Scroll to top
Threat Intelligence Factor's research team tracks real-world phishing, impersonation and social-engineering campaigns as they happen. See All Reports →

Asked, Clicked, Attacked: When an AI Assistant Points You to the Wrong Link

By Guy Ushomirsky, Factor Security Research · 9 Aug 2026

A user asks an AI assistant for the official site of a retailer they want to buy from. The assistant returns a link; the name and logo look right, and the user clicks. What follows is not a hypothetical — it is a pattern Factor's research team has observed with increasing frequency, and it reflects a broader shift in how phishing infrastructure targets discovery itself, not just the click.

  1. How the Trap Is Set

    Look-alike domains built to pass a quick check. An official store at a domain like audio-shop.com might be shadowed by a fake checkout at audio-shop-pay[.]co or audio.shop — close enough that a fast glance, human or automated, does not catch the difference.

    SEO poisoning. Attackers stuff keyword-rich content so a fake page outranks the legitimate one for searches like "brand support," "brand login," or "brand download" — the exact terms a user or an assistant would search to find a real destination.

    Malvertising. Paid ads that appear official route visitors to malware or a fraudulent checkout page, exploiting the trust users place in top search and ad placements.

    Content designed to influence AI assistants. Some campaigns embed content intended to bias which URLs an assistant surfaces or favors when summarizing search results — an early but real extension of SEO manipulation into AI-assisted discovery.

  2. What the Data Shows

    Malvertising incidents saw sharp spikes reported in late 2024 (Wired, Malwarebytes), and SEO poisoning remains an effective initial-access technique tracked across multiple threat reports (Red Canary, 2024). Platforms are actively pushing back — Google reported blocking 5.1 billion bad ads and suspending 39.2 million advertiser accounts in 2024 (Google Ads Safety Report) — but the scale of that enforcement effort is itself an indicator of how large the underlying problem is. Separately, researchers have documented that AI search and assistant tools can be manipulated by hidden page content or prompt-style tricks embedded in what they read (The Guardian, 2024).

  3. From "Find" to "Compromised" in a Few Clicks

    The sequence is short: a user asks an assistant for an official site; the assistant (or a search result) returns a convincing link; the user clicks through to a page that looks correct in every visible detail; and the user enters payment or login information into a live relay controlled by the attacker. Some versions of the flow even redirect the victim to the real site afterward, so nothing about the experience signals that anything went wrong.

  4. Where Existing Tools Fall Short

    Antivirus software scans files, not the moment a link is opened. Ad blockers hide banners, not fraudulent checkout pages returned by organic search or an assistant. DNS filters catch domains that are already known to be malicious, which does little against a newly registered look-alike. Each of these tools addresses a real problem, but none of them intercepts the decision at the moment it actually happens — when the link is opened, regardless of whether a human found it or an AI assistant suggested it.

  5. Why This Is a Mobile Problem

    AI assistants are increasingly used from mobile devices, where truncated URLs and compact browser chrome make it harder to spot a look-alike domain even when a user is being careful. Closing that gap means inspecting the destination in real time, at the moment the link is opened — whatever surfaced it — which is the layer of defense Factor's aiMTD platform is built to provide.

AI assistant suggesting a link that leads to a phishing site