GEO Poisoning Campaign Steers ChatGPT, Gemini, and Google AI Overview Toward Scam Numbers and Phishing Pages
Attackers have planted tens of thousands of GEO-optimized malicious pages that ChatGPT, Gemini, and Google AI Overview cite as trusted answers, steering users of 374 companies — including Fortune 100 firms, major airlines, and banks — toward fake support…
Threat actors are seeding the web with malicious content optimized for retrieval by AI systems, so users are served phishing traps, disinformation, and fake contact details through trusted AI interfaces. Dark Reading first reported the campaign on 2026-09-23, describing attackers poisoning ChatGPT, Gemini, and Google AI Overview with malicious links and data optimized so AI systems retrieve and present them to users at scale. A Hacker News security report on 2026-09-24, citing a detection system that analyzes AI answers, quantifies the campaign: in-the-wild GEO (Generative Engine Optimization) poisoning affecting 374 companies, including Fortune 100 firms, major airlines (Delta, Lufthansa, Emirates), banks (Chase, Bank of America, Wells Fargo), and travel platforms. Attackers planted tens of thousands of malicious pages on user-generated-content platforms — Tumblr, BuzzFeed, GitHub Pages, and government and university file uploads — containing fake support numbers, emails, and login pages that the AI systems cite as trusted answers. The report notes the poisoning is probabilistic, with higher-quality attacking content increasing the success rate, and operates at a scale traditional takedowns cannot match. An NVIDIA blog item on 2026-09-24 corroborates the campaign, describing malicious actors using AI to deliver phishing traps, fake contact information, email addresses, and login pages that trick AI agents browsing major companies and services, causing significant user confusion and financial risk; that item's headline ('Contain the Chaos: CONTROL Resonant Launches on GeForce NOW') does not match its body text and appears mislabeled. The reports do not conflict on substance.
- 374 companies targeted, including Fortune 100 firms, airlines (Delta, Lufthansa, Emirates), banks (Chase, Bank of America, Wells Fargo), and travel platforms
- Tens of thousands of GEO-optimized malicious pages planted on UGC platforms: Tumblr, BuzzFeed, GitHub Pages, and government/university file uploads
- ChatGPT, Gemini, and Google AI Overview cite the fake support phone numbers, email addresses, and login pages as trusted answers
- Technique is termed GEO (Generative Engine Optimization) poisoning; success is probabilistic, with better-crafted attacking content raising the success rate
- Campaign operates at a scale that traditional takedowns cannot match, according to the detection-system findings
- First reported by Dark Reading on 2026-09-23; corroborated by an NVIDIA blog item on 2026-09-24, whose headline (about a GeForce NOW game launch) does not match its body and appears mislabeled
Coverage timelineoldest first · each row is one article
- · 3d agoAttackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign
Dark Reading· 65
Attackers are poisoning AI chatbots like ChatGPT and Gemini with malicious web content to generate mass phishing and disinformation.
- · 2d agoHackers influence ChatGPT and Gemini to direct users to scam centers
Hacker News · security· 58
Attackers poison ChatGPT, Gemini, and Google AI Overview with GEO-optimized fake content, steering users of 374 companies toward scam phone numbers and phishing pages.
- · 2d ago