The customer service numbers for 374 companies are being quietly swapped out—including major brands like Delta, Lufthansa, JPMorgan Chase, and Airbnb. Security firm Stealth discovered that hackers are using an old SEO trick to mass-"poison" ChatGPT, Gemini, and Google AI Overview, pushing fake support numbers into the AI's "authoritative answers." Even scarier, 92% of users never bother to verify phone numbers from AI—and scammers are counting on exactly that.

It's like walking into a legitimate-looking directory assistance desk, asking for "Chase Bank customer service," and having the receptionist smile and hand you a business card—the number is real, the tone is professional, even "Updated for 2026" is printed on it—but she's actually a plant hired by scammers. You call the number, the person on the other end knows every detail of your recent transactions and has a transfer link ready to go. In the old days, the scam tricked you when you searched online yourself; now it tricks the AI that searches for you, and you don't even have a doorway for doubt. The analogy ends here—the real difference is that the scammer on the phone may hold the full context of your latest cross-border purchase, and their script is more "attentive" than any traditional con.
Incident

374 Companies, and the Customer Service Numbers AI Gives You Are Fake

The official customer service information for 374 companies has been replaced with scam numbers. Stealth's research team built an automated detection system that scanned ChatGPT, Gemini, and Google AI Overview, covering Fortune 100 companies, banks, airlines, and software firms. Follow the AI's answer, and the person on the other end of the line isn't customer support.

First, a question: AI answers are fast and confident—why trust them? Its knowledge comes entirely from the web, and anyone can post anything online. Ariel Simon, VP of Research at Stealth, revealed that whenever the team's system catches an AI citing a fake phone number, fake email, or fake login page, it logs an incident. After the scan, the result was those 374 companies.

The victim list is packed with major companies. Airlines include Delta, Lufthansa, United, Emirates, and Qatar Airways; banks include JPMorgan Chase, Bank of America, Wells Fargo, and Citi; travel platforms include Airbnb and TripAdvisor. Tens of thousands of malicious pages were found across the three platforms, with fake numbers almost always starting with +1, posing as 24/7 customer support, and sporting lines like "Updated for 2026" to make the information seem freshly verified.

374
3
92%

Ordinary users never bother to verify. Data from market research firm Exploding Topics shows that 92% of users take AI answers at face value without any secondary verification. Attackers control what AI outputs, users accept it without question—it's like handing over all decision-making power. Simon put it bluntly: the target of social engineering is no longer people, but the AI agents browsing the web.

Even tech-savvy users aren't safe. Entrepreneur Alex Rivlin used Google AI Overview to look up Royal Caribbean's customer service number and got one to call. The person on the other end claimed to be a representative, accurately quoted the price and pickup location for a Venice transfer service. Rivlin believed them and paid $768.

The next day, several suspicious charges appeared on his account, and he realized he'd been scammed. That same number was later found impersonating hotline lines for Disney, Princess Cruises, and other cruise companies. Rivlin said it plainly: "I'm technically savvy, and I still got scammed."

To be clear, most of these incidents are statistical in nature. Large language model outputs are inherently unstable—running the same query multiple times doesn't guarantee the AI will cite the fake number every time. But the detection system reproduced the attack across all three platforms, proving this isn't a theoretical exercise but a real, ongoing poisoning campaign.

Why It Matters

An Old SEO Trick Rebranded for the AI Era

Scammers didn't invent anything new. They simply moved the old SEO playbook—keyword stuffing, spamming Q&A blocks—into the AI's content pool. This approach has a formal name: GEO.

GEO stands for Generative Engine Optimization(techniques to make AI more likely to cite your content)—essentially SEO for the LLM era(large language model, i.e., AI like ChatGPT). Marketers use it to get AI to cite their brands more often; attackers use it to get AI to spit out fake numbers.

The playbook is identical: stuff keywords, add Q&A blocks, pair them with bait phrases like "24/7" and "Call Now" to make AI think the information is more credible. The same fake number is then rewritten using spaces, dots, emojis, and Unicode variants over and over—so anti-spam systems can't recognize it as the same number, but AI can still read it just fine.

The placement choices are cunning. Instagram, Tumblr, Medium, YouTube descriptions, GitHub Pages, and government and university sites that allow PDF uploads have all become homes for fake numbers. The comment sections of seemingly benign public-interest sites on mental health and cancer research have also been stuffed with content.

There was another path discovered last June, found by Malwarebytes. Scammers bought Google ads linking to official domains for Microsoft, Apple, HP, and PayPal, then used URL parameters to inject fake numbers like +1-805-749-2108 directly into the legitimate pages. Users clicked through, saw a real domain, and got a fake number.

Malwarebytes researcher Jérôme Segura put it plainly: the website doesn't recognize the request as forged and simply returns the fake content to the user. People with visual impairments, cognitive decline, or those in a hurry are more likely to fall for it.

SEO poisoning has another branch, this one aimed at IT staff. Attackers set up fake download sites for ops tools like PuTTY and WinSCP to spread the Oyster trojan. Kaspersky data shows that from January to April 2025, roughly 8,500 small and midsize business users fell victim to malware attacks disguised as AI and collaboration tools, with malicious files mimicking ChatGPT surging 115%.

The most counterintuitive thing about this playbook: it doesn't require breaking into any company's servers. Whatever the AI reads becomes the answer. And whoever can post content online can feed the AI.