AI fraud – a warning from Israeli experts

Israeli cybersecurity experts have uncovered the Dark Sourcery campaign: attackers inject fake contacts into sources used by neural networks. The attack affected 374 brands, including airlines and banks. Users are advised to verify data on official websites.

Israeli cybersecurity specialists have uncovered a large-scale campaign called Dark Sourcery, in which attackers inject fake contacts into sources used by popular neural networks. The attack affected 374 globally recognized brands, including airlines Lufthansa, United Airlines, Emirates, Qatar Airways, Delta, booking services Airbnb and TripAdvisor, and banks Chase, Citi, and Wells Fargo. The attack mechanism is not related to hacking the language models themselves but uses SEO poisoning: criminals mass-produce fake support pages and PDF files that neural networks accept as official sources. As a result, a user seeking contacts from AI may receive a number for a fake call center where fraudsters extract bank card details. The response from IT giants was mixed: Google stated that such cases do not fall under their vulnerability disclosure program, and OpenAI closed the report due to the difficulty of reproducing the error. Experts recommend always double-checking contact information on companies' official websites.

AI fraud – a warning from Israeli experts