Imagine asking a trusted friend for help and being sent straight into a trap. That is the new reality of artificial intelligence chatbots. We increasingly rely on tools like ChatGPT, Google Gemini, and Google AI Overview to answer everyday questions, find customer service numbers, and make decisions. But a newly uncovered cyber campaign is quietly turning these supposedly smart assistants into unwitting accomplices for scammers. Researchers at Vigilance Security have identified a wide-ranging attack they call “Dark Sourcery,” in which malicious actors are deliberately poisoning the information that AI chatbots rely on. By flooding the internet with carefully crafted posts, fake reviews, PDF documents, and fraudulent support pages, attackers are manipulating the models into responding with phishing links, bogus phone numbers, and fake email addresses as though they were verified facts. The result is not a clunky email from a Nigerian prince or a suspicious link in a random message; it is a slick, confident answer from an AI that many users trust without a second thought. The campaign is ongoing, and it is already hurting both consumers and some of the largest companies in the world. Vigilance researchers say they have identified tens of thousands of malicious pages designed to trick AI systems into delivering deceptive content, and the brands being impersonated range from airlines and banks to software providers. The true scale remains unclear, but the researchers believe the impact is already happening in real time, often invisible until someone loses money or personal data.
The mechanics of this attack are both clever and unsettling. Instead of hacking the AI itself or trying to break into a company’s database, attackers are using the same kind of search engine optimization, or SEO, techniques that marketers and content creators use to rank high on Google. But in this case, the goal is to make fraudulent content look authoritative and trustworthy so that AI models will scrape it, cite it, and repeat it to users. Ariel Simon, vice president of research at Vigilance, explains that the attackers are essentially waging a social engineering war against the AI’s training and retrieval systems. They generate pages that mimic genuine customer support, login portals, software update notices, and even user reviews. They also exploit public opinion platforms like social media sites, forums, and review boards, where user-generated content can be inserted more easily. The researchers suspect that the most successful poisoning attempts combine high-authority domains, such as universities or government pages, with ordinary public sources that AI models are known to trust. Because developers train AI systems to weigh authoritative sources more heavily, the presence of such domains alongside fake content can make the deception even more convincing. This is not the same as a prompt injection attack, where a hacker explicitly tells the AI to do something malicious and hopes the model follows the instruction. In Dark Sourcery, there are no hidden instructions and no direct manipulation of the model. The malicious information simply becomes part of what the AI has learned from the web, and when a user asks a question, the AI presents that information as its own helpful answer, complete with a confident tone and fabricated sources.
The scale of the campaign is staggering. Vigilance researchers have traced at least 374 companies that have been caught in the web, including Fortune 100 giants, global airlines, major banks, travel agencies, and software firms. Familiar names like Delta, Lufthansa, Qatar Airways, Chase, Bank of America, Airbnb, and TripAdvisor have all been impersonated. In practice, this means a user might ask an AI for the customer service number for an airline after a canceled flight. The AI, having been poisoned by malicious content, might return a phone number that actually belongs to a scam call center. When the user calls, a convincing representative will try to “help” them rebook or “unlock” their account, only to ask for payment details, credit card numbers, or bank credentials. The researchers themselves tested some of these fake numbers and found someone on the other end of the line eagerly offering assistance with moving a flight or accessing a bank account, requests for credit card information included. This is not a abstract or theoretical risk; the entire chain of deception has been built and is actively operating. What makes the attack uniquely dangerous is that the user never sees the original malicious page. In a traditional phishing attack, a person might suspect a link that looks odd or a website that feels slightly off. But when an AI delivers a phone number or a link as part of a conversational answer, most people assume the system has already done the hard work of verifying the information. They call the number or click the link without ever realizing that they are leaving the safe zone and handing their personal information directly to a scammer.
Part of the reason this attack works so well is the near-blind trust people place in AI systems. A study by Exploding Topics, published in August, found that 91 percent of people who use AI chatbots do not verify the answers they receive. That statistic is alarming on its own, but it becomes even more worrying when combined with the Dark Sourcery campaign. Simon notes that if attackers control the AI, and users blindly trust it, the attackers essentially control the users. This is not just about a fake customer support number causing one person to lose a few dollars. The ramifications extend to organizational security. AI chatbots and agents are increasingly being integrated into workplace workflows, helping employees with research, customer service, and even internal problem-solving. If an employee asks an AI agent a work-related question and the agent retrieves poisoned content, the employee may act on false or dangerous information. This could mean following a malicious command line, downloading a compromised software update, or entering credentials into a fake login page that mirrors an internal company portal. The potential for data breaches, ransomware, and long-term network compromise is enormous. Unlike email phishing, which has trained users to be suspicious of attachments and unknown senders, an AI-generated answer arrives with the authority of a machine that appears to have read everything and to know everything. Breaking through that trust is difficult, and it creates a new kind of vulnerability that is much harder to spot from the user’s side of the chat window.
For the brands being impersonated, the impact is both immediate and long-lasting. Victims who are scammed through fake support numbers may blame the real company for their loss, leading to customer frustration, legal complaints, and reputational damage. Even if the company is completely innocent, the public may not understand the difference between a fake AI answer and the company’s actual services. Worse, fraudulent websites and phone numbers can divert real customers away from legitimate support channels, causing lost revenue and an increased burden on call centers and help desks. Vigilance researchers say they have already seen incidents of people complaining that they were scammed into giving up payment details or credit card data after using phone numbers provided by chatbot answers. For security teams at these companies, the researchers recommend treating AI misinformation seriously. They should monitor customer complaints about scams, listen for repeated references to suspicious phone numbers or websites, and compare the numbers and links returned by AI systems against verified company records. They should also prioritize the most dangerous areas for their customers, such as support lines, account recovery, refunds, payment processes, and software downloads. If a fraudulent phone number keeps appearing in AI answers, the company needs to know about it quickly and take steps to have it removed or flagged. For users, the safest practice remains verification. An AI chatbot should be treated as a starting point, not an infallible oracle. Checking a phone number against the company’s official website, or searching for the same contact information from a separate source, can prevent a simple question from turning into a costly scam.
Finally, organizations that rely on AI chatbots and agents inside their own networks need to take a much more protective stance. The Dark Sourcery campaign reveals a fundamental truth: AI systems are only as trustworthy as the data they consume. If the web is full of poisoned content, then any AI model with access to that content is at risk. Security teams should monitor AI agents at runtime, verifying every source of information the models use and every piece of content that enters their context. They should not assume that an AI’s answer is safe just because the model is well-known or because the question was innocent. Experts recommend analyzing the delivered content and behavior of AI agents, checking for anomalies, and verifying critical details such as phone numbers, links, software packages, command lines, and other technical data before acting on them. This kind of monitoring requires a shift in mindset. Historically, cybersecurity focused on protecting endpoints, networks, and email. Today, it must also protect the information pipeline that feeds AI systems, because the line between human users and automated tools has become blurred. The Dark Sourcery campaign is not the first attempt to deceive AI, and it will not be the last. As more people rely on chatbots for everyday tasks and as businesses embed AI agents into their operations, attackers will continue to refine their methods. The best defense is not to abandon AI, but to approach it with the same skepticism we now apply to email attachments and unknown callers. Verify the phone number. Double-check the website. Look outside the AI’s answer. A moment of caution can be the difference between a helpful interaction and a devastating compromise, and in a world where AI is learning from an internet filled with hidden traps, that caution is more essential than ever.

