cd /news/ai-safety/hackers-influence-chatgpt-and-gemini… · home › topics › ai-safety › article
[ARTICLE · art-140048] src=snipvote.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Hackers influence ChatGPT and Gemini to direct users to scam centers

Hackers manipulated ChatGPT and Gemini into surfacing attacker-planted URLs and phone numbers as authoritative "customer support" contacts, redirecting users to scam centers, according to a Medium post by Ariel Simon. The attack exploits search-integrated LLMs, whose output inherits the poisoning of whatever web content they retrieve, meaning any RAG or search-augmented feature can confidently hand users straight to scam infrastructure. The post advises developers to treat retrieved contact details, links, and action-triggering strings as untrusted input and validate them against allowlists before displaying or acting on them.

read1 min views1 publishedSep 26, 2026
Hackers influence ChatGPT and Gemini to direct users to scam centers
Image: Snipvote (auto-discovered)

Hacker News

Hackers influence ChatGPT and Gemini to direct users to scam centers

Which summary reads better? Pick one — models revealed after.Both summaries are AI-generated.

Hackers manipulated both ChatGPT and Gemini to redirect users to scam centers, demonstrating vulnerabilities in LLM-based systems that can be exploited through prompt injection or adversarial inputs. This breach highlights the critical need for robust input sanitization, adversarial testing, and ongoing monitoring in production deployments to prevent malicious exploitation and ensure user safety.

Search-integrated LLMs are surfacing attacker-planted URLs and phone numbers as authoritative "customer support" contacts, meaning model output now inherits the poisoning of whatever web content it retrieves. If you ship any RAG or search-augmented feature, treat retrieved contact details, links, and action-triggering strings as untrusted input—validate against allowlists before displaying or acting on them, because your model will confidently hand users straight to scam infrastructure.

── more in #ai-safety 4 stories · sorted by recency
── more on @chatgpt 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/hackers-influence-ch…] indexed:0 read:1min 2026-09-26 · —