Download Privacy Needle App

Type to search

Cybersecurity

Fake AI Subscription Sites Threaten Enterprise Data Security

Share

More than 100 fraudulent websites are impersonating reputable artificial intelligence (AI) services to sell fake subscriptions, potentially exposing sensitive enterprise data to unknown actors, according to researchers at Malwarebytes.

Impersonation of Popular AI Brands

The malicious sites target well-known products, including GPT-6 Astra, DaVinci Resolve, PixAI, and OpenCut. Some fraudulent sites also impersonate defunct services, such as the chat platform Omegle, which ceased operations in 2023.

These websites appear professionally designed and use genuine Google authentication processes to build credibility. By inviting users to “Sign in with Google”, the sites appear legitimate while charging fees ranging from $10 per month to as much as $2,000 for annual access.

Risks to Enterprise Data and Shadow IT

Malwarebytes researchers noted that while the sites do not appear to use fake password forms or push malware downloads directly, they pose a significant risk through data harvesting. Some sites encourage users to upload documents, recordings, or other files to “unlock” the advertised AI services.

This creates a substantial risk for organisations through “shadow IT”, where employees may attempt to purchase low-cost tools for departmental use without involving the IT or security departments. When users upload sensitive corporate information to unverified services, there is no way to ensure where that data is ultimately stored or how it is used.

Technical Tactics and Detection

The fraudulent sites leverage the legitimate Google consent screen to request basic information, such as a user’s name, email address, and profile picture. Although these sites typically do not request access to Gmail or Google Drive, they mask their true identity through the developer contact information provided during the authentication process.

Malwarebytes found that the developer contact details displayed on the Google consent screen used free webmail addresses rather than the official corporate domains associated with the impersonated AI brands. Researchers suspect the campaign is being managed by a single entity or group, as the websites were built using the same commercial website creation kit and share closely related developer email addresses.

Mitigation Strategies

To defend against these scams, users should look beyond a website’s visual polish and familiar authentication options. Malwarebytes recommends verifying the company’s identity and checking the developer details shown during the Google sign-in process.

Users should avoid uploading sensitive documents or recordings to any AI service that cannot be independently verified. Additionally, individuals can manage their security by reviewing and removing untrusted third-party connections within their Google Account settings.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.