Fake AI Subscription Sites Threaten Enterprise Data Security
Share
More than 100 fraudulent websites are impersonating reputable artificial intelligence (AI) services to sell fake subscriptions, potentially exposing sensitive enterprise data to unknown actors, according to researchers at Malwarebytes.
Impersonation of Popular AI Brands
The malicious sites target well-known products, including GPT-6 Astra, DaVinci Resolve, PixAI, and OpenCut. Some fraudulent sites also impersonate defunct services, such as the chat platform Omegle, which ceased operations in 2023.
These websites appear professionally designed and use genuine Google authentication processes to build credibility. By inviting users to “Sign in with Google”, the sites appear legitimate while charging fees ranging from $10 per month to as much as $2,000 for annual access.
Risks to Enterprise Data and Shadow IT
Malwarebytes researchers noted that while the sites do not appear to use fake password forms or push malware downloads directly, they pose a significant risk through data harvesting. Some sites encourage users to upload documents, recordings, or other files to “unlock” the advertised AI services.
This creates a substantial risk for organisations through “shadow IT”, where employees may attempt to purchase low-cost tools for departmental use without involving the IT or security departments. When users upload sensitive corporate information to unverified services, there is no way to ensure where that data is ultimately stored or how it is used.
Technical Tactics and Detection
The fraudulent sites leverage the legitimate Google consent screen to request basic information, such as a user’s name, email address, and profile picture. Although these sites typically do not request access to Gmail or Google Drive, they mask their true identity through the developer contact information provided during the authentication process.
Malwarebytes found that the developer contact details displayed on the Google consent screen used free webmail addresses rather than the official corporate domains associated with the impersonated AI brands. Researchers suspect the campaign is being managed by a single entity or group, as the websites were built using the same commercial website creation kit and share closely related developer email addresses.
Mitigation Strategies
To defend against these scams, users should look beyond a website’s visual polish and familiar authentication options. Malwarebytes recommends verifying the company’s identity and checking the developer details shown during the Google sign-in process.
Users should avoid uploading sensitive documents or recordings to any AI service that cannot be independently verified. Additionally, individuals can manage their security by reviewing and removing untrusted third-party connections within their Google Account settings.




Leave a Reply