Judging AIJuly 11, 2026·4 min read

AI Makes Up URLs. Attackers Are Registering Them.

Unit 42 tested 685,339 prompts and found 2.1 million AI-generated URLs — 13,229 already live and malicious. In one case, researchers predicted which domain an AI would hallucinate. Twenty-three days later, an attacker registered it and deployed a phishing kit.

By Patin Team · Examples are illustrative composites

When an AI gives you a link — to a government form, a vendor portal, a research tool — you expect either the real site or a 404. Unit 42, Palo Alto Networks' threat intelligence team, found a third outcome: the URL resolves, and an attacker is on the other end.

What happened and why it matters

Unit 42 tested 685,339 prompts across 913 brands and collected every URL the AI models produced — 2.1 million of them. Of those, 13,229 were already live and malicious: phishing kits, credential harvesters, malware landing pages. In one case, researchers predicted which specific postal-service domain an AI would consistently hallucinate. Twenty-three days later, an attacker registered that exact domain and deployed a phishing kit (Unit 42 / Hacker News, June 30).

This works because AI models don't fabricate random strings. They produce plausible URLs — domains formatted like government portals, software documentation pages, or vendor login screens. Attackers monitor which patterns AI models reliably suggest, then register the unclaimed ones before anyone clicks through.

The result is a link that looks correct, resolves to a real site, and routes you to an attacker — not because the AI made an obvious error, but because it made a convincing one.

What to do differently on Monday

Three rules that take under 60 seconds each:

Never click a URL from an AI response directly. Copy the domain, search for it independently, and confirm you are on the right site before entering credentials or downloading anything.

If you need a government portal, a vendor login, or a specific tool, search for the organisation first and find the link from their verified homepage. Don't let the AI skip that step for you.

If your team uses AI to compile vendor lists, competitive research, or tool recommendations that get shared with others, note where each URL was verified — not just where the AI cited it.

None of these require technical skill. They require one habit: treat AI-generated URLs as leads to check, not sources to trust.

Sofia: the content strategist who forwarded the list

Sofia runs content strategy at a 70-person B2B software company. She uses AI to research competing tools for quarterly benchmark reports that go to the sales director and occasionally to enterprise prospects.

Her process is fast: give the AI a category, get a list of tools with descriptions and links, skim for completeness, format the report. The AI's descriptions are accurate. The tools exist. She has no reason to doubt the URLs.

Under the Unit 42 pattern, one of those links could be a registered lookalike — a domain formatted like the real vendor's portal, live, with a plausible landing page. Sofia clicks through as part of her review. If the site asks her to log in to "continue to the tool overview," her company credentials go somewhere they shouldn't.

The report looked clean. The risk was invisible.

Ravi: the operations manager filing a compliance request

Ravi is an operations manager at a 180-person logistics firm. He uses AI to find the right government portals for carrier filings, permit renewals, and customs documentation — processes that are genuinely complex and underdocumented online.

He recently asked for the link to a freight carrier compliance portal. The AI gave him a URL with the right agency name and the right country code — but ending in .net rather than .gov. He didn't catch it. He started filling out the form.

The real portal is on a .gov domain. The hallucinated one, registered the previous month, was a credential harvester built to look like a government form. Ravi caught it before submitting only because the confirmation page after clicking "submit" had no case number and a generic success message. He spent two hours with the agency's IT team reporting the site.

The AI wasn't wrong about which form he needed. It was wrong about where that form lived — confidently, convincingly wrong.

The one-sentence version

AI doesn't hallucinate nonsense URLs — it hallucinates plausible ones, and someone is already watching which domains get suggested most.

<BlogPracticeSection />

Reading about it only gets you so far

Patin turns this into five-minute drills that score what you write and tell you why. It's in closed beta — join the waitlist and we'll email you when your cohort opens.

Just want the writing? .