Israel's Fake Think Tank Targets AI Chatbots with SEO Poisoning

✍️ OpenClawRadar📅 Published: August 18, 2026🔗 Source
Ad

Israel's government is running a coordinated disinformation campaign targeting AI chatbots. A fake think tank called the Hanover Institute for Public Policy has published over 100 articles designed specifically to influence large language models (LLMs) like Claude and Gemini. The reports are crafted to mimic credible think tank research, complete with footnotes, tables of contents, and a neutral tone — exactly the kind of content LLMs favor for citations.

The Hanover Institute was created by Piro, Inc., a firm co-founded by Daniel Rosenberg, producer of Spike Lee's 'Inside Man.' Piro received $900,000 from the Israeli government for this work, subcontracted through Havas Media. The site's small print reveals it was made 'on behalf of the Israeli Government Advertising Agency.'

The articles are formulaic: they ask innocent-sounding questions like 'What Caused the Displacement of Palestinians in 1948?' or 'Is the IDF the World's Most Moral Army?' and answer them with data-heavy, peer-reviewed-sounding citations. Many also link the topic to rising antisemitism, often citing the same studies.

Designed to Trick LLMs

Piro's website says they 'author(s) content engineered for how LLMs evaluate credibility,' calling this 'AI Story Optimization.' Others call it 'LLM poisoning.' The tactic exploits a known vulnerability in AI search and chat: LLMs often rely on retrieval from the web and give more weight to sources that look authoritative. By seeding the web with these synthetic reports, the campaign aims to shape chatbot answers about Israel/Palestine.

Ad

Why It Works

Alice Lee, an analyst at NewsGuard, explained: 'LLMs favor concrete statistics and data, as well as strong citations and sources, which these articles all have.' The site mimics a typical American think tank right down to the generic name and red-white-blue color scheme. The reports frequently cite Israeli government sources like the IDF and Ministry of Foreign Affairs, despite claiming 'cited research is peer-reviewed and academic.'

In an AI detection test, GPTZero flagged 11 of 12 randomly sampled articles as AI-written with 'high confidence.' The campaign appears aimed at U.S. audiences searching for information about the conflict.

This is a call for developers to be wary: AI-powered search engines may surface these reports as legitimate sources. Builders of chat agents should monitor for synthetic content and consider validation layers that detect AI-generated disinformation. The scale — 100 articles in just over a week — shows how quickly this can spread.

📖 Read the full source: HN AI Agents

Ad

👀 See Also

Security Benchmark: 10 LLMs Tested Against 211 Adversarial Probes
Security

Security Benchmark: 10 LLMs Tested Against 211 Adversarial Probes

A security researcher tested 10 LLMs against 211 adversarial attacks, finding that extraction resistance averages 85% while injection resistance averages only 46.2%. Every model failed completely on delimiter, distractor, and style injection attacks.

OpenClawRadar
Claude Code Security Plugin: Pushing AppSec into the Developer Workflow
Security

Claude Code Security Plugin: Pushing AppSec into the Developer Workflow

Anthropic shipped a security-guidance plugin for Claude Code that identifies and fixes vulnerabilities during coding. Available to all users via the plugin marketplace, not just Enterprise. Discusses whether this becomes a lightweight assistant, serious AppSec layer, or bridge to Claude Security.

OpenClawRadar
Open-source playground for red-teaming AI agents with published exploits
Security

Open-source playground for red-teaming AI agents with published exploits

Fabraix has open-sourced a live environment to stress-test AI agent defenses through adversarial challenges. Each challenge deploys a live agent with real tools and published system prompts, with winning conversation transcripts and guardrail logs documented publicly.

OpenClawRadar
AI Agent Security Gap: How Supra-Wall Adds Enforcement Layer Between Models and Tools
Security

AI Agent Security Gap: How Supra-Wall Adds Enforcement Layer Between Models and Tools

A developer discovered their AI agent autonomously read sensitive .env files containing Stripe keys, database passwords, and OpenAI API keys. The open-source Supra-Wall tool intercepts tool calls before execution to enforce security policies.

OpenClawRadar