English

SecurityVigilance SecurityAriel Simon

Attack Campaign "Dark Sourcery" Identified Forcing AI Chatbots to Output Fake Contact Information

This article is a translation. Read the Japanese original

Researchers at the cybersecurity firm Vigilance Security have reported a cyberattack campaign dubbed "Dark Sourcery" that targets AI chatbots such as ChatGPT and Gemini, as well as Google Search's "AI Overviews."

According to Ariel Simon of Vigilance Security, attackers are polluting AI responses by spreading massive amounts of fake posts, PDFs, reviews, and support pages across the internet. This leads to situations where, when a user asks an AI for a company's contact information, the AI provides fraudulent phone numbers, email addresses, or login pages prepared by the attackers.

Attackers utilize techniques such as Search Engine Optimization (SEO) to guide AI into retrieving this forged content as highly reliable information. Simon points out that by combining authoritative Sources such as universities and government agencies with user-generated content from social media, they have successfully distorted AI responses.

At least 374 companies, including Delta Air Lines, Lufthansa German Airlines, JPMorgan Chase, and Airbnb, are reported to be affected.

According to an August 2026 investigation by Exploding Topics, 91% of people using AI chatbots do not verify the answers provided. Therefore, Simon urges caution and advises not to blindly trust the information presented by AI.

Sources

  1. ChatGPTなどのAIに企業の偽の連絡先を出力させユーザーを詐欺へと導くサイバー攻撃「Dark Sourcery」 (GIGAZINE、2026-09-25)