AUTO-UPDATED

Ernst & Young published cybersecurity report full of hallucinations

Ernst & Young’s 2025 cybersecurity report is facing scrutiny after GPTZero identified widespread use of "vibe citing," a practice involving fabricated citations and inaccurate statistics generated by artificial intelligence.

Key Points

  • GPTZero’s Hallucination Check tool identified numerous fake references and contradictory statistics within the 44-page EY Canada report, Points of Attack.
  • The report contains broken or non-existent URLs and misattributed data, including fabricated citations from McKinsey & Company and Forbes.
  • EY Canada’s report has been syndicated across more than 60 Australian newspapers, demonstrating how flawed data can spread through legitimate media channels.
  • AI-powered search tools, such as ChatGPT and Perplexity, are currently surfacing these hallucinations, effectively poisoning the data pool for future researchers.
  • GPTZero is now using its detection technology to screen submissions for major academic conferences, including NeurIPS, ICLR, and IJCAI.

Why it Matters

The prevalence of "vibe citing" in professional reports threatens the integrity of the digital information ecosystem by injecting false data into the training sets used by AI models. When reputable firms publish AI-generated misinformation, it creates a cycle of data poisoning that misleads both human researchers and automated research tools.
Gptzero.me Published by Om Ogale, Paul Esau, Alex Cui
Read original