Attackers are exploiting popular AI chatbots to spread misinformation and phishing links, creating a new and insidious threat that can bypass even the most advanced defenses. The campaign, dubbed “Dark Sourcery,” has already swept up over 374 companies, including major brands like Delta, Lufthansa, and Bank of America.
The attackers are using a clever tactic called social engineering on OpenAI’s ChatGPT, Google’s Gemini, and Google AI Overview to get the chatbots to deliver malicious content. They do this by flooding the web with optimized posts, PDFs, reviews, and fake support pages that trick the AI into presenting fraudulent phone numbers, email addresses, and login pages as trusted information.
The attackers are essentially using search engine optimization (SEO) techniques to make their malicious content more visible to the chatbots. This allows them to bypass traditional security measures, such as filtering out suspicious links or phishing lures. The campaign is particularly insidious because it doesn’t require explicit instructions from the attacker; instead, the disinformation is embedded in the AI’s answer itself.
The stakes are high for both users and organizations. As Vigilance Security researchers noted, 91% of people using AI chatbots don’t verify the answers provided. This means that if attackers control the AI, they essentially have control over us as well. The campaign’s impact is not limited to users; brands being attacked and organizations using AI chatbots within their networks are also at risk.
The Dark Sourcery campaign is a wake-up call for all of us who rely on AI chatbots for information. It highlights the dangers of blindly trusting these technologies, which can be manipulated by attackers to spread misinformation and phishing links. As researchers noted, social engineering has taken on a new level with this attack, making it even more challenging for security experts to detect.
The campaign’s success also raises questions about the trust we place in AI chatbots. While they are designed to provide helpful information, they can be manipulated by attackers to present false or malicious content as trusted information. This is particularly concerning given that many users don’t verify the answers provided by these chatbots.
In practical terms, this means that users should exercise caution when interacting with AI chatbots and always verify the accuracy of the information provided. Organizations using AI chatbots within their networks should also take steps to detect and prevent such attacks. This includes implementing robust security measures, educating users about the risks associated with AI chatbots, and regularly monitoring for suspicious activity.
Ultimately, the Dark Sourcery campaign serves as a reminder that even the most advanced technologies can be exploited by attackers if we don’t stay vigilant. By being aware of these threats and taking proactive steps to protect ourselves, we can minimize the risk of falling victim to such attacks.
Source: Dark Reading — 2026-09-23