Ask ChatGPT where to log into your company’s customer portal.
Do it a few times, in a few different phrasings, and sooner or later it hands back a URL that looks plausible and does not exist.
Criminals run the same exercise at scale and register the answers.
What Unit 42 Found
Palo Alto Networks’ Unit 42 published the numbers in June. They ran 913 global brands through two families of large language models, 685,339 prompts in all, and collected 2.1 million URLs from the responses. 809,455 of those pointed at domains that did not exist. The models made them up. That is what these systems do when they don’t know something: they produce a confident, plausible answer. A confident, plausible domain name is a specific kind of dangerous.
You may know this, but AI hallucinations do not happen randomly. The same model, asked the same kind of question, invents the same domain again and again. Researchers call these high-persistence hallucinations. Attackers call them a product roadmap.
Cybernews covered the findings on July 1, counting more than 13,000 confirmed malicious URLs with roughly 250,000 hallucinated domains still sitting unregistered:
“Models trained on human-authored corpora will naturally hallucinate plausible-sounding domains for brands, products, and services based on internal linguistic patterns,” the researchers said.
Unit 42 called that pool of unregistered names “a significant opportunity for adversaries to exploit the software supply chain through preemptive registration.”
And that means, a quarter million pre-approved phishing domains, waiting for a twelve dollar checkout.
The Playbook Is Already Running
Monitor what the models say.
Find the invented domains that keep recurring for a valuable brand.
Register them and stand up a credential harvesting page.
Unit 42 watched a domain resembling a national postal service’s e-commerce marketplace surface as a persistent hallucination on March 8. On March 31, someone registered that exact name and had a phishing operation running on it. Twenty-three days from model output to live attack infrastructure. By early July the technique had a name, phantom squatting, and the first campaign reports followed.
Why Your Brand Protection Program Misses It
This is worse than ordinary typosquatting. Here’s why.
Every brand protection program ever built starts from the same assumption:
You can enumerate the names that matter.
You register the obvious variants, and your monitoring service watches permutations of the domains you own, swapped letters, added hyphens, alternate TLDs. All of it is anchored to names a human could derive from yours.
Phantom squatting breaks the assumption.
The domain came out of a statistical process, with no connection to any name you own, and it matters only because that process keeps directing people to it. Your users asked a tool they trust a reasonable question. Nobody mistyped anything. Nothing in your SOC sees this, because the domain is not on your infrastructure, and there is no traffic to inspect until your customers, or your employees, arrive at it with credentials in hand.
(In the early 2000s we fielded calls from customers holding official-looking “expiration notices” that were slamming attempts, transfer forms dressed up as renewal invoices. The layer under attack is always the one nobody in the org chart owns.)
Nobody Owns Domains That Don’t Exist Yet
Ask who in your company is responsible for them. Marketing owns the brand. Security owns the perimeter. Legal owns the trademarks. The intersection of all three, the domain layer itself, reports to nobody. That intersection is where this entire attack lives.
What to Do About it
Interrogate the models yourself.
Ask the major LLMs for your login pages, support portals, and download sites, repeatedly and in varied phrasings. The recurring inventions are your exposure list. This costs nearly nothing and almost nobody does it.
Watch registrations, not just permutations.
Monitoring that only scans variants of your existing names will not catch a hallucinated domain. You need visibility into the new-registration stream, scored against your brand. Unit 42 clocked the average gap between a name’s first appearance in model output and its registration by an attacker at 51 days. That is a seven-week head start for whoever watches.
Register the persistent ones before someone else does.
Twelve dollars per domain, weighed against a credential harvesting campaign aimed at your customers. The math is not hard. Criminals would rather pay the $12.
Lock down your real estate.
A phantom domain is worthless to an attacker who can hijack your real one instead. Registry locks, DNSSEC, hardened registrar accounts. If chatbots send people to your actual domain and your actual domain has been redirected, the two problems compound.
The Short Version
A new discovery channel now sits between your customers and your infrastructure. It makes things up, and criminals have industrialized the harvest. Your attack surface is no longer limited to the domains you own, or even the domains that exist. It includes every plausible name a machine might dream up on your behalf.
We have looked after mission critical domains since 1998, over 130,000 of them at last count. The machines rely on the domain layer now too, and they don’t check whether any of it is real. The postal service domain went from hallucination to phishing kit in twenty-three days. Somewhere in a model’s output right now, there is a plausible domain with your brand on it.

