Hackers influence ChatGPT and Gemini to direct users to scam centers
Attackers poison ChatGPT, Gemini, and Google AI Overview with GEO-optimized fake content, steering users of 374 companies toward scam phone numbers and phishing pages.
A detection system analyzing AI answers found in-the-wild GEO (Generative Engine Optimization) poisoning campaigns affecting 374 companies, including Fortune 100 firms, major airlines (Delta, Lufthansa, Emirates), banks (Chase, Bank of America, Wells Fargo), and travel platforms. Attackers planted tens of thousands of malicious pages on UGC platforms (Tumblr, BuzzFeed, GitHub Pages, government/university file uploads) containing fake support numbers, emails, and login pages that ChatGPT, Gemini, and Google AI Overview cite as trusted answers. Poisoning is probabilistic, with higher-quality attacking content increasing the success rate, and operates at a scale traditional takedowns cannot match.