Practical guides to protect yourself, your family, and your business from AI-driven scams, deepfakes, and emerging cyber threats.
Ariel Simon, vice president of research at the security firm Vigilance Security, typed an ordinary customer service question into three of the world's most used AI assistants this month. Each one answered with confidence and a phone number. Dialing it would not have reached Delta Air Lines. It would have reached a stranger running a card-skimming scam. Simon's team found the same pattern reaching into at least 374 real companies, disclosed publicly on September 23, 2026, in a campaign the firm named Dark Sourcery.
This is not a phishing email with bad grammar, and it is not a cloned voice on a phone call. It is an attack on the thing that now sits between a customer and the internet: the AI answer itself. Understanding how it works changes what "checking the source" is supposed to mean.
Vigilance Security's research, published September 23, 2026, describes attackers who spent months building and posting large volumes of fabricated content: fake blog posts, PDFs, product reviews and impostor "support" pages, each carrying a phone number, email address or login link falsely attributed to a real company. Named targets span airlines, banks, travel platforms and software firms, including Delta Air Lines, Lufthansa, Qatar Airways, JPMorgan Chase, Bank of America, Airbnb and Tripadvisor. Simon's team counted tens of thousands of these planted pages, built to be read by AI systems rather than by people.
The technique is a variant of what researchers now call generative engine optimization, or GEO, the AI-era successor to search engine optimization (SEO, the practice of shaping a page to rank higher in search results). Where SEO competes for a spot in a list of links a person can still evaluate, GEO competes to become the raw material an AI system quotes inside its own answer, with the source stripped away. Vigilance Security found that pairing content on a high-authority domain (a university site, a government subdomain, anywhere search engines already extend trust) with a matching chorus of claims on forums, social media and review sites was enough to get ChatGPT, Google's Gemini and Google Search's AI Overview to repeat fabricated contact details as settled fact. No hidden commands were involved. Unlike prompt injection, where an attacker buries instructions inside a document to hijack a model's behavior, Dark Sourcery never tries to control the AI at all. It only has to win the ordinary retrieval race every generative search runs, and let the model do the rest.
For the people who called those numbers, the cost was immediate and ordinary: a card number and a security code, read out to a stranger who sounded exactly like the support line they expected, because an AI assistant they trusted recommended it. For your organization, the uncomfortable fact is that none of this touches your website, your domain records or your call center. It happens entirely on infrastructure you do not own and cannot patch, so the first sign of trouble is often a customer complaining about a call your company never took. Across the industry, Dark Sourcery marks a shift past the fight over prompt injection and jailbreaks. The newest attack surface is not a model's instructions, it is the pool of content the model draws on to answer an honest question, and a decade of training people to check the URL before they click has nothing to say about an answer that never shows a URL at all. If your support line fields calls today, it is worth asking the team how many callers this week say they found the number "through an AI search."
The detail worth keeping from Dark Sourcery is that nobody broke into anything. Attackers did not compromise Delta's website or steal Chase's domain. They published enough convincing fake content that generative engines mistook it for truth and repeated it with confidence, at a scale of tens of thousands of pages across 374 companies. That is now a working route to a customer's money, and it will not show up in a phishing simulation or a firewall log. Bring one question to your next security review: if a customer asked an AI assistant for your support number today, would it give the real one?

