Ariel Simon, vice president of research at security firm Vigilance Security, has published a report naming an ongoing attack "Dark Sourcery." Attackers are seeding the web with optimized posts, PDFs, reviews, and fake support pages so that when users ask ChatGPT, Google Gemini, or Google's AI Overview for a company's contact information, the AI hands back a scam phone number, a scam email address, or a phishing login page. The researchers counted at least 374 affected brands.
The findings first appeared on Medium, then were picked up by security and tech outlets including Dark Reading and GIGAZINE.
The targets are companies people call when they need a human, fast
The brands named in the report cluster around airlines, banks, and travel platforms: Delta Air Lines, Lufthansa, Qatar Airways, JPMorgan Chase's Chase, Bank of America, Airbnb, TripAdvisor. They share a common trait — when people reach out to them, they're usually in a hurry: a flight needs rebooking, an account is locked, an order is in dispute. That's exactly the moment someone is most likely to ask an AI, "what's the customer service number?"
The researchers actually dialed some of the numbers. According to Dark Reading, whoever picked up was happy to help rebook a flight or unlock a bank account — then asked for credit card details. Other users reported having their payment and credit card information stolen after contacting a support number an AI had provided.
Three ways to poison the well
Per the report, the attackers don't touch the models themselves — they go after the sources the models trust:
- Plant content with fake phone numbers on compromised government and university websites, borrowing the authority of those domains
- Post videos and reviews on user-generated platforms like YouTube and Yelp
- Mass-produce junk pages specifically optimized for how large language models retrieve and rank information
GIGAZINE's summary is that attackers blend "authoritative sources" with "crowd sentiment sources" in a mix that lines up neatly with how AI systems judge credibility. In Simon's own words:
"Attackers are flooding the web with carefully optimized posts, PDFs, reviews, and fake support pages, to trick AI into presenting fraudulent phone numbers, email addresses, and login pages."
The report also cites an August survey from Exploding Topics: among people who use AI chatbots, 91% don't verify the answers they get.
Old scam, new front door
Fake customer-service numbers are a scam that's been around for years. Scammers used to impersonate airlines and banks in search ads and map listings; search engines pushed back with ad review and business verification, and users could at least see a row of links and tell which site a number came from.
AI Overview writes the number straight into a single, complete-sounding answer, with the source compressed into a small citation mark that almost nobody clicks to check. The target attackers need to fool has shifted too — from users scanning a results page to the retrieval and ranking systems themselves, which already lean toward high-authority domains like .gov and .edu. In the eyes of an AI system, one compromised .edu page can outweigh a pile of ordinary websites combined.
The researchers say the attack is ongoing and real losses are happening, though they still can't fully measure its scale. Neither OpenAI nor Google has said publicly whether they've blocked the numbers identified in the report.
For everyday users, the advice is simple: for anything like a support phone number, a payment page, or a login screen, go back to the company's own website or official app to double-check it.
Sources: Vigilance Security research report, CocoLoop, Dark Reading, GIGAZINE, The Hacker News; the affected-brand count and named companies follow the research report, and the user-verification rate follows the Exploding Topics survey.