Scammers are poisoning ChatGPT's answers with fake support numbers
A stealth security startup says it found hundreds of companies whose AI answers hand users scam contact details. The attack class is real and documented by others; the specific number is one vendor's word. Also today: light instead of copper inside AI clusters, and a small round aimed at what agents are allowed to do.
Vigilance Security's researchers say they built a detector that queries ChatGPT, Gemini and Google AI Overview about hundreds of large companies and scores the sources behind each answer. They report 374 companies whose answers cite attacker-controlled phone numbers, email addresses or login pages, fed by tens of thousands of malicious pages — Fortune 100 firms, airlines including Delta, Lufthansa, United, Emirates and Qatar, and banks including Bank of America, Wells Fargo, Chase and Citi among them. The write-up, by Ariel Simon and colleagues, describes an automated campaign rather than a proof of concept.
The mechanics are worth understanding, because nothing in them is exotic. The payloads are ordinary web content: posts on Instagram, Tumblr, LeetCode and Medium, video descriptions, PDFs uploaded to university and government sites, Yelp and Apple Maps reviews, WordPress and GitHub Pages. Attackers repeat the fake number in question-and-answer form, dress it in "call now" and "updated 2026" phrasing, and write it with spaces, dots and emoji so number-scrubbing spam filters miss it while the model still reads it as a phone number. The framing is deliberately panicked — refunds, canceled flights, locked accounts — so a stressed user dials instead of checking the company's own site. They also mix real support numbers into the same page, which is what gets the fake one cited alongside them.
Almost everything above comes from one source, and that is the part to read carefully. Vigilance's site is still a "building in stealth" placeholder and the post ends with a contact address for its forthcoming product. The 374 figure is the company's own measurement, published with the admission that "most of the incidents were statistical" and that the poisoning did not reproduce on every repeat query. Dark Reading interviewed the same researcher — a second outlet, not a second measurement. Vigilance also says Google classified the report as out of scope for its bug bounty program and OpenAI closed it as not reproducible.
The class of attack, though, is documented by people with no product to sell. Aurascape's Aura Labs named "LLM phone number poisoning" in December 2025, showing Google AI Overview and Perplexity's Comet recommending scam airline support numbers as if official. Cornell researchers showed that ordinary Reddit posts can steer AI search results. NewsGuard tracks false claims appearing in chatbot answers. The common thread is that manipulating what an assistant tells a user is not a breach of the assistant vendor's own systems, so no bug bounty owns it — the victim is the brand being impersonated, and the takedown loop does not close, because hundreds of posts per day per company outrun removal and archived copies stay indexed. The web's trust signals are the attack surface: Seven in ten sites waved a fake GPTBot straight through.
PicoJool raised $27.5 million to put light where AI clusters currently use copper. The Series A was led by Socratic Partners with Hudson River Trading participating, taking the startup to $39.5 million raised after a $12 million seed backed by Pat Gelsinger's Playground Global. PicoJool makes VCSELs — tiny lasers that carry data over fiber instead of copper wire, the interconnect that runs out of reach at a few meters once a cluster grows past a rack — and says its 200G-per-lane parts, now sampling at more than 37GHz, plus its MicroVCSEL designs aggregate toward 3.2 terabits per second, with WIN Semiconductors lined up for volume production early next year. The pitch is supply chain as much as physics: VCSELs ride the mature gallium-arsenide fabs rather than the constrained silicon-photonics one. It is the same wall we covered ten days ago — Ayar Labs adds $150M more as copper interconnects hit the wall — and SiliconANGLE is so far the only newsroom to write this round up; the rest of the paper trail is the company's own.
Kontext raised $4 million to decide what an agent is allowed to do after it logs in. The German startup sits between an agent and every action it requests, checking the agent's identity, the resource, and the job it was actually given: an agent assigned to fix a bug may read the code repository, but not ship that code to an outside service or reuse its access to touch unrelated infrastructure. Teams can run it in observe mode before switching enforcement on, and every decision lands in an audit record. It works with Claude Code and Codex today; individual developers use it free, with team plans from $149 a month. 42CAP led the round, joined by a16z's crypto startup accelerator and High-Tech Gründerfonds. It is the small end of a market that priced a $6.4 billion company this morning — Island raises $400M at $6.4B as rogue AI agents drive security spend.
What to watch: whether any AI vendor starts paying for poisoned-answer detection, or whether impersonated brands keep footing the bill alone.
If your AI assistant hands you a support number, do you dial it or check the company's site — and should the model vendor be liable when it's wrong? Tell us in the comments.
Sources: Dark Sourcery (Vigilance Security) · Dark Reading · ZDNet — LLM phone number poisoning · 404 Media — manipulating AI search · SiliconANGLE — PicoJool · PicoJool · SiliconANGLE — Kontext · Kontext