Hackers Are Poisoning AI Chatbot Answers to Spread Phishing Links
Security researchers have identified a growing campaign in which threat actors seed the internet with malicious links and misleading data, then optimise that content so it gets picked up and repeated by AI chatbots such as ChatGPT, Gemini and Google's AI Overview. Because these tools summarise information pulled from across the web, attackers are effectively gaming the system to have their phishing links and disinformation surfaced as trustworthy AI-generated answers.
This technique, sometimes described as AI or search poisoning, exploits the trust users place in AI assistants. When a chatbot presents a malicious link as part of a helpful response, users are far less likely to question it than if they found the same link through a suspicious email or search result. For small businesses increasingly relying on AI tools for research, customer support or quick answers, this creates a new avenue for phishing and scams that bypasses traditional email-based defences.
As AI tools become embedded in everyday business workflows, staff need to treat AI-generated links and recommendations with the same caution as any unsolicited web content.