New AI Search Manipulation Technique Exposes Consumers to Global Fraud Scams
Israeli cybersecurity researchers reveal a new fraud technique using GEO to manipulate AI engines like ChatGPT and Gemini, planting fake customer service numbers targeting 374 global brands.

A new cybersecurity study reveals a sophisticated fraud method exploiting public trust in artificial intelligence engines. Conducted by Israeli security researchers Dan Lasker, Ariel Simon, and Naor Khaziz, former members of elite IDF intelligence units, the research highlights how attackers leverage Generative Engine Optimization (GEO) to manipulate AI-generated search results.
GEO-Based Manipulation and Phishing
According to the findings, 92% of users accept AI-generated answers as absolute truth without cross-referencing external sources. Attackers exploit this habit by planting malicious data across the web, including phone numbers embedded with Unicode special characters and emojis. AI search engines, such as ChatGPT, Gemini, and Google AI Overview, process these manipulations and present the altered numbers as official customer service contacts.
Consumers searching for legitimate assistance—such as bank branch hours or flight cancellation procedures—are fed fraudulent numbers. When they call, deceptive call centers impersonate official support desks, charging exorbitant fees or extracting sensitive data. The researchers' system has already detected active attacks targeting 374 major international brands, including Delta, Lufthansa, United, Emirates, Qatar Airways, Airbnb, TripAdvisor, Chase, Citi, and Wells Fargo.
The Challenge of Accountability
Malicious content is continuously uploaded to government websites, academic .edu domains, and social media platforms. Even when removed, archived copies on sites like archive.org continue to feed AI training models, rendering standard takedowns insufficient.
"People have learned to be wary of suspicious links in emails or texts, but when a phone number is presented to them as an absolute fact directly from an AI engine, it is perceived as completely trustworthy," explains security researcher Dan Lasker.
Tech giants and affected corporations currently exhibit a gap in responsibility. Targeted companies argue that since their internal servers remain uncompromised, mitigating fraudulent numbers online falls outside their purview. Meanwhile, researchers report resistance from tech platforms, noting that Google classifies AI-induced misinformation outside the scope of its vulnerability reward programs, while OpenAI frequently closes reports citing the non-deterministic nature of large language models.





