安全研究者披露黑客用 GEO 污染 ChatGPT、Gemini 和 Google AI Overview,374 家企业被植入诈骗联系方式
Key Highlights
A security researcher has documented a large-scale AI disinformation campaign in which attackers manipulated the retrieval and knowledge layers of ChatGPT, Gemini, and Google's AI Overview so that the chatbots surfaced fake customer-support phone numbers and phishing links for hundreds of well-known companies. The study identified 374 affected organizations, including Delta, Lufthansa, Bank of America, and Airbnb. The attack did not require breaching the model weights; instead it exploited how these systems ingest, rank, and trust publicly editable and search-indexed content that anyone can publish.
What Happened
The researcher, writing on Medium, describes a method he calls "dark sourcery." By planting crafted content on websites, app-store listings, and business directories that AI systems crawl and trust, attackers can steer the answers those systems return. When a user asks ChatGPT or Gemini for the support number of a bank or airline, the model may now read the poisoned source and read back a number controlled by the attacker. The same technique lets the AI Overview box on Google Search present scam links as the top result, turning a search feature into an inadvertent amplifier of fraud that reaches millions of daily queries.
Technical Details
The core weakness is that modern assistants blend parametric knowledge with live retrieval. If the retrieval corpus can be influenced, so can the answer. The attacker does not need to hack the model itself; he needs only enough surface on the open web that the ranking algorithm treats as authoritative. In several documented cases the poisoned entries sat in plain HTML pages and review sites that search engines already index heavily, which means the AI systems inherited the contamination automatically rather than through any direct compromise of vendor infrastructure.
This is a close cousin of "Generative Engine Optimization," the legitimate practice of shaping web content so AI answers cite a brand favorably. The attack simply weaponizes the same pipeline. Because the models trust retrieved text by default, there is no built-in step that verifies a phone number against an official registry before repeating it to a user, which is precisely the gap the campaign exploits. The researcher notes the poisoned pages were often indistinguishable from genuine business listings to both crawlers and readers.
Comparison With Past Incidents
This campaign is broader than earlier "prompt injection" cases that targeted a single application through its own input field. Here the manipulation is upstream, in the shared information ecosystem that multiple vendors rely on, so one planted page can poison several competing assistants at once. It also differs from classic SEO spam because the victim is not a human clicking a search result but an AI that then relays the scam to a human, lending the fake number an air of machine-verified authority that a normal search snippet would not carry. The blast radius scales with how many assistants index the same corrupted source.
Industry Impact
For users, the risk is direct financial fraud: a victim who calls the attacker's number may be guided to hand over credentials or payments, or to install remote-access software that compromises their machine. For vendors, the episode shows that retrieval hygiene is now a security boundary, not just a quality concern. Expect more investment in source reputation scoring, provenance checks, and "known scam number" blocklists, as well as clearer disclaimers when an assistant cites a phone number it pulled from the web.
The reputational stakes are high as well. When an assistant confidently states a wrong number, users blame the assistant's maker, not the attacker's webpage. That shifts the burden of cleanup onto the AI vendors, who must now monitor the open web for content designed to hijack their own outputs, a cat-and-mouse problem with no final resolution and significant ongoing cost.
One More Angle
The researcher argues the problem will worsen as agents gain the ability to act, not just answer. If an AI can place calls or fill forms on a user's behalf, a poisoned contact entry becomes a path to automated harm. He recommends that assistants refuse to state support numbers from unverified web sources and instead link to official help pages that the vendor controls, closing the loop between retrieval and action before a user can be defrauded.
Practical Notes
Companies named in the dataset should search for their own brand plus "support number" across low-quality directories and request takedowns. Consumers should bookmark official support URLs rather than trusting a number an AI reads aloud. Regulators may eventually treat AI-surfaced scam contacts as a consumer-protection issue, pushing vendors toward auditable sourcing and periodic third-party audits of what their models cite, much as they already audit financial disclosures.