Submit incident
Documented

Google's AI Search Became a Referral Service for Malware and Scams

January 1, 2024
Curated by Team Raidu · Reviewed by Shiva Ganesh
aiaaic:AIAAIC1412View source ↗
LinkedInX

What happened

In March 2024, Google's Search Generative Experience (SGE) was recommending malicious websites to users as part of its AI-generated conversational answers. The system, later rebranded as AI Overviews, had surfaced sites hosting malware and operating scams, embedding them inside a feature designed to save users the step of evaluating links themselves.

SEO consultant Lily Ray was among the first to document the problem publicly. The flagged sites shared identifiable characteristics: they clustered around the same .online top-level domain, used identical HTML templates, and deployed redirect chains designed to ferry visitors away from the initial URL before anyone realized they had left a legitimate-looking page. These patterns are consistent with coordinated SEO poisoning campaigns, where operators bulk-manufacture sites that game ranking signals without serving any real content.

Following the redirects leads to scam infrastructure built for maximum confusion. Users land on pages serving fake CAPTCHA prompts, spoofed YouTube pages, and fake giveaway forms, each designed to extract a click, a credential, or a small payment before the visitor understands what they are looking at. The AI-generated summary that surfaced the original link gave no indication that anything was wrong. To a user trusting the answer the model composed, the recommendation appeared as authoritative as the system delivering it.

Google stated that it continuously updates its systems and algorithms to detect spam. That response does not address the specific failure the incident exposed. Spam detection in traditional search operates on links users actively choose to visit. AI-generated answers work differently: they synthesize and endorse links inside a narrative the model presents as considered. When that output treats a poisoned domain as a source worth citing, it adds a layer of apparent credibility that a plain search ranking does not supply, and strips the user of the skepticism a bare list of results normally invites.

What is absent from this incident is any way to trace how those sites ended up in AI-generated answers, whether anyone reviewed the citation logic, or what specifically changed after Ray's findings circulated. Google's public position described an ongoing process with no verifiable specifics. A provable record of what a system cited, why, and when it was last checked against known bad-actor domains would make that kind of response testable rather than merely asserted. Without it, the fact that a search engine steered millions of users toward malware for weeks before external researchers noticed stands documented only as an observation, not as a problem anyone was ever made accountable for solving.

Reported impact

Affected parties
Not publicly disclosed
Harm type
Not publicly disclosed
Scale
Not publicly disclosed
Financial impact
Not publicly disclosed
Regulatory action
Not publicly disclosed

Classification

Organization
Not publicly disclosed
AI system
Not publicly disclosed
Industry
Not publicly disclosed
Country
Not publicly disclosed
Provider
Not publicly disclosed
Incident type
Not publicly disclosed

Relevant governance controls

Governance control mapping is not available for this record.

  • No controls mappedNot publicly disclosed

Control mapping is analytical. It does not state that any control would have prevented the incident.

Sources and evidence

This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.

AIAAIC Repository
Also catalogued in
Google's AI Search Became a Referral Service for Malware and Scams
2024