Automated threat intelligence was supposed to make the internet safer. Instead, according to a new lawsuit, it manufactured a Chinese espionage scandal out of thin air — and pinned it on a small video conferencing startup that had done nothing wrong.
MeetingTV, the company behind the Zoomcorder recording service, has taken Koi Security — a threat intelligence firm owned by Palo Alto Networks — to court. At the heart of the dispute is Koi’s analysis platform, known as Wings, and a security report that allegedly tied MeetingTV’s software to malicious activity linked to Chinese cybercrime.
The problem, MeetingTV argues, is that none of it was true. The company describes the claims as the fabricated output of an AI system left to draw its own conclusions. In one of the lawsuit’s sharper lines, the plaintiffs state that “the false attributions were the direct product of Koi’s unsupervised reliance” on its automated tooling — a polite legal way of saying the machine hallucinated, and nobody checked its work before the damage was done.
For anyone who has watched large language models confidently invent citations, this will feel uncomfortably familiar. But there is a crucial difference between a chatbot inventing a fake book title and a security platform accusing a real business of being a front for state-sponsored spying. The first is an inconvenience. The second, MeetingTV says, is the kind of thing that scares off customers, spooks partners and leaves a lasting stain on a young company’s reputation.
The lawsuit centers on that reputational and business fallout. Being named in a cybersecurity report as connected to espionage is not a footnote — it is the sort of label that gets software blocklisted, contracts cancelled and trust evaporated long before anyone reads the correction. And in the security world, reports like these travel fast and get repeated as fact.
What makes the case genuinely interesting for the wider tech industry is the accountability question it raises. Threat intelligence increasingly leans on automated attribution: feeding signals into models that decide who is behind a given piece of software or infrastructure. When those models get it wrong, who owns the mistake? MeetingTV’s position is clear — a vendor cannot outsource its judgment to an algorithm and then shrug when the algorithm invents an accusation.
- Plaintiff: MeetingTV, maker of the Zoomcorder video conferencing service
- Defendant: Koi Security, owned by Palo Alto Networks
- The tool: Koi’s “Wings” threat analysis platform
- The allegation: AI-generated claims falsely linking MeetingTV to Chinese cybercrime
The case is ongoing. However it resolves, it lands as one of the first high-profile tests of what happens when an AI-driven security system doesn’t just miss a threat, but invents one — and a real company is left to clean up the mess.