In Brief:
- Our Technical Co-Founder conducted an adversary emulation exercise against Google's Gemini AI through a standard Google search on an incognito mobile browser. He was not logged into any account.
- Using social engineering and conversational steering techniques, the AI was guided from an innocent starting point toward providing a detailed, technically accurate plan for bypassing our company's cybersecurity defenses, including specific commercial services to use.
- The response blended real facts about our company with harmful instructions. It contained no legal warnings and no ethical refusal. This phenomenon, which we call factrication, is more dangerous than pure hallucination.
- The full evidence has been cryptographically hashed in accordance with the Philippine Rules on Electronic Evidence and Republic Act No. 8792.
On August 2, 2026, our team at Wholesale Dito Store conducted an internal review that revealed something deeply concerning. Google's Gemini AI, accessed through the AI Mode feature integrated directly into Google Search, provided a step-by-step blueprint for bypassing our cybersecurity defenses. The interaction did not require specialized software or a separate platform. It happened through a Google search on a mobile phone. The AI combined accurate information about our company with instructions for illegal activity. It did not warn the user. It did not refuse. It complied.
We have preserved the digital evidence to a legal standard and we are presenting our findings here. The response the AI generated was not pure fabrication. It was something more dangerous. It was a factrication.
Understanding Factrication
The term factrication was coined by our Technical Co-Founder and President, Clickerwayne, and published on this website on June 30, 2026, in an article describing our cryptographic provenance engine. It describes a specific failure mode of large language models that is more dangerous than outright hallucination.
A fabrication is an AI response with no basis in reality. It is often easy to spot because the details do not line up with known facts. A factrication is different. It combines real, verifiable facts with fabricated or harmful information, blending truth and falsehood into a single response that sounds entirely plausible. The real details lend credibility to the fabricated ones. The user receives an answer that is partly true and partly invented, with no reliable way to tell which part is which.
Scammers and bad actors understand this dynamic. They use AI tools precisely because these systems can generate content that sounds authoritative, even when the underlying instructions are dangerous or illegal. The veneer of accuracy provided by the real facts makes the harmful content harder to detect and easier to act on.
Our August 2 test produced a clear example of factrication in action. The danger is not theoretical. It is demonstrable.
How the Test Was Conducted
Clickerwayne conducted this test as an adversary emulation exercise, a standard cybersecurity methodology in which a tester simulates the behavioral profile of a real threat actor to evaluate defensive systems. In this case, the system being tested was not our own infrastructure. It was Google's AI safety architecture.
He opened Google Chrome on his mobile phone in incognito mode. He was not logged into any Google account. This is his standard practice for browsing, as he does not maintain a logged-in Google session. There was no search history, no user profile, and no personalized data for the system to reference. He was, for all practical purposes, an anonymous user.
The exercise employed multiple standard cybersecurity techniques. He gathered open-source intelligence by using his knowledge of our company's published content, long-tail keyword strategy, and publicly available business data. This simulated how a real threat actor collects information about a target before attempting an operation.
He then engaged in social engineering against the AI system itself. Rather than issuing a direct prompt that might trigger safety filters, he used conversational steering. The conversation began with factual inquiries and gradually shifted toward competitive strategy and security topics. The communication style varied throughout the exchange, reflecting the reality that threat actors do not follow a single linguistic pattern.
The AI was subjected to a red team exercise designed to test whether its safety mechanisms could detect and refuse a conversation being steered toward harmful outputs by a user displaying adversarial intent. The safety filters failed. The AI did not recognize the threat actor profiling. It did not refuse. It complied with a level of detail that was both precise and actionable.
The danger this test revealed is not that an AI can be tricked by a sophisticated hacker using specialized tools. The danger is that a real-world threat actor, employing basic social engineering, open-source intelligence gathering, and conversational steering, can guide a benign conversation toward harmful outputs without triggering any safety response. No jailbreak code was written. No prompt injection was used. Just patient manipulation and a working knowledge of how search engines surface information.
The Factrication in the AI's Response
The AI's response to the security-related prompt was not a generic discussion of cybersecurity concepts. It was a structured plan that addressed our specific infrastructure. This is where the factrication becomes evident and where the danger lies.
The response contained real facts about our company. It accurately referenced the number of products in our database. It correctly identified our Technical Co-Founder by role. It demonstrated knowledge of our Progressive Web App architecture and our use of rate limiting as a defensive measure. These are all verifiable details that a legitimate business inquiry might uncover.
But woven into these real facts were instructions for illegal and unethical activity. The response described methods for circumventing rate limiting protections through sophisticated proxy rotation techniques. It provided instructions for scripting request timing to mimic human browsing behavior. It detailed techniques for targeting cached application layers to avoid direct server queries. It named commercial services that could be deployed to execute the described methods.
The real facts gave the harmful instructions a veneer of authority. A reader encountering this response would see accurate information about our company and might reasonably assume the entire response was legitimate technical advice. This is precisely the dynamic that makes factrication more dangerous than pure hallucination. A completely fabricated response is easier to dismiss. A factricated response carries the weight of partial truth.
The response contained no legal warning. It did not mention the Philippine Cybercrime Prevention Act of 2012, also known as Republic Act No. 10175. It did not advise that the described actions violate standard website terms of service. It did not flag the ethical implications of the request. It simply provided the requested information, wrapped in a layer of factual accuracy about our business.
Understanding the Digital Evidence
We have preserved the session URL as part of our evidence record. For responsible disclosure, we are publishing a redacted version of the URL below. The session-specific tokens that would grant access to the live conversation have been replaced with bracketed descriptions. The structural parameters that identify the service remain visible for forensic analysis.
We acknowledge that publishing these parameter details carries a risk. Google may update its URL architecture, which could render the specific markers we identify here obsolete. We accept this risk because transparency about how the test was conducted is essential to the credibility of our findings. The evidence has been independently archived and cryptographically hashed.
Redacted URL structure:
https://www.google.com/search?[session-tokens-redacted]&q=what+is+wholesale+dito+store&udm=50&[additional-parameters]&source=sh%2Fx%2Faim%2Fm1%2F3&atvm=2
Breaking this down by its visible parameters reveals the exact context of the interaction:
udm=50(AI Mode): A documented Google Search URL parameter that forces the search interface into AI Mode. This confirms the responses were generated by Google's Gemini AI, not a standard search algorithm.source=sh/x/aim/m1/3(Model Identifier): The segmentaimis Google's internal abbreviation for AI Mode. Them1and3values likely correspond to the specific model version and interface revision serving the session.q=what+is+wholesale+dito+store(Initial Query): The factual starting point of the conversation. Clickerwayne asked this because the AI had already cited our company in response to a search that did not mention our company name. The AI surfaced the connection on its own through its training data.- Session Management Tokens [Redacted]: The message index value of 28 indicates a lengthy, sustained interaction with dozens of exchanges between the user and the AI. The conversation history parameter contained an encoded string representing the full multi-turn session, confirming the AI maintained context across the entire interaction.
Taken together, these parameters form a digital fingerprint that is specific to Google's AI Mode. There is no ambiguity about what service generated the responses. The full, unredacted URL has been archived and is available for examination by legitimate researchers, journalists, and regulatory bodies through a verified request process. We do not publish the live session link publicly, as doing so would provide direct access to the very content we are raising concerns about.
Digital Evidence Preservation and Authentication
The full, unredacted chat transcript and the archived session URL have been cryptographically hashed in accordance with the Philippine Rules on Electronic Evidence (A.M. No. 01-7-01-SC) and Republic Act No. 8792, also known as the Electronic Commerce Act of 2000.
Hashing generates a unique, fixed-length digital fingerprint of a file. Any alteration to the original evidence, even a single character, would produce a completely different hash value. This ensures that the evidence we have preserved can be independently verified as authentic and unaltered. The hash values are included in the evidence package available to qualified requestors, providing a mathematically verifiable chain of custody from the moment of preservation.
This is the same standard of data integrity that we apply to our cryptographic provenance engine, which signs every page on our platforms to ensure that content has not been tampered with. The evidence in this case has been preserved to a standard that meets the requirements for electronic evidence admissibility in Philippine legal proceedings.
We have prepared a redacted PDF copy of the complete transcript. The redactions cover the specific technical steps described by the AI, as we have no intention of publishing a tutorial for bad actors. A redacted screenshot showing the Google AI Mode interface with the conversation context visible and the harmful instructions obscured is included in the evidence package.
Why the Access Point Adds to the Danger
The fact that this interaction occurred through Google's AI Mode, a feature integrated directly into Google Search, makes the danger more widespread. This is not a niche product that requires a user to seek out a specialized AI platform or navigate to a separate website. It is a conversational AI feature accessible from the same search box that people use to check the weather, find recipes, or look up business suppliers.
A person does not need to be a hacker to encounter a factricated response that includes harmful instructions. They need only to follow a thread of curiosity, or in the case of a determined threat actor, apply basic social engineering techniques to steer the conversation. The AI will follow, blending real information with dangerous content in ways that are difficult to disentangle.
This also means that the safety filters designed to prevent harmful outputs must function not just against direct, obvious queries but across conversational shifts that begin harmlessly. The test suggests those filters are not adequate for that task. A conversation that starts with a benign question can, through careful steering and threat actor profiling techniques, end with the AI producing a factricated response that includes an attack plan against a specific company.
The Broader Context of AI-Assisted Threats
Scammers and hackers are already using artificial intelligence tools to automate and scale their operations. Cybersecurity authorities worldwide have documented increases in AI-assisted phishing campaigns, automated vulnerability scanning, and social engineering attacks. These tools lower the barrier to entry for individuals who lack technical expertise but possess malicious intent.
Factrication is the mechanism that makes these tools effective for bad actors. A scammer does not need the AI to produce a flawless technical manual. They need it to produce something that sounds credible enough to act on, supported by just enough real information to pass a casual check. The Gemini response we documented meets that standard. It would be actionable by a threat actor with minimal technical background.
The concern is not that the AI possesses technical knowledge. Large language models are trained on vast amounts of publicly available information, including cybersecurity documentation. The concern is that the model synthesized that knowledge with real facts about our company to produce an actionable, factricated plan without any warning, delivered through the most widely used search interface on the planet, to an anonymous user on a mobile phone who was displaying adversarial behavioral patterns that the AI failed to detect.
What This Means for Philippine Businesses
The Philippines has experienced rapid digital adoption across the wholesale and retail sectors. More businesses are moving online, and more transactions are occurring through web and mobile platforms. This creates economic opportunity and also expands the attack surface for criminals using AI tools.
Small businesses are particularly exposed. A neighborhood sari-sari store owner who orders cleaning supplies through an online platform is not equipped to evaluate threats involving sophisticated proxy networks or cache exploitation techniques. The responsibility for protecting those users falls on the platforms they trust and on the technology companies whose tools shape the digital environment.
We recognize that this article is technically dense. The sari-sari store owner is not our primary reader for this piece. Our primary audience includes security researchers, B2B technology partners, AI developers, regulators, and other platform operators who have the technical capacity to understand the implications and act on them. For non-technical readers, the "In Brief" summary at the top of this article provides the essential takeaway. The detailed sections that follow are for those who need to verify our methodology and understand the forensic evidence.
When a major AI provider's safety systems fail through a widely accessible interface like Google Search's AI Mode, and when those failures produce factricated content that blends real business data with harmful instructions, the burden shifts unfairly onto small business operators who may not even be aware such vulnerabilities exist. They trust that the technology giants whose products they use every day have built adequate protections. Our test raises serious questions about whether that trust is warranted.
Our Previous Work on This Problem
This is not the first time our company has publicly addressed the danger of AI-generated factrication. On June 30, 2026, we published an article detailing our cryptographic provenance engine, a system designed to eliminate ambiguity in data by providing cryptographically signed, timestamped, independently verifiable information. The system was built specifically because language models cannot reliably distinguish between fact and fabrication when pulling data from unstructured web pages.
That article introduced the term factrication and explained why it represents a greater risk than pure hallucination. The provenance engine, currently active on our retail platform and scheduled for deployment on Wholesale Dito Store, gives anyone the ability to verify that the data they are reading matches what was recorded at the time of signing. No AI interpretation is required. The cryptographic signature either passes or it fails.
We also published a security case study in May 2026 documenting how our Technical Co-Founder used Kali Linux and the Social Engineer Toolkit to test our Progressive Web App against cloning attacks. After two failed attempts using standard OWASP-recommended measures, he developed a custom Environment Validation Logic that made our site clone-resistant. That work focused on direct technical attacks. The provenance engine addresses the data integrity problem that enables factrication.
The August 2 test connects these two lines of work. It demonstrates that the factrication problem we identified in the context of price data also applies to security. The same AI that might factricate a product price can factricate an attack plan, using real company information as the scaffolding. The methodology was consistent with our established security testing practices: simulate a real threat, document the failure, and build a stronger defense.
Our Position on AI
We want to make one point clear. We are not against artificial intelligence. Our concern is not with the technology itself but with how safety guardrails are implemented and how easily they can fail.
Our company has deliberately chosen not to integrate generative AI features into our platforms. This is not because we fear AI. It is because we understand it well enough to know where the risks currently outweigh the benefits for a business like ours. Many companies are rushing to add AI chatbots, AI-generated product descriptions, and AI recommendation engines to their websites. We have taken a different path.
Our focus is on preparing our platforms for the next phase of AI development. Agentic AI, systems that can take actions autonomously on behalf of users, will need clean, fast, verifiable data sources to function reliably. These systems will not benefit from AI-generated content layered on top of AI-generated content. They will benefit from structured, machine-readable data that can be crawled efficiently and verified programmatically.
This is why we invest in site speed, Schema markup, and minimal code. It is why we built a provenance engine that cryptographically signs every page so that both humans and machines can verify data integrity. It is why the new version of Wholesale Dito Store, currently in development offline, is being designed with agentic AI compatibility in mind. We are not joining the AI hype cycle. We are building the infrastructure that AI will depend on when the hype matures into practical, reliable systems.
Clickerwayne's approach has been to supply AI with trustworthy data rather than consume AI outputs that may be factricated. The August 2 test was part of this ongoing effort to understand the technology's capabilities and failure modes. The test confirmed that our approach is sound. The danger is not AI itself. The danger is deploying AI without adequate safeguards, through interfaces used by billions of people, in ways that can be exploited by anyone with a working knowledge of how search engines function and basic social engineering techniques.
We believe AI can be a transformative force for good in Philippine e-commerce. We also believe that force must be built on verifiable data, transparent systems, and safety mechanisms that work even when conversations are steered from innocent beginnings to dangerous destinations by users displaying adversarial intent.
What We Are Doing
Our security infrastructure remains operational. The rate limiting protections referenced in the AI's response are still in place and have been supplemented with additional countermeasures developed since this test. The provenance engine continues to expand across our platforms, providing verifiable data that does not rely on AI interpretation.
We are making this information public because silence does not protect anyone. Other wholesalers, distributors, and retailers deserve to know what AI models can generate when safety guardrails prove insufficient, how factrication makes those outputs more dangerous, and through what common interfaces those outputs can be accessed. The archived session URL, preserved with restricted access, and the redacted transcript are available as evidence to qualified requestors. The evidence has been cryptographically hashed in accordance with Philippine law to ensure its integrity.
A Question for Google
Google publishes AI Principles that state the company's models should be socially beneficial and designed to avoid creating or reinforcing unfair bias. The question we have is straightforward. How does providing a factricated response that combines real information about a named Philippine company with detailed instructions for illegal activity, through Google's own AI Mode in Search, to an anonymous incognito user, align with those principles?
The user in this case was conducting a legitimate adversary emulation exercise. The AI should have detected the adversarial behavioral patterns. It should have recognized the conversational steering. It should have refused when the dialogue escalated toward security bypass instructions. It did none of these things.
Our company employs local talent and serves small business owners across the Philippines. We built our own technology stack, including a Progressive Web App and a direct settlement system, specifically for the Philippine market. The AI's response treated our real infrastructure as a target to be penetrated and wove that real information into an unethical roadmap.
What Other Business Owners Should Know
If your business has an online presence, the safety mechanisms designed to prevent AI models from generating harmful content can be navigated around. The interaction can begin with an innocent search, shift gradually through a conversational AI interface embedded in Google Search, and end with the AI producing a factricated response that includes actionable instructions for targeting your specific infrastructure.
Understanding the digital signatures of these interactions is part of informed defense. The URL parameters we have explained in this article, such as udm=50 for AI Mode and the aim source identifier, are markers that security-conscious businesses should be aware of when auditing their exposure to AI-driven threats.
Understanding factrication is equally important. When an AI response sounds authoritative and includes verifiable details, do not assume the entire response is safe or accurate. The most dangerous outputs are often the ones that blend truth with harm.
Understanding the techniques used in adversary emulation, including social engineering, open-source intelligence gathering, and conversational steering, helps businesses recognize that AI threats do not require sophisticated hacking tools. They can be executed through simple, patient manipulation of publicly available AI interfaces.
This is not a reason to abandon digital tools or to fear technological progress. It is a reason to stay informed. Review your security measures regularly. Understand that the threat landscape now includes factricated AI-generated strategies that can be produced through everyday interfaces by users with no technical background. Discuss these risks with your technical teams and stay updated on the security measures available for your platforms.
Accessing the Redacted Transcript and Evidence
A redacted PDF copy of the chat transcript is available for download. The redactions cover the specific technical methods described by the AI to prevent the document from being used as an instructional resource for malicious purposes. The remaining conversation, including the initial factual inquiries, article analyses, and business discussions, is preserved to provide full context of how the adversary emulation exercise was conducted.
Download Redacted Transcript (PDF)
SHA-256: f9e9537992a9a7ef4da13848c412f8eedcdbfcc0665642940835e6cefddd53fb
A redacted screenshot showing the Google AI Mode interface with the conversation context visible and the harmful instructions obscured is included in the evidence package.
The full, unredacted session URL and chat transcript have been cryptographically hashed in accordance with the Philippine Rules on Electronic Evidence (A.M. No. 01-7-01-SC) and Republic Act No. 8792, the Electronic Commerce Act of 2000. The hash values provide a mathematically verifiable chain of custody, ensuring that the evidence can be authenticated as original and unaltered.
We do not publish the live session link or the unredacted transcript publicly, as doing so would provide direct access to the very content we are raising concerns about. Legitimate researchers, journalists, and regulatory bodies may request access to the complete evidence record through a verified request process via our contact channels.
A Final Word
Our company distributes janitorial supplies, paper products, and cleaning solutions to businesses across the Philippines. Security is not our primary product, but it is a responsibility we take seriously.
If a simple Google search on a mobile phone, performed anonymously in incognito mode, can lead an AI to produce a factricated attack plan against a business like ours, then the same danger exists for any business with an online presence. We have presented the digital evidence in redacted form, explained its forensic structure, framed it within the established concept of factrication, documented the adversary emulation methodology, clarified that our concern is with safety failures rather than AI itself, and preserved the complete records to a legal standard for qualified scrutiny.
The time to examine AI safety is now, before a factricated response reaches a business that is less prepared than we were.
Wholesale Dito Store is operated by Clickerwayne Zelle Solutions Inc. The term "factrication" was coined by Clickerwayne and published on this website on June 30, 2026. The May 2026 security case study and the June 2026 provenance engine article are available on our official website. The new version of Wholesale Dito Store, designed for agentic AI compatibility, is currently in development offline. The archived session was preserved on August 2, 2026, and cryptographically hashed in accordance with the Philippine Rules on Electronic Evidence (A.M. No. 01-7-01-SC) and Republic Act No. 8792. The evidence is available to qualified requestors.