Saturday, September 26, 2026
Advertise Here 728X90 Banner
Advertise Here 728X90 Banner
Home Technology WARNING: New AI scams are now tricking people with fake software subscriptions

WARNING: New AI scams are now tricking people with fake software subscriptions

0

Scammers are using polished websites, familiar AI brand names and genuine Google sign-in pages to sell software subscriptions that may not exist, with some plans costing more than $2,000 a year.

More than 100 websites have been linked to the same commercial website toolkit and closely related developer details. The sites present themselves as AI assistants, image generators, video editors, study tools and voice-cloning services. Some copy the names of products that people already know, while others promote unfamiliar brands with little information about who runs them.

The operation relies on a simple but effective trick. A visitor arrives at a professional-looking site, clicks a button such as “Sign in” or “Get started”, and is taken to a real Google authentication page. The use of Google’s own web address can make the service appear trustworthy, even though Google is only handling the login and is not confirming that the company behind the product is genuine.

The sites examined include imitations using the names GPT-6 Astra, DaVinci Resolve, PixAI and OpenCut. Another uses the name Omegle, the video-chat service that closed in 2023. Other pages advertise services with names such as Astra AI and VoicesCloning, including one that claims to copy a person’s voice from a ten-second recording.

The prices vary sharply. Some subscriptions cost less than $10 a month, while others rise to hundreds of dollars each month or more than $2,000 for a year. A fake GPT-6 Astra site lists plans at $89, $169 and $249 a month. Several sites also ask users to upload documents, recordings or other files for processing before giving them any chance to test the advertised service.

Visitors are not shown a working product before payment. Buttons on the landing pages remain inactive until a user signs in, after which the visitor is taken to a pricing page showing plans, credits and payment histories. Some subscriptions say that unused credits expire after a fixed period, adding pressure to spend more or use the service quickly.

The websites are linked by their underlying code. Investigators found identical file names and matching structures across pages with different branding, colours and product descriptions. The sites also used developer contacts with the same name in free webmail addresses, with only small differences such as added numbers. Those details were entered when the applications were registered with Google rather than being automatically created by the website software.

The sites appear to have been built from a $249 starter kit sold as a quick way to launch online services. The kit includes user accounts, billing tools, file storage and administrative controls. Additional templates cost about $2 each. The buyer supplies a new domain, logo, colours and description, allowing another version of the site to be created with little extra work.

Several pages still contain traces of the kit’s original demonstration material. These include unused promotional banners, generic menu entries and testimonials that were not written for the products being sold. One page displayed the word “boilerplate” in the name of a paid plan. Another had relabelled a demonstration list of businesses as its own customers.

Some sites claim to have millions of users or to serve well-known companies. One says that more than 12 million students use its study tools. There is no independent evidence supporting those claims, and the names of large businesses displayed as customers do not appear to be connected to the services.

The appearance of a secure connection adds another layer of reassurance. Each site may display the familiar padlock in the browser, but that only shows that the connection is encrypted. It does not identify the owner of the website or prove that the software being sold is authentic.

The Google sign-in stage is central to the deception. The pages do not necessarily collect a password through a fake form. Instead, the user enters details on Google’s genuine site and may approve the sharing of basic information such as a name, email address and profile picture. The investigated services did not request access to Gmail or Google Drive, but the sign-in still creates an account with an outside application.

Google’s own documentation says that its consent screen shows the information a user is releasing, along with the application’s branding and the developer details associated with the request. That information can be checked against the website. In the cases examined, several developer contacts were free Gmail addresses rather than addresses linked to the brand displayed on the page.

“A free email address is not proof of wrongdoing, but it should raise questions when a service claims to have millions of users or presents itself as an established company,” researchers warned.

The lack of basic business information is another feature of the network. The sites generally provide no registered company name, office address or independently verifiable contact. In many cases, the only way to reach the seller is through an email address using the site’s own domain. That can leave customers struggling to request a refund, challenge a payment or establish who is responsible for the service.

The subscription websites form part of a larger wave of scams built around the rapid growth of AI. In a separate campaign identified in September, criminals sent fake ChatGPT billing emails to work and personal users. The messages warned that an outstanding balance of $23.80 had to be paid within 48 hours to prevent an interruption to service. A button labelled “Update Payment Information” redirected victims through a Google service to a page closely resembling the genuine ChatGPT login portal.

The emails came from an address unrelated to the official service. The campaign was designed to steal account credentials and payment information by combining a familiar logo with an urgent billing problem. Similar attacks have impersonated Microsoft, Google, Adobe, Copilot, DeepSeek and Claude.

AI brands are also being used to distribute malware rather than merely collect subscription payments. In July, a malvertising campaign directed people searching for the Claude desktop application to a public page hosted on the genuine Claude domain. The page looked like a download site and offered a file called “ClaudeDesktop.exe”. It then redirected users to attacker-controlled domains.

At least 29 organisations were affected in two days. The downloaded file was not a genuine Claude application. It installed SectopRAT, a remote access trojan capable of stealing passwords, files, personal information and card details. The malware also used techniques intended to evade analysis and maintain access to infected computers. The malicious page had received 7,100 views before it was removed.

The separate incidents show how little technical sophistication is needed to create a convincing fraud when popular AI names do most of the work. A seller can launch a subscription page with a cheap template, borrow a familiar product name and add a real authentication service. A criminal group can also buy search adverts or exploit a trusted platform to place a fake download in front of people who are actively looking for an AI tool.

“Search for the product separately and look for an official website or app-store listing. Do not rely on ratings and testimonials displayed by the seller,” researchers advised.

People who have linked an unfamiliar application to their Google account can review and remove that connection in their account settings. Anyone who has entered payment information into a suspicious site should contact their card provider, while users who have downloaded an alleged AI application should scan their devices and change exposed passwords from a separate, trusted device.

The growing market for AI software has created a new opportunity for fraudsters: sell access to a product that does not exist, or use the promise of access to steal information that is worth far more than the subscription fee. The websites may look modern, the sign-in page may be genuine and the prices may be presented with the confidence of a major technology company. None of those features establishes who is behind the service or whether the promised software will ever be delivered.

For customers, the most revealing details are often the simplest ones: a brand that cannot be found through its official channels, a developer address that does not match the company name, claims of millions of users with no independent trace, and a demand for payment before any product can be tested. Those signs are now appearing across a growing collection of AI subscription sites built from the same cheap foundation.