Malicious actors have unleashed a sophisticated attack on popular AI chatbots, poisoning them with misinformation and phishing links to create a massive disinformation campaign that’s already sweeping up hundreds of major brands worldwide.
Researchers from Vigilance Security have identified the campaign, dubbed “Dark Sourcery,” which manipulates OpenAI’s ChatGPT, Google’s Gemini, and Google AI Overview by seeding the web with malicious content. The attackers use social engineering techniques to optimize their posts, PDFs, reviews, and fake support pages to trick AI into presenting fraudulent phone numbers, email addresses, and login pages as trusted information. This manipulation has already affected at least 374 companies, including Fortune 100 organizations, major airlines, banks, travel companies, and software providers.
The attackers’ strategy is to create a convincing narrative that the AI chatbots will use as part of their conversations with users. By flooding the web with carefully crafted content, they increase the chances of the chatbots retrieving and presenting this malicious information. The researchers suspect that high-authority domains combined with public opinion sources have achieved significant success in poisoning AI answers.
The campaign’s impact is not limited to the affected brands; it also poses a threat to users who trust blindly in AI. A study found that 91% of people using AI chatbots don’t verify the answers provided, making them vulnerable to manipulation by attackers. “That means that if attackers control AI, and we blindly trust it, they essentially control us,” says Ariel Simon, vice president of research at Vigilance.
The attack is similar to SEO poisoning in its aim to trick AI into serving up results, but it’s different in a fundamental way. Unlike traditional attacks that rely on explicit instructions or prompts, this campaign uses social engineering to make the AI answer the user with false information without following any instruction or prompt from the attacker. This makes it more challenging for defenders to detect and mitigate.
The ramifications of this attack are far-reaching, affecting not only users but also brands and organizations using AI chatbots within their networks. As the campaign remains ongoing, stakeholders must be aware of the risks and take steps to protect themselves. This includes verifying information provided by AI chatbots and being cautious when interacting with suspicious links or pages.
Ultimately, this attack highlights the importance of understanding the limitations and vulnerabilities of AI systems. Blind trust in these technologies can lead to unforeseen consequences, making it essential for users to exercise caution and critical thinking when engaging with AI-powered tools. By doing so, we can mitigate the risks associated with these attacks and ensure a safer online experience.
Source: Dark Reading — 2026-09-23