AI Hallucination Brands Startup as Chinese Spy Operation. No One Checked.
A video conferencing startup has sued Palo Alto Networks and its newly acquired threat intelligence firm Koi Security, alleging that an AI-generated report falsely tied the company to a Chinese espionage campaign, and that nobody bothered to verify the claims before publishing them.
The lawsuit, filed by MeetingTV Inc., centres on a blog post Koi Security published on December 30. According to the complaint, Koi fed data into its proprietary 'Wings' analytical platform, the AI produced a string of erroneous connections between MeetingTV and a threat actor it called DarkSpectre, and Koi then dressed those hallucinations up as vetted threat intelligence.
The report originally named MeetingTV's Zoomcorder product, a meeting recording tool, as a 'public-facing front' for a Chinese criminal outfit allegedly responsible for stealing corporate meeting data from 2.2 million users. Serious accusations. The kind that tend to stick.
And stick they did. Security vendors worldwide began blocking MeetingTV's domains, flagging its services as malware infrastructure and command-and-control endpoints. MeetingTV's CEO Michael Robertson only found out because providers started cutting off access to his company's own services. Nobody at Koi had contacted him before publishing. Or after.
'I was contacting the security companies one by one asking them to unlock us,' Robertson told The Register. 'Most never respond in any fashion, but one finally did respond and told us he was blocking us because of the Koi report and he gave us the URL.'
The technical linchpin of Koi's theory was a browser extension called 'Twitter X Video Downloader', which the report described as the critical connection between MeetingTV's infrastructure and DarkSpectre's operations. There's just one problem: according to Robertson and the lawsuit, the extension does not exist. When MeetingTV asked Koi to produce evidence of this software, Koi reportedly refused.
If the central piece of evidence in a threat report is a piece of software that nobody can locate, that is not a minor methodological quibble. That is the whole thing falling apart.
Palo Alto Networks completed its acquisition of Koi in April. Robertson subsequently emailed CEO Nikesh Arora directly, asking him to retract the report, remove MeetingTV's domains from Palo Alto's own blocklists, and help get them removed from third-party lists. Palo Alto has since quietly edited the blog to remove references to Zoomcorder, but issued no retraction.
The company's official response to The Register was the usual nothing: it 'believes Koi's cybersecurity research reflects its commitment to identifying and exposing threats' and expects the dispute to be resolved through legal process. The specific questions about whether anyone checked the findings before publication went unanswered.
Robertson is blunt about what this means for his business. 'If people on the internet are blocked from reaching your company, then that's a death sentence. Plus all the LLMs now say we're working with Chinese cyber criminals. How will that ever get removed?'
That last point deserves attention. Koi's report has now been scraped, indexed, and fed into training data and retrieval systems across the web. Even if the original post were fully retracted today, the damage propagates. AI systems will continue surfacing these associations long after the humans involved have moved on.
Robertson draws the obvious broader conclusion. AI systems hallucinate. Everyone technically literate knows this. What happened to MeetingTV is what happens when that basic fact is ignored in a high-stakes context, where an AI output gets treated as ground truth and published to the world without meaningful human review or any opportunity for the accused to respond.
Security research that relies on AI-generated analysis without rigorous verification is not security research. It is defamation with extra steps.