Security researchers this week named a new attack technique that should worry any business using AI chatbots or AI browsing tools day to day: “phantom squatting.” It works because large language models occasionally invent web addresses that sound plausible but don’t actually exist — and attackers have started buying those exact domains before anyone else can, then loading them with phishing pages and malware.

One recent analysis tested nearly 1,000 well-known brands across hundreds of thousands of AI-generated queries and found the models invented roughly 250,000 fake domains between them. Over 13,000 of those made-up web addresses were already linked to malicious sites by the time researchers checked. In one documented case, a security team flagged a hallucinated e-commerce-style domain as high-risk 23 days before an attacker registered it and built a full phishing kit designed to steal customer payment details.

Why this is different from a normal phishing email

Traditional phishing relies on tricking someone into clicking a suspicious link in an email or text. Phantom squatting flips that around: the malicious link comes recommended by a tool the user already trusts. If an employee asks an AI assistant “what’s the login page for our supplier’s account portal?” and the model hallucinates a URL that an attacker has already registered, the AI delivers that link with total confidence — no red flags, no obvious spelling mistakes, no sense that anything is wrong.

This matters more every month as UK businesses lean harder on AI tools for everyday tasks — drafting emails, researching suppliers, even letting AI agents browse the web and take actions on their behalf. The more autonomy an AI tool has to click links and enter information without a human double-checking each step, the more damage a single hallucinated, weaponised domain can do.

What SMEs can actually do about it

Treat AI-suggested links like you’d treat a link from a stranger. Before an employee logs into a supplier portal, bank platform, or payment system via a link an AI tool has surfaced, get in the habit of checking it against a bookmarked or independently verified address. This is a small habit change that closes off most of the risk.

Ask whoever manages your AI tools whether they’re using retrieval-grounded or verified-source configurations. Business AI deployments that pull answers from a defined, trusted set of company documents rather than freely generating URLs from memory are far less likely to hallucinate a domain in the first place. This is exactly the kind of configuration question worth raising with a partner like ApplyAI if your business is rolling out AI tools without in-house technical oversight.

If your business has its own domain and brand name, consider basic defensive registration. Attackers don’t only invent domains for big household names — they target any brand an AI model might plausibly reference when answering a customer query, including regional and niche B2B brands. A quick check of common misspellings and AI-style variants of your own domain is worth an afternoon.

Keep reporting real incidents to your IT provider or KeepSafe. Because phantom squatting is new and still being mapped by researchers, individual sightings — a colleague nearly logging into a fake portal, a weird domain an AI tool suggested — are genuinely useful signal, not just a nuisance to shrug off.

The takeaway

The trust people place in AI-generated answers is exactly what this attack exploits. It doesn’t require a single mistake from your business — it only requires an AI tool guessing wrong once, and an attacker being ready when it does. The fix isn’t to stop using AI tools; it’s to keep a human verification step between an AI-suggested link and anywhere real credentials or payment details get entered.