RESEARCHERS at Vigilance Security have identified an ongoing campaign, dubbed “Dark Sourcery”, that manipulates answers from ChatGPT, Google Gemini and Google AI Overview. Attackers are seeding the web with search-optimised posts, PDFs, reviews and fake support pages containing fraudulent phone numbers, email addresses, login pages and software-update information.
The material is designed to be retrieved by AI systems and presented directly in their answers, rather than merely ranking malicious pages highly in conventional search results.
Vigilance says it has found tens of thousands of malicious pages and linked the campaign to at least 374 companies, including Fortune 100 organisations, airlines, banks, travel firms and software providers. Named brands include Delta, Lufthansa, Qatar Airways, Chase, Bank of America, Airbnb and TripAdvisor. Researchers suspect attackers combine high-authority domains, such as universities and government sites, with social-media posts, forums and user reviews to make the information appear more trustworthy.
The report says researchers have seen a few cases in which victims provided payment or card details to fraudulent numbers supplied by chatbots; calls to some numbers reached people posing as airline or banking support staff.
Vigilance advises users to verify chatbot-provided contact details through official company records. Affected brands should monitor AI answers and cited sources, prioritising support, account recovery, refunds, payments and software downloads. Organisations using AI agents should monitor them at runtime, validate sources and inspect critical outputs such as phone numbers, links, software packages and command lines.