Researchers Discover a New AI Security Threat
Phantom Squatting is a growing cyber threat that targets AI-generated web addresses. Researchers found that attackers register fake domains created by AI models. Moreover, these domains often look trustworthy to users and developers. As a result, attackers can launch phishing campaigns and malware attacks. Therefore, organizations should understand this emerging security risk.
Researchers explained that large language models sometimes invent website addresses that do not exist. However, attackers quickly purchase those unused domains before anyone else. They then create phishing pages or malware websites on them. Consequently, AI tools may direct users to dangerous locations. This misplaced trust makes the attack highly effective.
AI Models Can Generate Fake Links
Researchers examined how AI models respond to questions about well-known organizations. They tested hundreds of thousands of prompts across many industries. Moreover, the models generated millions of website links during the study. Some links already pointed to known malicious websites. Meanwhile, many other invented domains remained available for registration.
The research showed that AI models consistently create similar fake domains. Therefore, attackers can predict which domains may appear in future responses. Increasing the model’s creativity also produced more fake web addresses. However, this behavior comes from the model’s design rather than stored data. As a result, fixing the issue may be difficult.
Phantom Squatting Exploits User Trust
The attack succeeds because new domains have no security history. Therefore, reputation services and blocklists cannot immediately detect malicious activity. Attackers can abuse this short window before security tools react. Meanwhile, users often trust links suggested by AI systems. Consequently, victims may visit harmful websites without realizing the danger.
Unlike traditional phishing, this method requires no suspicious email. Instead, users receive the malicious link directly from an AI assistant. Moreover, developers may unknowingly include these fake domains in their projects. This increases the attack surface across many industries. Therefore, phantom squatting creates risks for both businesses and individuals.
Real Attacks Show the Growing Risk
Researchers observed several real-world examples of phantom squatting. In one case, AI models repeatedly generated the same fake postal service domain. However, an attacker later registered that exact address. The attacker then built a convincing phishing website. As a result, victims unknowingly shared payment details and personal information.
Another case followed a similar pattern. Researchers identified another fake postal-related domain weeks before registration. However, attackers eventually purchased the domain and copied the original website. They also promoted a malicious Android application. Consequently, unsuspecting users downloaded harmful software from what appeared to be a trusted source.
AI Output Creates New Supply Chain Risks
Researchers compared phantom squatting to earlier attacks involving fake software packages. In both cases, attackers exploit incorrect information generated by AI systems. Moreover, many developers rely on AI suggestions without verification. Therefore, fake package names and fake domains become valuable attack targets. This trend creates new supply chain security challenges.
The researchers also noted that phishing services continue to grow. Attackers now create large numbers of fake websites with little effort. As a result, AI-generated mistakes become even more dangerous. Organizations should expect similar attacks to increase. Therefore, stronger verification practices are essential.
How to Prevent Phantom Squatting Attacks
Users should always verify website addresses before entering passwords or sensitive information. Moreover, organizations should prevent AI agents from automatically opening unknown links without review. Continuous threat monitoring can identify suspicious domains before attackers exploit them.
In addition, managed detection and response services help security teams quickly investigate unusual activity and reduce potential damage. Regular security awareness training also helps employees recognize phishing attempts and avoid AI-generated fake domains.
Sleep well, we got you covered.

