The report that should not have existed

On December 30, 2025, Koi Security published a report titled "DarkSpectre: Unmasking the Threat Actor Behind 8.8 Million Infected Browsers." The document identified MeetingTV — an American videoconferencing and webinar startup — as part of a large-scale Chinese criminal operation. The problem: the link was false, generated by Koi proprietary AI system called Wings, and published without adequate human verification.

MeetingTV founder Michael Robertson describes what happened next: "We have expended considerable effort to get unblocked. It is laborious and often impossible because there are hundreds of lists, and it is unclear which connectivity companies or businesses use which security company."

The automatic cascade

Once published, the report propagated automatically through the cybersecurity community. Corporate firewalls, security products, and defense contractors worldwide began blocking traffic to MeetingTV domains. The company describes in its complaint "a catastrophic collapse in online visibility, operational disruption, and severe damage to revenue and reputation — which effectively destroyed business continuity."

At the center of the hallucination: the Koi report repeatedly cited a browser extension called "Twitter X Video Downloader" as the "critical bridge" connecting the Zoom Stealer campaign to DarkSpectre infrastructure. MeetingTV alleges this extension simply does not exist among the IDs listed in the report — pointing to an AI-generated error or fundamental flaw in Koi analysis.

The late and ineffective correction

On February 12, 2026, Koi added an update at the bottom of the report stating there was "no evidence that this domain is connected or related in any way to the malicious infrastructure." It did not update the title or indicate the correction at the top of the article. MeetingTV argues the correction came too late — the original report had already been widely disseminated and incorporated into hundreds of security products. Palo Alto Networks acquired Koi in April 2026 and was added as defendant in the amended complaint.

The precedent being set

The case raises three questions the industry has not formally answered: How much human oversight is required before publishing AI-generated security analyses? Who is responsible when an automated report circulates and causes damage before correction? And how do you undo cascade blocks once an entity is flagged as malicious across hundreds of distributed systems?

Ironically, MeetingTV own attorneys used AI to prepare the petition — and certified they independently verified every legal citation and factual assertion.


Primary sources:
- Axios: axios.com
- The Register: theregister.com
- Inc. Magazine: inc.com
- TechRadar: techradar.com