Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign
BLUF
Adversaries are weaponizing generative AI search results to distribute malware and disinformation at scale.
NEWS
Threat actors are poisoning responses from major models including ChatGPT, Gemini, and Google AI Overview by injecting optimized malicious data into public web sources. This campaign leverages search engine optimization techniques to ensure AI systems retrieve and propagate harmful links during user queries.
Why I Care
Users lose trust in AI tools as a reliable information source, while organizations face increased phishing risks from seemingly legitimate AI recommendations. This undermines the security of automated workflows and exposes employees to sophisticated social engineering attacks via trusted platforms.
Next Steps
Security teams should audit AI-generated responses for suspicious links and implement verification protocols for external resources. Organizations must update security awareness training to include AI hallucination and poisoning risks immediately.
Source: Dark Reading ·