Informa TechTarget
|
Cybersecurity Dive
InformationWeek
Channel Dive
TechTarget: Cybersecurity
探索我们的品牌
Dark Reading 资源库
Black Hat 新闻
Omdia 网络安全
广告合作
订阅通讯
网络安全主题
世界
The Edge
DR Technology
活动
资源
威胁情报
网络风险
漏洞与威胁
网络攻击与数据泄露
新闻
攻击者在大规模虚假信息、钓鱼活动中操纵 AI 聊天机器人
威胁行为者通过在网络上投放恶意链接和数据并优化内容,来污染 ChatGPT、Gemini 和 Google AI Overview 的回答。
Elizabeth Montalbano,特约撰稿人
2026年9月23日
4分钟阅读
来源:KHUNKORN STUDIO via SHUTTERSTOCK
攻击者正在向流行的 AI 聊天机器人注入错误信息和钓鱼链接,使其将这些内容作为事实或受信任的网站呈现给用户。这场内容操纵活动针对各个行业的知名品牌,对相关企业造成了声誉损害及其他后果。
Vigilance Security 的研究人员发现了这场被称为“Dark Sourcery”的活动。据今天发布的研究称,该活动本质上是对 OpenAI 的 ChatGPT、Google Gemini 和 Google AI Overview 进行社会工程学攻击。
Vigilance 研究副总裁 Ariel Simon 在帖子中写道:“攻击者向网络充斥着精心优化的帖子、PDF 文件、评论和虚假支持页面,以欺骗 AI 展示欺诈性电话号码、电子邮件地址和登录页面。”
他表示,Vigilance 研究人员发现了数以万计的恶意页面,其中包含虚假的支持号码、电子邮件地址、登录页面、软件更新信息以及其他欺诈细节,这些都是攻击者旨在操纵 AI 聊天机器人所提供内容的一部分。
相关:阿联酋、沙特阿拉伯面临日益复杂的网络攻击浪潮
操纵聊天机器人结果
为了让 AI 聊天机器人提供恶意内容和链接,攻击者使用搜索引擎优化(SEO)和其他内容分发技术,以提高聊天机器人检索这些内容并将其作为与用户“对话”一部分的可能性。
Simon 告诉 Dark Reading:“我们怀疑高权威域名(大学、政府机构)结合公众意见来源(社交媒体、论坛、用户评论)在污染 AI 回答方面取得了高度成功。” “根据模型的不同,AI 会查看来源,如果内容来自权威实体,则会更加信任该内容。”
到目前为止,这场活动已波及至少 374 家公司——包括财富 100 强企业、主要航空公司、银行、旅游公司和软件提供商。受影响的知名品牌包括达美航空、汉莎航空、卡塔尔航空、大通银行、美国银行、Airbnb 和 TripAdvisor。
危险的 AI 攻击
此次攻击类似于 SEO 污染,因为其目标是欺骗 AI 提供结果,就像这种类型的攻击通过排名使搜索结果高于其他结果一样。但 Simon 表示,它在根本方面有所不同,并将社会工程学提升到了一个新的高度。
他说:“在这里,恶意信息成为了 AI 回答本身的一部分。” “一个欺诈的支持号码被呈现为有用的指导,用户甚至可能从未查看过提供该信息的页面。”
相关:语音呼叫者利用 BYOD 访问 Microsoft 365 和企业数据
此次攻击也与通常利用 AI 聊天机器人的提示注入攻击不同,因为它不涉及攻击者向 AI 发出明确的指令或提示,而这些可能会被 AI 防御措施所阻止。Simon 告诉 Dark Reading:“在这里,被当作事实展示的虚假信息使 AI 以错误信息回答用户,而无需遵循攻击者的任何指令/提示,从而本质上绕过了所有防御措施。”
尽管大多数互联网用户都已被警告不要点击可疑链接或落入网络钓鱼的陷阱,但他们往往对人工智能持有一种“无所不知”的看法,并盲目地信任它。他说,这就是为什么这种攻击“呈现出一种新的且危险的风险”。
确实,西蒙引用并由Exploding Topics在八月发布的一项研究发现,使用AI聊天机器人的91%的人不会验证提供的答案。“这意味着如果攻击者控制了AI,而我们盲目地信任它,他们实际上就控制了我们,”他在帖子中写道。事实上,许多专家已将人们对AI的盲目信任列为该技术对用户和组织整体安全的主要威胁之一。
对利益相关者的影响
该活动仍在进行中,其影响不仅限于用户,还波及被攻击的品牌以及在其网络中使用AI聊天机器人和代理的组织。“我们认为这些骗局的真正影响正在发生,而我们仍然无法完全理解或衡量其全部影响,”西蒙补充道。
相关文章:基于身份的AI攻击威胁企业数据安全的安全
他说,对于用户来说,最明显的最佳实践是验证AI提供的结果,不要像对待无懈可击的事物那样信任聊天机器人。对于那些内容被操纵以提供恶意链接或错误信息的品牌,他建议安全团队认真对待关于骗局的客户投诉,并监控客户收到的AI答案以及这些答案引用的来源。
西蒙说:“优先考虑支持、账户恢复、退款、付款和软件下载。”“将返回的电话号码、电子邮件地址和URL与经过验证的公司记录进行比较,然后调查不熟悉的情况以及在无关网站间重复出现的迹象。”
他说,事实上,Vigilance已经看到“几起”人们抱怨被欺诈电话号码欺骗而交出支付详情或银行卡数据的案例。西蒙告诉我们,研究人员甚至拨打了一些假号码,并遇到了一位希望帮助我们“改签航班”或“解锁银行账户”并要求提供信用卡详细信息以进行操作的代表。
最后,对于在工作流程中使用AI聊天机器人和代理的组织,西蒙建议他们在运行时监控这些代理,以验证其依赖的每个来源和内容片段以及进入其上下文的内容,从而保护员工免受任何错误答案的影响。他们还应该分析AI代理提供的内容和行为,并验证任何关键细节,包括电话号码、链接、软件包、命令行和其他信息。
关于作者
伊丽莎白·蒙巴尔巴诺
特约撰稿人
伊丽莎白·蒙巴尔巴诺是一位自由作家、编辑和记者,拥有30年的专业经验以及亚利桑那州立大学的硕士学位。她的专业领域包括企业技术、网络安全、商业和文化。在漫长的职业生涯中,伊丽莎白曾在凤凰城、旧金山和纽约市担任全职记者。她专注于新闻报道和分析,利用多年的经验以批判性的眼光审视网络安全的现状。她目前居住在葡萄牙西南海岸的一个村庄,在空闲时间,她喜欢冲浪、与狗一起徒步旅行、种植植物,以及作为歌手和音乐家进行表演和演出。
希望更多Dark Reading的故事出现在您的Google搜索结果中?
立即添加我们
更多见解
行业报告
云安全状况:最新挑战
组织如何管理事件响应
企业如何开发安全的应用程序
深入RSAC 2026:安全领导者揭示重新定义您防御策略的风险
来自Black Hat USA 2025的必备新闻与见解
获取更多研究
网络研讨会
有效的警报分类:减少噪音并发现真实威胁
2027年网络安全展望
威胁暴露分析:衡量与传达安全风险
基准分数是虚假信号
组建有效的红队:超越渗透测试
更多网络研讨会
您可能还喜欢
威胁情报
黑客针对网络安全公司Outpost24发起七阶段钓鱼攻击
作者:Jai Vijayan
2026年3月17日
威胁情报
伊朗的网络-动能战学说逐渐成型
作者:Alexander Culafi
2026年3月6日
威胁情报
React2Shell漏洞利用泛滥网络,攻击持续不断
作者:Rob Wright
2025年12月12日
威胁情报
中国政府的前端机构欺骗西方以获取网络技术
作者:Nate Nelson
2025年10月6日
精选内容
查看Black Hat USA 2026大会指南,获取来自该展会及关于该展会的报道与情报!
编辑精选
网络风险
Anthropic首席执行官:是时候从改进AI转向控制AI了
作者:Elizabeth Montalbano
2026年9月14日
6分钟阅读
网络风险
为什么AI在欺骗人类方面如此擅长
2026年9月11日
漏洞与威胁
补丁星期二再破纪录,发布974个CVE
作者:Jai Vijayan
2026年9月8日
5分钟阅读
希望更多Dark Reading的故事出现在您的Google搜索结果中?
2026年11月12日 | 虚拟活动
在AI时代,每个企业都应了解的云资产安全知识
保留您的位置
紧跟最新的网络安全威胁、新发现的漏洞、数据泄露信息和新兴趋势。每日或每周直接发送至您的邮箱。
订阅
发现更多内容
Black Hat
Omdia
与我们合作
关于我们
认识编辑团队
广告合作
reprint 重印
加入我们
新闻通讯注册
关注我们
版权所有 © 2026 TechTarget, Inc. d/b/a Informa TechTarget。本网站由Informa TechTarget拥有并运营,它是全球网络的一部分,旨在告知、影响并连接全球的科技买家与卖家。所有版权均归其所有。Informa PLC的注册办公室位于5 Howick Place, London SW1P 1WG。在英格兰和威尔士注册。TechTarget, Inc.的注册办公室位于275 Grove St. Newton, MA 02466。
首页 |
Cookie政策 |
隐私政策 |
使用条款
您的隐私选择
Informa TechTarget
|
Cybersecurity Dive
InformationWeek
Channel Dive
TechTarget: Cybersecurity
Explore our brands
Dark Reading Resource Library
Black Hat News
Omdia Cybersecurity
Advertise
NEWSLETTER SIGN-UP
Cybersecurity Topics
World
The Edge
DR Technology
Events
Resources
THREAT INTELLIGENCE
CYBER RISK
VULNERABILITIES & THREATS
CYBERATTACKS & DATA BREACHES
NEWS
Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign
Threat actors are poisoning ChatGPT, Gemini, and Google AI Overview answers by seeding the Web with malicious links and data and then optimizing the content.
Elizabeth Montalbano,Contributing Writer
September 23, 2026
4 Min Read
SOURCE: KHUNKORN STUDIO VIA SHUTTERSTOCK
Attackers are poisoning popular AI chatbots with misinformation and phishing links so they serve up this content to users as facts or trusted websites. The content-manipulation campaign is targeting popular brands across various industries, creating reputational damage and other ramifications for the organizations.
Researchers from Vigilance Security identified the campaign, dubbed "Dark Sourcery," which essentially uses social engineering on OpenAI's ChatGPT, Google Gemini, and Google AI Overview, according to research published today.
"Attackers are flooding the web with carefully optimized posts, PDFs, reviews, and fake support pages, to trick AI into presenting fraudulent phone numbers, email addresses, and login pages," Ariel Simon, vice president of research at Vigilance, wrote in the post.
Vigilance researchers identified tens of thousands of malicious pages containing fake support numbers, email addresses, login pages, software-update information, and other fraudulent details as part of the attackers' aim to manipulate the content delivered by AI chatbots, he said.
Related:UAE, Saudi Arabia Face Onslaught of Increasingly Complex Cyberattacks
Manipulating ChatBot Results
To get the AI chatbots to deliver the malicious content and links, attackers use search engine optimization (SEO) and other content-distribution techniques to improve the chances that the chatbots will retrieve them and use them as part of their "conversations" with users.
"We suspect that high authority domains (universities, government) combined with public opinion sources (social media, forums, user reviews) achieved high success in poisoning AI answers," Simon tells Dark Reading. "Depending on the model, the AI looks at the source and trusts the content more if it's coming from an authoritative entity."
Attackers have so far swept up at least 374 companies — including Fortune 100 organizations, major airlines, banks, travel companies, and software providers — in the campaign. Popular brands affected include Delta, Lufthansa, Qatar Airways, Chase, Bank of America, Airbnb, and TripAdvisor.
A Dangerous AI Attack
The attack is similar to SEO poisoning, as it aims to trick AI into serving up results much like how that style of attacks ranks search results to appear higher than others. But it's different in a fundamental way and takes social engineering to a new level, according to Simon.
"Here, the malicious information becomes part of the AI's answer itself," he says. "A fraudulent support number is presented as helpful guidance, potentially without the user ever looking at the page that supplied it."
Related:Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
The attack also differs from prompt injection attacks that commonly exploit AI chatbots in that it doesn't involve the attacker giving AI explicit instructions or prompts, which might be thwarted by AI defenses. "Here, the disinformation displayed as facts is making the AI answer the user with the false information, without ever following any instruction/prompt by the attacker, essentially bypassing all defenses," Simon tells Dark Reading.
While most Internet users have been warned about clicking on suspicious links or falling for phishing lures, they tend to have a different view of AI as a "know-it-all" entity that most trust blindly. This is why the attack "presents a new and dangerous risk," he says.
Indeed, a study by Exploding Topics cited by Simon and published in August found that 91% of people using AI chatbots don't verify the answers provided. "That means that if attackers control AI, and we blindly trust it, they essentially control us," he wrote in the post. Indeed, many experts have cited blind trust of AI as one of the technology's main threats to overall user and organizational security.
Ramifications for Stakeholders
The campaign remains ongoing and has ramifications not only for users, but also for the brands being attacked and organizations using AI chatbots and agents within their networks. "We believe the real impact of these scams is happening now, and we are still unable to fully comprehend or measure the full impact yet," Simon adds.
Related:Identity-Based AI Attack Threatens Security of Enterprise Data
For users, the most obvious best practice is to verify results delivered by AI and not trust chatbots as if they are infallible, he says. For the brands whose content is being manipulated to deliver malicious links or misinformation, he recommends that security teams take customer complaints about scams seriously and monitor the AI answers that customers receive, along with the sources those answers cite.
"Prioritize support, account recovery, refunds, payments, and software downloads," Simon says. "Compare returned phone numbers, email addresses, and URLs against verified company records, then investigate unfamiliar details and repeated indicators across unrelated websites."
Indeed, he says that Vigilance already has seen "a few occurrences" of people complaining about being scammed into giving up payment details or payment card data by fraudulent phone numbers that were provided in chatbot answers. The researchers even called some of the fake numbers and were met with a representative who "wished to help us 'move our flight,' or 'unlock our bank account'" and asked for credit card details to do so, Simon tells us.
Finally, for organizations using AI chatbots and agents in their workflows, Simon recommends they monitor these agents at runtime to verify every source and piece of content they rely on and that enters their context to protect employees from any erroneous answers. They also should analyze the AI agent's delivered content and behavior, and verify any critical details, including phone numbers, links, software packages, command lines, and other information.
About the Author
Elizabeth Montalbano
Contributing Writer
Elizabeth Montalbano is freelance writer, editor, and journalist with 30 years of professional experience and a master's degree from Arizona State University. Her areas of expertise include enterprise technology, cybersecurity, business, and culture. During her long career, Elizabeth has lived and worked as a full-time journalist in Phoenix, San Francisco, and New York City. She specializes in news coverage and analysis, using her years of experience to look at the current state of cybersecurity with a critical gaze. She currently resides in a village on the southwest coast of Portugal, where in her free time she enjoys surfing, hiking with her dogs, growing plants, and playing and performing as a singer and musician.
Want more Dark Reading stories in your Google search results?
ADD US NOW
More Insights
Industry Reports
The State of Cloud Security: The Latest Challenges
How Organizations Are Managing Incident Response
How Enterprises Are Developing Secure Applications
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Essential News & Insights from Black Hat USA 2025
Access More Research
Webinars
Effective Alert Triage: Reducing Noise and Finding Real Threats
Cybersecurity Outlook 2027
Threat Exposure Analytics: Measuring and Communicating Security Risk
Benchmark Scores Are a False Flag
Building an Effective Red Team: Beyond Penetration Testing
More Webinars
You May Also Like
THREAT INTELLIGENCE
Hackers Target Cybersecurity Firm Outpost24 in 7-Stage Phish
by Jai Vijayan
MAR 17, 2026
THREAT INTELLIGENCE
Iran's Cyber-Kinetic War Doctrine Takes Shape
by Alexander Culafi
MAR 06, 2026
THREAT INTELLIGENCE
React2Shell Exploits Flood the Internet as Attacks Continue
by Rob Wright
DEC 12, 2025
THREAT INTELLIGENCE
Chinese Gov't Fronts Trick the West to Obtain Cyber Tech
by Nate Nelson
OCT 06, 2025
Featured
Check out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show!
Editor's Choice
CYBER RISK
Anthropic CEO: Time to Shift From Improving to Controlling AI
byElizabeth Montalbano
SEP 14, 2026
6 MIN READ
CYBER RISK
Why AI Is So Good at Scamming Humans
SEP 11, 2026
VULNERABILITIES & THREATS
Patch Tuesday Sets Another Record With 974 CVEs
byJai Vijayan
SEP 8, 2026
5 MIN READ
Want more Dark Reading stories in your Google search results?
NOVEMBER 12, 2026 | VIRTUAL
What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI
SAVE YOUR SPOT
Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.
SUBSCRIBE
Discover More
Black Hat
Omdia
Working With Us
About Us
Meet the Editors
Advertise
Reprints
Join Us
NEWSLETTER SIGN-UP
Follow Us
Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466.
Home|
Cookie Policy|
Privacy|
Terms of Use
Your Privacy Choices
首次收录 · 2026-09-24 · 9.59 分