AI detection firm GPTZero published an investigation in May, revealing that a 44-page cybersecurity whitepaper from EY Canada, released in late 2025, was riddled with fabricated content. The report, titled Points of Attack: Uncovering Cyber Threats and Fraud in Loyalty Systems, focused on loyalty program security. GPTZero cross-checked all 27 cited references and found 16 were AI hallucinations—either nonexistent or completely made up. Over 72% of the document's text was flagged as AI-generated.
How GPTZero Uncovered the 16 Phantom References
The report lacked academic footnotes; instead, it listed sources in a table on pages 41–43, including titles, descriptions, URLs, and some publishers and dates. The problem was pervasive: almost all URLs were dead or never existed, and more than half of the source titles didn't match any real publication. GPTZero engineers coined the term vibe citing to describe researchers or consultants who skip verifying sources and let AI generate references, producing entries that look legitimate but are entirely fabricated.
The $200 Billion Contradiction and Fake Citations
The most glaring issue was a numerical inconsistency. The executive summary claimed the global loyalty points market was worth $200 billion, adding that 30%–50% of points are never used. Page 10, however, redefined that $200 billion as the value of unredeemed points. If 50% of points are unredeemed and already worth $200 billion, the total market would be at least $400 billion—a clear contradiction. Each of these two figures had a citation: one fake Forbes article and one fake McKinsey report. GPTZero tracked down the supposed “McKinsey & Company: Loyalty Economics Report (2022)” but found no such document. Six months earlier, a Financial IT blog post contained nearly identical phrasing, also citing this fake McKinsey report.
Citation Chain Poisoning: From Obscure Blog to Big Four
GPTZero described this as citation chain poisoning—someone first created a fake academic reference in a low-traffic blog, then EY's report laundered it into a credible Big Four publication. GPTZero has built an automated pipeline to scan public reports from major consulting firms; preliminary data suggests vibe citing is an epidemic, affecting even industry leaders. The firm also warned of data poisoning: uploading false information into the public knowledge pool misleads future researchers and decision-makers. Since EY Canada provides millions of dollars in audit and consulting services to the Canadian government annually, and the PDF was hosted on a high-traffic official site, the damage spreads faster and trust is harder to repair. The report has already rippled through Australian media, with a Canberra Times article that cited it being syndicated to over 60 local newspapers.
GPTZero tested Claude, ChatGPT, and Perplexity on questions like “average detection time for loyalty program fraud” and found all three AI tools citing the hallucination-ridden EY report. AI research tools rely heavily on brand signals, making them more vulnerable to such poisoning. GPTZero's hallucination detection tool is already used by top conferences like IJCAI, ICLR, and ICSE to screen paper submissions. The company has previously checked government documents and two Deloitte reports.
Following the investigation, EY Canada removed the whitepaper from its website and issued a statement: “EY Canada takes seriously the accuracy of all content we publish and has an organization-wide commitment to responsible use of AI. We are reviewing how this report was issued.” A global audit giant entrusted its brand credibility to a language model that didn't even bother to verify citations—only to be caught by a three-person startup. This is not an isolated case; it reflects a broader trend where professional judgment is replaced by AI generation, and brand endorsement itself becomes the riskiest citation of all.

