← All news

general

AI Hallucination Gets a Startup Blocked as Chinese Malware

2026-07-03

MeetingTV is suing Palo Alto Networks over a threat report that accused it of being the public face of a Chinese cyber espionage operation. According to the complaint, the report was largely drafted by an AI system, the AI invented key details, and Koi Security, since acquired by Palo Alto, published the results as fact.

The blog went up on 30 December. It linked MeetingTV's meeting recording tool Zoomcorder to a group Koi called DarkSpectre, alleging the startup was a front lending credibility to a malware campaign affecting 2.2 million users. The connective tissue, according to the lawsuit, was a browser extension called Twitter X Video Downloader that MeetingTV says does not exist. When the company asked Koi for details, it says Koi refused to hand anything over.

Blocked before anyone answered the phone

The fallout was immediate and, for a small business, catastrophic. Security vendors and ISPs around the world began blocking MeetingTV's domains as malware and command and control infrastructure. Founder Michael Robertson says he only discovered the report existed because his services started going dark. He has been contacting blocklist operators one at a time, mostly without response. Verizon and Palo Alto Networks are among those still blocking the company.

Robertson also notes that large language models now confidently describe MeetingTV as a Chinese cybercrime affiliate, which is the sort of reputational damage that does not easily wash out. Once a claim is in the training data, it tends to stay there.

A very careful non-apology

Palo Alto's statement is measured. The company says the research predates the acquisition, that Koi's work reflects its commitment to exposing threats, and that the dispute will play out in court. Koi has quietly edited the original blog to remove references to Zoomcorder but has not retracted it. Robertson emailed CEO Nikesh Arora directly asking for a full retraction and removal from the blocklist. He is still waiting.

The bit worth sitting with

Whether or not the lawsuit succeeds, the underlying question matters. Threat intelligence carries real weight. Being named in a public report can cut a company off from customers, payment processors and large stretches of the open internet within days. Domains go on blocklists. Search results turn hostile. Sales calls stop returning.

If the analysis behind those reports is being generated by tools that occasionally invent software that never existed, the review process before publication has to be a lot more than a quick skim. Human review is not a nice-to-have here, it is the entire point of publishing under a firm's name.

There is a broader thread too. Every organisation is now, whether it wants to be or not, at the mercy of what AI systems say about it. That includes threat reports, but also chatbot answers to customer questions, LLM summaries of company reputations, and the growing habit of using generative tools as a first-pass research layer. The MeetingTV case is a useful reminder that the confident tone of a machine is not the same as the accuracy of one.

Robertson may or may not win his case. But the block on his domains is already the punishment, and it went into effect long before any court did.

AI Hallucination Gets a Startup Blocked as Chinese Malware | RiskSense