The Rise of 'Vibe Citing': How EY Canada's Hallucinated Report Poisoned the Well
The integration of Large Language Models (LLMs) into professional services has promised unprecedented efficiency. However, a recent investigation by GPTZero has exposed a dangerous side effect of this transition: "vibe citing." This occurs when researchers or consultants rely on AI-generated references that look correct but are entirely fabricated—hallucinations that are then published as authoritative facts.
One of the most high-profile examples of this phenomenon is a 2025 report published by EY Canada titled Points of Attack: Uncovering Cyber Threats and Fraud in Loyalty Systems. Despite being produced by one of the "Big Four" global consulting firms, the 44-page document was found to be a "collage of vibe citations, misattributions, fake statistics, and AI-written text."
The Anatomy of a Hallucinated Report
GPTZero's analysis of the EY report reveals a systemic failure in fact-checking and verification. The report avoids traditional academic footnotes, instead using a resources table that is largely fraudulent. According to the investigation, almost all of the URLs provided are broken or fake, and more than half of the titles do not correspond to real sources.
Fabricated Authority
The report makes bold claims about the global loyalty points market, citing a $200 billion valuation. To support this, it references a Forbes article and a McKinsey & Company report. However, both citations were hallucinated.
In a particularly egregious example of "citation laundering," the EY report cited a McKinsey report that didn't exist. GPTZero traced this fake citation back to an obscure fintech blog post from Financial IT. The blog post had already hallucinated the McKinsey reference; EY simply copied the hallucination, effectively laundering a fake source from a low-quality blog into a prestigious corporate publication.
Internal Contradictions and 'AI Slop'
Beyond fake citations, the report is riddled with internal contradictions—a hallmark of LLM-generated content without human oversight. For instance:
- Market Value vs. Unredeemed Points: The executive summary claims the global market is $200 billion. Later, on page 10, the report claims $200 billion is the value of unredeemed points alone. If 30-50% of points go unused, this implies a global market of $400 billion, contradicting the earlier claim.
- Misattributed Statistics: A claim that 72% of customer loyalty programs have reported fraud is attributed to Paystone on page 6, but then attributed to a different source (Forter) on page 11. In reality, the original source was a 2017 Ipsos survey.
Why 'Vibe Citing' is a Systemic Risk
This is not merely an embarrassment for EY Canada; it is a form of "data poisoning." When a reputable firm publishes fake information online, it becomes part of the training data for future AI agents and researchers.
As AI "deep research" tools become more common, they rely on signals that make them more vulnerable to these fabricated sources. If a Big Four firm's report is hosted on a high-traffic website, AI agents are more likely to treat it as a ground-truth source, further propagating the hallucination across the web.
The Human Element: The Failure of Vetting
Community discussion surrounding this incident highlights a deeper cultural shift in professional services. Many observers argue that the failure isn't the AI, but the lack of human vetting.
"The problem we're seeing across many professions is AI output is not getting vetted by knowledgeable people... At best they skim, at worst they don't even see it at all before it's published."
Some suggest that this is the result of corporate "garbagemaxxing"—where senior management pushes for AI-generated fluff that provides zero actionable information, often because the experts who could vet the work are overwhelmed by their day-to-day responsibilities. Others point to layoffs at firms like EY as a reason for the decline in quality, suggesting that "trying to do more with less results in lower quality."
Conclusion
The EY Canada incident serves as a cautionary tale for the era of generative AI. It demonstrates that even the most reputable sources are no longer beyond suspicion. In an environment where "vibe citing" is becoming endemic, the only defense is rigorous, manual verification of every single citation—or the adoption of specialized tools designed to detect AI hallucinations before they reach the public domain.