing related sources, and identifying duplicate infrastructure.

Clear first-party contact pages remain important. Organizations should maintain consistent, machine-readable support information and remove outdated regional pages that create ambiguity.

They should also warn customers that staff will not request remote-control software, cryptocurrency payments, gift cards, or full credentials. Those warnings help when a fraudulent operator has already captured the initial call.

Enterprise use introduces another layer of exposure. Employees increasingly ask assistants for package names, command-line instructions, vendor portals, and account-recovery procedures.

A poisoned consumer answer might steal a payment card. A poisoned workplace answer could direct an employee to malware, a credential-harvesting page, or a compromised software dependency.

Security controls should therefore verify actionable outputs at runtime. Links, phone numbers, software packages, commands, and payment instructions deserve more scrutiny than general explanatory text.

Knowledge workers can reduce their exposure by preserving the source trail behind important decisions. A searchable personal knowledge base can retain official procedures and prior verification, but stored material must still be reviewed when contact details change.

The safest user behavior remains direct verification. Open the company’s official app or type its known domain into the browser. Use the number printed on a payment card or formal account document when appropriate.

Do not treat a second AI answer as independent confirmation. ChatGPT, Gemini, and Google AI Overview can retrieve overlapping sources, so two matching responses may reflect the same poisoned page.

What will show whether AI answer providers can contain the threat

The next test is whether platforms can authenticate high-risk facts before generating them, not simply remove each reported scam page.

The first signal will be product-level handling of phone numbers, login pages, and payment instructions. A meaningful response would give these details stricter verification than ordinary factual claims.

For support queries, the system could prefer a company’s verified first-party domain and label the source clearly. If no authenticated record is available, it could decline to provide a number instead of synthesizing one from third-party pages.

This would strengthen the case that ChatGPT search poisoning can be contained at the answer layer. Continued reports of newly planted numbers appearing as official contacts would weaken it.

The second signal will be transparent measurement. Google, OpenAI, and other providers do not need to disclose defenses that would help attackers, but they can publish useful aggregate data.

Relevant metrics include how many support-detail queries receive first-party grounding, how quickly confirmed poisoned sources disappear, and how often high-risk answers trigger warnings or refusals.

Independent replication matters too. Researchers should test consistent query sets across products, regions, and dates. They should separate a poisoned citation from an answer that actually repeats the fraudulent detail.

The third signal will be coordinated response across brands, hosting providers, review platforms, and AI companies. Removing one AI answer while leaving the malicious documents online allows another system to retrieve them.

Likewise, deleting a single document does little if the same operator controls many accounts and domains. Infrastructure-level disruption must connect repeated numbers, templates, hosting patterns, and payment requests.

The Dark Sourcery disclosure places immediate pressure on ChatGPT, Gemini, and Google AI Overview because their interfaces turn web retrieval into a direct recommendation. It also pressures every organization whose customers use those systems as an unofficial support desk.

For users, the practical rule is simple. Treat AI-generated contact information as an unverified lead when money, credentials, downloads, or account access are involved.

For companies, the action is broader. Test how AI systems represent your support channels, collect the cited sources, and build a process for correcting poisoned answers before customer complaints become the first warning.

The final question is not whether an AI assistant can find a phone number. It is whether the assistant can establish who controls that number before asking a user to trust it.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page