EY Canada Report Full Of Fake Citations, GPTZero Finds

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- EY Canada published a 44‑page cybersecurity report titled Points of Attack: Uncovering Cyber Threats and Fraud in Loyalty Systems in late 2025, credited to two partners and a senior manager.
- The report’s resources table (pages 41‑43) lists source titles, descriptions, URLs, publishers and dates, but over half the titles have no real counterpart and most URLs are broken or fake.
- GPTZero’s Hallucination Check identified the report’s “vibe citations” as hallucinated references, and a team member manually verified the findings.
- The report is being quoted in newspapers, blog posts and AI search overviews, spreading inaccurate data that both human researchers and AI agents rely on.
- EY Canada provides millions of dollars of services to the Canadian government each year, meaning the flawed report risks misallocation of public‑sector resources.
Why it matters: The Canadian government risks basing security decisions on bogus data, while GPTZero’s validation service gains demand; millions of dollars in public contracts risk misallocation.




