The Tokyo Metropolitan Police Department is urging caution after confirming cases where internet search results and AI summarization features are being exploited to fabricate credibility for investment fraud groups. When victims search for the names of SNS communities or websites they were directed to by fraud groups, positive phrases such as “not a scam,” “excellent,” and “I made money” appear in search results, and AI summaries linked to search engines also display “not a scam.”
The Tokyo Metropolitan Police Department’s Cyber Security Countermeasures Division (referred to as the Cyber Crime Countermeasures Division in a separate release) disclosed this tactic on their official X (formerly Twitter) account on July 24, strongly urging the public “not to place blind trust solely in search results.” According to the announcement, after fraud groups direct victims to specific SNS groups or sites, they intentionally contaminate search engine display results so that only positive information appears when victims search for those names.
The Tokyo police did not disclose the specific technical methods used to manipulate search results. However, such attacks are generally considered a form of abuse of search engine optimization known as “SEO poisoning.” A blog post published in 2023 by JADE, an SEO consulting firm, provides a detailed explanation of a similar attack method called “site search spam.”
In this method, attackers first input large volumes of specific phrases such as “XX is not a scam” into the on-site search functions implemented on legitimate corporate or organizational websites. The site’s system then automatically generates search result pages corresponding to those search queries. The attackers subsequently post these generated URLs in large numbers on external blogs, forums, fake sites, and other locations. When search engine crawlers from Google and others follow these links and discover and index the on-site search result pages, the information appears in general web search results as if the phrase “not a scam” were published on the domain of that legitimate company.
In the cases confirmed this time, it has been pointed out that AI likely referenced these contaminated search results and generated incorrect summaries such as “not a scam.” When victims search for the names of fraud groups, the manipulated positive information appears higher in rankings than warnings from trusted third-party sites or official agencies, and AI may compile these as positive information, creating the intended effect of making victims mistakenly believe “this is not a scam.”
Following the Tokyo police announcement, cybersecurity experts have expressed a sense of crisis over the current situation where the very credibility of search engines and AI is being weaponized as a tool for fraud. Particularly in recent years, features that automatically summarize and display search results—such as Google’s “AI Overviews” and the AI summarization function built into Microsoft’s Bing—have become commonplace, and users increasingly tend to judge information without visiting individual websites. This trend has effectively become a new attack vector for fraud groups to fabricate the “endorsement of authoritative AI.”
The Tokyo police are urging that when approached with investment opportunities or money-making schemes, people should not rely solely on superficial search result information, but should cross-reference multiple trusted sources and directly check information from official agencies such as Japan’s Financial Services Agency warning lists and the Consumer Affairs Agency’s alerts. They also advise that if someone met on SNS introduces an investment group or money-making know-how, even if a search for that name yields results saying “not a scam,” people should not accept this at face value and must carefully verify the operator’s actual existence, registration numbers, location, and other details.
This tactic cleverly exploits search engines’ evaluation criteria of “information from trusted domains” and AI’s tendency to summarize phrases that “appear across multiple sources” as facts. It is extremely difficult for ordinary users to see through such manipulation, making continuous countermeasure enhancements by search engine operators essential.

AloJapan.com