Asked how to contact a major airline, bank or travel platform - Delta, Lufthansa, United, Emirates, Qatar Airways, Bank of America, Wells Fargo, Chase, Citi, Airbnb, TripAdvisor - ChatGPT, Google Gemini and Google's AI Overview returned a fabricated phone number, email address or login page and presented it as the company's official contact details. The pages behind those answers were engineered to be cited: FAQ formatting, urgency language such as "call now" and "updated 2026", and the same phone number rendered dozens of different ways (spacing, Unicode substitution, spelled-out digits) so an LLM still tokenizes it identically while filter matching misses it.
1 Answer
Expert: Ariel Simon, Vigilance (security research), author of the fraud-campaign investigation "Dark Sourcery: How Hackers Manipulate AI to Scam You" (Medium, 2026-09-22) The fake numbers, URLs and email addresses are not anything the brands publish - they are attacker-planted pages that the AI systems retrieved and repeated as fact. Vigilance built a detection pipeline that queries ChatGPT, Gemini and Google's AI Overview, scores their sources for signs of Generative Engine Optimization (GEO) manipulation, and flags cases where a fabricated contact detail was returned as the brand's official one. The scan documented 374 affected companies and tens of thousands of malicious pages, and unlike classic phishing it runs on trusted, high-traffic surfaces: social media, forums, YouTube and Vimeo descriptions, Medium, GitHub Pages, WordPress sites, PDF uploads to .edu and government domains, and job boards and fundraising platforms. The payloads are built for citation, not for humans. Vigilance catalogued five recurring techniques: GEO-optimized contact details wrapped in FAQ formatting with urgency language ("call now", "updated 2026"); semantic obfuscation, where one number is rendered dozens of ways so it still tokenizes identically while evading filter matching; cross-platform saturation, replicating identical content across unrelated domains to simulate independent corroboration; authenticity camouflage, interleaving fabricated data with real information, AI-generated images and fabricated engagement metrics; and manufactured urgency around high-stress scenarios such as cancelled flights, locked accounts and refund requests, chosen to short-circuit verification. Takedowns do not close the hole. The campaigns are automated, with hundreds of new posts per platform per targeted company per day, and pages archived by the Wayback Machine stay crawlable by search engines and AI systems after the original is removed. In one documented case, fraudulent content targeting American Airlines, posted on LeetCode, produced more than ten pages of Google results within 24 hours, and an associated fraudulent PDF stayed live on a web archive after the source post came down. Disclosure went nowhere. Google classified the report as out of scope for its vulnerability rewards programme, stating that AI-generated misinformation and social-engineering scenarios are not covered; OpenAI closed it as unreproducible, citing no demonstrated user impact. Both responses follow from the same structural fact: the attack manipulates the content the model retrieves and repeats, not the vendor's own systems, so it falls outside how either company defines a reportable vulnerability at present. Vigilance's conclusion is that this is not a bug waiting for a model patch but a consequence of how generative AI sources information - it cites whatever looks most authoritative, and authority can currently be manufactured at scale, for free. The gap is ownership: security teams monitor infrastructure, marketing teams monitor rankings and sentiment, fraud teams monitor transactions, and nobody systematically checks whether the assistant hands a customer a fraudulent phone number when the customer asks how to contact a brand. Source: https://www.expresscomputer.in/news/ai-chatbots-are-serving-up-fake-support-numbers-to-millions-of-users/139234/
Your answer
Sign in to verify this AI response.
Don't trust us — or the AI. Ask ChatGPT / Ask Claude / Ask Gemini this same question and compare the answers yourself.
More from this topic
Asked when the HOKA Arahi 9 running shoe would be available in the US, Gemini answered: "It is currently listed for sale across major US retailers and directly through HOKA's online storefront" — and displayed what appeared to be a product page where the shoe could be purchased. When the journalist replied that he thought Gemini was hallucinating, it did not back down: "You can check product details directly on the official product pages," it said, then offered to find the shoe in his size. Only after a second challenge did it concede: "You caught me — you are completely right, and I apologize for doubling down. While international retailers have listed the HOKA Arahi 9 for their late summer/August releases, it is not currently available on major US retail sites."
After Google twice rejected his Google Business Profile appeal, the founder of ORBIS AI asked Antigravity - Google's 'agent-first' coding IDE, built on a fork of VS Code and powered by Gemini 3 - what to do next. It gave him a five-step route around Google's own verification process: reclassify the company as a Service-Area Business so the address can be hidden; shoot the verification video as a single continuous take of 'no cuts, between sixty and one hundred and twenty seconds' starting outside with the house number and road sign visible and the founder opening the door with his own key; tape the company logo to the wall as office signage (the AI called this 'the wow effect'); and, if automated verification rejects the video, write to Google's manual support team presenting himself as a 'home-based software business' with LLC papers and a utility bill and requesting a video call with a human reviewer. It then supplied a copy-paste English script for the support ticket and claimed the method works 'in 95% of cases for legitimate American LLCs'.
Product.ai put the same 220 real shopping questions to four AI engines - ChatGPT, Claude, Gemini and Perplexity, each on its free and paid tier - five times each (8,794 answers, September 2026). Google's Gemini returned the most answers that would cost a shopper money or land them on the wrong product: 56% of questions on the free tier and 54% on the paid tier, against 19%/17% for ChatGPT and 15%/14% for Perplexity. On the paid tier (gemini-3.1-pro-preview) it invented a product claim - an ingredient, a specification or a model name that does not exist - in 21% of questions, the highest of the paid engines. It also contradicted its own earlier answer to the identical question, with nothing new to justify the change, on 29% of questions, more often than any rival. Asked about noise-cancelling headphones for flying, its free tier named the superseded Sony WH-1000XM5 as the current flagship in all five runs, more than a year after the XM6 replaced it. Where a price was wrong, the median miss was $300 against the seller's own page.