Contact Us
Share:

When Your AI Assistant Recommends a Domain That Was Built to Rob You

August 9, 2026 Cyber Trends

image

When Your AI Assistant Recommends a Domain That Was Built to Rob You

Your team trusts AI. Developers lean on coding assistants to scaffold APIs. Employees ask AI tools to pull up a vendor portal, a benefits site, or an internal service link. Increasingly, research agents surface

The problem: large language models don't always know the difference between a domain that exists and one that sounds like it should. New research shows that AI models routinely invent plausible-looking web domains for real, well-known brands — domains that were never registered by the company at all. Security researchers have named this behavior phantom squatting, and it's quickly becoming one of the more difficult-to-detect supply chain risks facing enterprises that have integrated AI into daily operations.
 
This isn't a theoretical concern. It's already been weaponized, and the people building the phishing kits are using AI tools of their own.
 
Bottom line for leadership: every AI assistant, coding copilot, or research agent your organization uses is now a potential referral service for attacker-controlled infrastructure — and the recommendation carries the built-in credibility of a trusted internal tool.
 
 
Ready to find out where your AI tools might be sending your people?
 
 
 
The Evidence: This Is a Measurable, Growing Attack Surface
 
The research quantified just how widespread the problem is. Analyzing 913 global brands across 685,339 URL queries and multiple large language model configurations, researchers found the models generated roughly 250,000 hallucinated domains tied to those brands — domains sitting alongside more than 13,220 confirmed malicious URLs already exploiting the same companies' names.
 
This draws a direct comparison to a threat security teams may already know: AI-hallucinated software package names, which attackers have exploited for over a year by publishing malicious packages under the fictitious names models invent. Phantom squatting is the same mechanism applied to web infrastructure — a model can just as easily invent a fake portal, API endpoint, or corporate service URL as it can a fake code library.
 
How the Attack Actually Plays Out
 
Security researchers describe three realistic exploit paths that are already showing up in the wild:
 
  • A coding assistant generates a plausible but unregistered benefits-portal URL, and an attacker registers it before anyone else notices it doesn't exist.
  • A research agent recommends a banking or vendor portal domain that an adversary already registered specifically to capture the traffic AI tools are about to send it.
  • A developer copies an AI-generated API endpoint straight into production code, unknowingly routing live application data to a server the attacker controls.
Unlike typosquatting, which depends on a human mistyping a URL, phantom squatting depends on a model inventing a plausible one and an AI tool presenting it as legitimate. That makes it fundamentally harder to catch: the domain doesn't fit the predictable misspelling patterns defenders normally monitor for, and because it's newly registered, it has no reputation history to trip existing threat-intelligence filters.
 
Proof It's Already Being Exploited
 
It was found that attackers registering flagged phantom domains within 18 to 51 days of the researchers first identifying them. In one confirmed case, a "high-risk" postal-service e-commerce domain was flagged 23 days before an attacker registered it and turned it into the victim-facing front for a phishing operation researchers dubbed "Montana Empire." Notably, the attacker used an AI coding assistant to build the entire kit — scraping a legitimate storefront's design, writing the backend, and standing up a Telegram-based command-and-control channel — before the domain even went live.
 
Also identified - phantom squatting campaigns targeting national postal services and other sectors through phishing pages and a malicious Android application.
 
 
Why This Matters More for Manufacturing, Healthcare, and Financial Services
 
The organizations InfoSight works with every day are exactly the ones this threat targets hardest:
 
 
Financial services firms whose employees and customers rely on AI tools to locate banking portals, vendor payment systems, and compliance documentation — all high-value phantom-squatting targets.
 
Healthcare organizations where AI-assisted research tools may recommend patient portals, insurance verification systems, or referral platforms that don't actually belong to the organization.
 
Manufacturing and critical infrastructure environments increasingly using AI coding assistants to build integrations between OT systems, ERP platforms, and vendor APIs — exactly the scenario where a hallucinated endpoint can quietly become a live data leak.
 
The danger is that the malicious recommendation arrives through a channel the organization already trusts, rather than an email that a spam filter might catch — and it bypasses the reputation-based defenses most security stacks depend on. Researchers also warn this threat is evolving beyond bad recommendations toward fully automated supply chain compromise, where an AI agent could act on a hallucinated endpoint without a human ever clicking anything.
 
 
How InfoSight Closes This Exposure Gap
 
Phantom squatting sits at the intersection of AI governance, threat detection, and supply chain security — which is exactly where InfoSight's services are built to operate.
 
We inventory where and how AI tools — coding assistants, research agents, chatbots — are actually being used across your organization, then identify where hallucinated recommendations could introduce unvetted domains, endpoints, or dependencies into your environment. This is the fastest path to knowing your real exposure before an attacker finds it first.
 
Our expert-validated testing methodology specifically probes the AI tools your teams rely on daily to surface the kind of hallucinated URLs, endpoints, and recommendations that phantom-squatting attackers are actively hunting for. We show you what your AI assistants would tell an employee — before an attacker does.
 
Our purple team engagements simulate the full phantom-squatting attack chain end to end, from AI-recommended endpoint through credential capture, so your detection and response capabilities are tested against this threat before it's tested against you.
 
Our vCISO and vGRCe advisors help you build the AI usage policies and approval workflows Edholm's own recommendation calls for: verifying URLs against authoritative documentation, restricting AI agents from connecting freely to arbitrary new domains, and ensuring no AI-generated recommendation becomes a production action without an independent check in between.
 
 
The Recommendation Your AI Just Gave Might Not Be Real
 
Phantom squatting is a preview of where AI-driven supply chain risk is headed — and most organizations have no visibility into whether it's already affecting them. If your teams are using AI coding assistants, research agents, or copilots in daily workflows, it's worth finding out what those tools would recommend under pressure.
 
Talk to InfoSight about an AI Governance & Exposure Assessment and get expert-validated visibility into where AI hallucinations could be creating your next attack surface.
 
 
 
 
Share This Post:

Stay ahead of evolving threats with expert insights

Subscribe to our newsletter to keep you updated on the latest cybersecurity insights & resources.

One follow-up from a security expert—no spam, ever.