Attackers Exploit AI Hallucinations to Send Users to Phishing Sites
KnowBe4, Wednesday, July 22nd, 2026
KnowBe4 warns attackers are exploiting AI hallucinations to steer users toward phishing sites.
KnowBe4 reports that attackers are exploiting AI hallucinations, where AI assistants invent plausible but false URLs, to lure victims to phishing sites.
Threat actors register these hallucinated domains and populate them with malicious content, waiting for AI tools to recommend them.
The tactic turns AI's confident errors into a novel attack vector. KnowBe4 urges users to verify AI-provided links and organizations to monitor for lookalike and hallucinated domains.