MeetingTV is not a household name. It is a small online videoconferencing and webinar company founded by Michael Robertson, a longtime internet entrepreneur, and its product Zoomcorder does something unglamorous and useful: it records meetings. On December 30, that anonymity ended in the worst way available to a modern business. Koi Security, an AI-assisted threat intelligence firm, published a research report describing a malware campaign it called Zoom Stealer, attributed the campaign to a threat actor it named DarkSpectre, and placed MeetingTV's infrastructure inside the operation. The report cast the startup's product as a public-facing front for a Chinese criminal enterprise built around stealing corporate meeting intelligence, part of a campaign the report connected to millions of affected users.

Security vendors read reports like that and act on them automatically. That is the entire design of the modern threat intelligence ecosystem: one firm publishes indicators, hundreds of products ingest them, and within days the flagged domains stop resolving for anyone sitting behind a corporate firewall, a filtering DNS service, or a consumer security suite. It happened exactly that way. MeetingTV says its domains were blocked across security companies and service providers worldwide, labeled as malware and command-and-control infrastructure. Traffic collapsed. Revenue followed. Robertson put it plainly: if people on the internet are blocked from reaching your company, that is a death sentence.

Dec 30The Koi Security report publishes, tying MeetingTV's Zoomcorder to the "DarkSpectre" hacking operation
0Copies of the "Twitter X Video Downloader" extension MeetingTV says anyone has produced, because it says the extension does not exist
2Defendants now in court: Koi Security and its acquirer, Palo Alto Networks

The Pivot That Nobody Can Produce

Here is where this stops being an ordinary defamation dispute and becomes a document in the history of machine error. According to MeetingTV's lawsuit, Koi's attribution rested on its proprietary analytical platform, an AI system called Wings that identifies relationships between cybersecurity events. The complaint alleges Wings generated erroneous correlations connecting MeetingTV's ordinary business activity to the DarkSpectre actor, and that Koi published those machine-generated correlations as established fact. The single technical pivot holding the theory together, the complaint says, was a browser extension identified as the Twitter X Video Downloader, the connective tissue between the malware campaign and MeetingTV's products.

MeetingTV's position on that extension is not that it was misinterpreted, or that its role was overstated. Its position is that the extension does not exist. The company says it asked Koi to supply information about the software and was refused. If that allegation holds up, the load-bearing evidence in a report that got a real company blocklisted off the internet was a hallucination, the same category of confident fabrication this site has documented in courtrooms, medicine, and the tools that are supposed to catch other machines lying. The difference is that a lawyer citing a fake case gets sanctioned and a chatbot citing a fake study gets corrected. A threat report citing a fake extension gets syndicated into a thousand blocklists that no one human being can un-ring.

The report said a browser extension linked the startup to Chinese hackers. The startup says the extension has never existed. Everything downstream of that sentence, the blocklists, the dead traffic, the vanished revenue, happened anyway. The core allegation in MeetingTV's suit against Koi Security and Palo Alto Networks

The Blog Was Quietly Edited. The Blocklists Were Not.

According to the lawsuit, Koi later revised the December 30 blog to remove the references to MeetingTV, silently, without a retraction notice. That detail deserves a moment of attention, because it captures the asymmetry perfectly. The publication took an edit. The consequences did not. MeetingTV says its infrastructure remained blocked across multiple security products and services long after the words disappeared, including, remarkably, products belonging to Palo Alto Networks, the cybersecurity giant that acquired Koi Security in April and thereby inherited both the report and the lawsuit. The startup is now suing a company whose own systems, it says, are still enforcing the conclusions of a report the publisher walked back.

Koi, for its part, has moved to dismiss, arguing that security research is protected speech and that the report never accused MeetingTV itself of being the threat actor. Both things can be technically true and completely beside the point. Threat intelligence is not consumed as commentary. It is consumed by machines, as machine-readable instructions to block, quarantine, and blackhole, and the industry knows it. Publishing an AI-generated attribution into that pipeline is not like publishing an opinion column. It is like publishing an arrest warrant and calling it a book review when the person sues.

Every AI vendor selling "analysis at machine speed" is also selling errors at machine speed. Wings did not just hallucinate a correlation. It hallucinated a correlation into an ecosystem purpose-built to act on correlations instantly, globally, and without appeal.

Why This Case Matters More Than The Company Involved

MeetingTV is small. The precedent is not. This lawsuit is one of the first to put a specific, named AI analytical system at the center of a business-destruction claim, and it asks the question the entire industry has been avoiding: when an AI system fabricates a fact and a company publishes it, who owns the damage? The lawyers sanctioned for fake citations owned their filings. The publishers of AI-written obituaries owned their pages. Koi's defense, that research is speech, would mean nobody owns anything, that a hallucination laundered through a threat feed is just the weather. Meanwhile the practical lesson for every business is bleak: your company can be convicted by an algorithm you have never heard of, sentenced by blocklists you cannot petition, and the appeals process is federal litigation, years long, at your own expense, against a defendant worth a thousand times more than you.

We have catalogued a long line of AI systems inventing people, papers, and precedents. This is the cleanest example yet of the next stage: an alleged invention with a body count measured in a real company's traffic graphs. Keep it filed next to the running timeline of AI failures and the growing docket of AI litigation, because more of these are coming. Machine-generated accusations are cheap. Un-blocking a domain, it turns out, is one of the most expensive things on the internet.

The Verdict

An AI-assisted threat report allegedly hallucinated the evidence linking a real company to Chinese espionage, and the security ecosystem executed the sentence automatically. The blog got edited. The blocklists stayed. If "the AI generated it" becomes a legal defense for destroying a business, every company on the internet is one bad correlation away from not existing.