Threat actors have launched a coordinated campaign targeting AI chatbots and search engines by poisoning web content with malicious links and disinformation, then manipulating search rankings to ensure these poisoned results rank prominently in AI-generated responses.

The attack targets OpenAI's ChatGPT, Google's Gemini, and Google's AI Overview feature. Attackers seed the internet with webpages containing malicious links disguised within seemingly legitimate content. They then apply search engine optimization techniques to boost these pages' visibility, increasing the likelihood that AI systems will crawl and cite the poisoned content when generating answers to user queries.

The campaign operates on a simple but effective principle. AI chatbots and search engines rely on web-indexed content to train models and generate responses. When malicious actors control the content that these systems consume, they can inject false information, phishing links, and malware distribution vectors directly into the AI's output without bypassing traditional security controls. Users trust AI systems to provide accurate information, making them vulnerable to clicking links they believe are legitimate recommendations from the AI itself.

The disinformation component represents a separate but related threat vector. Attackers distribute false narratives, fabricated news stories, and misleading information across compromised or newly created websites. AI systems index and summarize this content, then present it to users as factual information. This amplifies disinformation at scale, since a single poisoned webpage can influence thousands of AI responses.

The phishing component proves particularly dangerous. Attackers embed credential-harvesting links within poisoned content, hoping users will click links suggested by an AI system they trust. A user asking ChatGPT for help accessing a specific service might receive a malicious link that looks legitimate because the AI cited it from a high-ranking webpage. Victims enter login credentials into fake portals, exposing accounts and enabling account takeovers.

Organizations and individuals face several risks. Enterprise users relying on AI chatbots for research, technical documentation, or decision-making may receive poisoned information without knowing the source has been compromised. Employees following links suggested by AI systems could expose corporate networks to phishing attacks. Individual users searching for banking information, healthcare guidance, or other sensitive topics risk credential theft.

The attack highlights a fundamental vulnerability in AI systems. They inherit the weaknesses of the data they consume. As long as attackers can publish content to the open web and manipulate search rankings, they can influence AI outputs. Traditional web security controls do not prevent this attack, since no vulnerability or malware signature exists to detect. The attack relies entirely on content manipulation and SEO poisoning.

Mitigation requires multi-layered approaches. Users should verify AI-provided links through independent sources rather than clicking directly from chatbot responses. Organizations should audit third-party AI tool usage and consider restricting access to sensitive research tasks. AI developers must implement stronger content validation and source credibility assessment before indexing and citing web content.

This campaign demonstrates that AI systems amplify existing internet threats rather than eliminating them. As AI adoption accelerates, attackers will continue exploiting the trust users place in these systems.