koi
– Koi Security

Palo Alto Networks and its new acquisition, Koi Security, are facing legal action after a firm alleged AI hallucinations were used in a security report falsely accusing it of Chinese cyber-espionage – while possibly inflating the value of Koi's $400 million acquisition.

According to court documents seen by The Register, videoconferencing player MeetingTV is contesting a blog published by Koi in December accusing its domain and Zoomcorder service of being fronts for Dark Spectre, a China-linked threat actor behind malware which has reportedly infected over 8.8 million users to date.

In the same document seen by this title, MeetingTV's counsel claimed the blog was released during Koi’s active acquisition negotiations with Palo Alto to showcase the capabilities of the endpoint vendor’s Wings AI platform.

"By manufacturing a sensational narrative of a massive Chinese espionage operation – and positioning Wings as the only solution capable of detecting it – Koi sought to inflate its valuation and generate sales leads. This strong economic incentive further supports an inference of reckless disregard," MeetingTV claimed.

A swim in "AI slop"?

The claimant also accused Koi of publishing "unverified AI-generated conclusions" drawn from its Wings suite, while "recklessly" disregarding that "such AI-assisted systems are widely recognized in the cybersecurity industry as prone to “hallucinations, false positives, and phantom linkages."

"Despite this well-established risk, Koi published [its conclusions] as definitive investigative fact without adequate human oversight, basic attribution checks, or even contacting [MeetingTV] prior to publication," the suit reads

In dispute is an X (formerly Twitter) extension which Koi alleged was harvesting meeting intelligence from almost 30 videoconferencing platforms, including Zoom, Google Meet, and Microsoft Teams. Dubbed Zoom Stealer, it alleged the breach had affected 2.2 million users.

MeetingTV alleges the extension is "non-existent" and did not appear among the extension IDs listed in the report itself, and Koi "refused to supply information on when requested."

Such alleged hallucinations, it claimed, extended to the accusations around its Zoomcorder product.

CEO to CEO

The court filing also includes an email sent in April by MeetingTV CEO Michael Robertson to Palo Alto Networks CEO Nikesh Arora after Robertson reportedly had not heard from Koi following his protests.

In the email sent a fortnight after the Koi deal closed, Robertson asked Arora to take down the "false report" and remove its domains from Palo Alto's own blacklist as well as those blocking it in the aftermath of the Koi report.

This list includes Cloudflare, Fortinet, and Cisco Talos, which all classified MeetingTV-related domains as being malicious or malware. According to The Register, these blacklistings were what alerted MeetingTV to the Koi report, which has since been updated to remove mention of MeetingTV. The original can still be viewed via the Wayback Machine.

While perhaps unique in the security software space, accusations of Chinese espionage are not uncommon in the hardware space. It was revealed in November that TP-Link Systems was suing fellow network equipment vendor Netgear after the latter allegedly accused it of being "infiltrated" by Chinese authorities.

The Federal Communications Commission (FCC) meanwhile has been stepping up security on Chinese-made network equipment.

AI hallucinations are also a threat in the autonomous networks space, with NTT DoCoMo warning AI-generated slop can impact service availability in operational environments.