GEO Poisoning: 374 Brands Are Serving Scam Numbers Through AI Search (2026)
Quick verdict
Researchers documented a large-scale campaign manipulating ChatGPT, Gemini and Google AI Overview into citing fraudulent support numbers for 374 brands including Delta, Lufthansa and Bank of America. The technique is Generative Engine Optimization weaponized — fake contact details in FAQ formatting, Unicode-obfuscated phone numbers, cross-platform saturation — living on trusted surfaces like .edu PDFs and LeetCode. Google and OpenAI both declined to treat it as a vulnerability.
The Finding
Security researchers documented a large-scale, automated campaign that manipulates ChatGPT, Google Gemini, and Google AI Overview into presenting fraudulent phone numbers, email addresses, and login pages as official brand contact information — for 374 companies, including Fortune 100 organizations.
The affected set spans exactly the industries where users search while stressed: airlines (Delta, Lufthansa, United, Emirates, Qatar Airways), banks (Bank of America, Wells Fargo, Chase, Citi), and travel platforms (Airbnb, TripAdvisor). The scenario is always the same shape: a canceled flight, a locked account, a refund request — high-stress moments where a user wants a phone number and wants to trust it.
The research — published by Vigilance Security (researchers Dan Lasker, Ariel Simon, and Naor Khaziz) and documented in Ariel Simon's September 22 post "Dark Sourcery" — comes with a reproducible detection pipeline rather than anecdotes: query the three AI systems repeatedly, compare returned contact details against official records, and score sources for signs of GEO-driven manipulation. That pipeline surfaced tens of thousands of malicious pages.
The Technique: GEO, Weaponized
Generative Engine Optimization is a legitimate marketing discipline: structure content with statistics, expert quotes, and FAQ sections so AI systems are more likely to cite it. The attack uses the identical toolkit for fraud — which is why it works so well and why it is uncomfortable for anyone practicing GEO legitimately. Including us.
Five recurring techniques were documented:
| Technique | How it works |
|---|---|
| GEO-optimized payloads | Fake contact details wrapped in FAQ formatting with urgency language ("call now," "updated 2026") designed to trigger AI citation |
| Semantic obfuscation | The same phone number rendered dozens of ways — spacing, Unicode substitution, emojis, spelled-out digits — evading text filters while an LLM still reads them as identical |
| Cross-platform saturation | Identical content replicated across unrelated domains to simulate independent corroboration |
| Authenticity camouflage | Fake data interleaved with real information, AI-generated images, and fabricated engagement metrics |
| Manufactured urgency | Content built around canceled flights, locked accounts, and refund requests to short-circuit verification |
Where the Payload Lives
This is the detail that makes takedowns nearly futile: the poisoned content sits on trusted, high-traffic surfaces, not throwaway phishing domains.
Researchers found poisoning posts on Instagram, Tumblr, BuzzFeed, LeetCode, YouTube and Vimeo descriptions, Medium, GitHub Pages, WordPress sites, Blogspot, Yelp and Apple Maps reviews — and PDFs uploaded to government and university (.edu) domains, plus fundraising and job-search platforms.
The LeetCode case is the sharpest example: fraudulent content targeting American Airlines generated more than ten pages of Google results within 24 hours, and an associated PDF remained live on a web archive after the original was removed. Archived copies on the Internet Archive continue to feed AI systems long after takedown.
The campaigns are fully automated — researchers estimate hundreds of new posts per platform, per targeted company, per day. Removing one page while the attacker creates more is not a defense; it is a treadmill.
Why the Answer Varies — and Why That's a Problem
The poisoning did not produce the same answer on every query. Because AI systems may consult different sources on each run, researchers described most incidents as statistical: a fake number appeared in some tests while other runs returned legitimate results. Stronger poisoning content increased the likelihood of the fraudulent detail being repeated.
That inconsistency creates a detection problem in both directions. A single clean test does not show a campaign has ended — security teams need repeated queries across several systems, source checks, and records of what each system returned. And for the user, an answer delivered with confidence reads as fact regardless of which run produced it.
A cited study from Exploding Topics reports that 92% of users do not verify AI answers. As researcher Dan Lasker put it: people have learned to distrust suspicious links in emails, but a phone number presented as fact directly by an AI engine is perceived as trustworthy.
The Responsibility Gap Nobody Owns
The most consequential finding is organizational, not technical. The attack manipulates content the AI retrieves and repeats, not the AI vendor's systems — so it falls outside how everyone currently defines a reportable problem:
- Google classified the report as out of scope: AI-generated misinformation and social-engineering scenarios are not covered under its vulnerability rewards program
- OpenAI closed its report as unreproducible, citing the non-deterministic nature of LLMs
- Targeted companies argued that because their internal servers were untouched, mitigation falls outside their purview
Three teams watch adjacent territory — security monitors infrastructure, marketing monitors rankings and sentiment, fraud monitors transactions — and none of them systematically checks whether an AI assistant is handing customers a fraudulent phone number. The attack works precisely because it targets a gap nobody owns.
The exposure breaks into three categories: revenue loss from customers redirected during active purchase or support intent; brand erosion, because victims blame the impersonated company rather than the attacker; and legal and support overhead from the resulting disputes.
Note what this is not: it is not prompt injection. There is no instruction sent to the model. The disinformation is woven into the fabric of the web the model retrieves from, which is exactly why the standard defenses against malicious prompts do not apply.
What To Do
If you publish content (and if you are investing in AI-search visibility, you do):
- Monitor your own answer surface. Periodically query the major AI systems for your brand's support details and compare against official records. A single clean result proves nothing — sample repeatedly.
- Own the canonical contact surface. Publish support details on your official domain with structured data, so the authoritative version exists and is easy to cite.
- Assume archived copies persist. If fraudulent content referencing your brand appears, takedown is necessary but not sufficient — archived and syndicated copies keep circulating.
As a user:
- Treat any phone number, email, or login link inside an AI answer as unverified
- Obtain support contacts only from the official domain you type yourself
- The strongest signal of fraud is urgency — a support number surfaced around a canceled flight deserves more skepticism, not less
The Bigger Point for This Site's Readers
We publish GEO guidance on this site, and this story is the uncomfortable mirror of it. The techniques that make content citable — FAQ structure, urgency, saturation, authority signals — do not know the difference between legitimate and fraudulent intent. That is not an argument against optimizing for AI search; it is an argument that the same accountability that applies to search rankings must extend to AI answers: monitor what the machines say about you, the way you monitor what the search results say.
The source study's title is "Dark Sourcery." The less dramatic but more accurate framing: the information supply chain behind AI answers has no owner, and attackers noticed first.
Related Articles
Keep reading