Helpnetsecurity Scammers Exploit Google Sign-Ins for Fake AI Subscription Services
Article Content
- •Over 100 fraudulent sites selling AI subscriptions identified.
- •Sites use genuine Google sign-ins to appear trustworthy.
- •No independent verification of claims made by the sites.
A network of over 100 fraudulent websites has emerged, selling unverified AI subscriptions priced up to $2,000 annually. These sites utilize a $249 website toolkit and feature polished designs, including genuine Google sign-in screens, which mislead users into believing they are purchasing legitimate products. The sites impersonate well-known brands like GPT-6 Astra and DaVinci Resolve, while others promote obscure names with no verifiable history. Researchers from Malwarebytes have linked these sites through identical underlying files and developer details, indicating a single operator or closely connected group. The sites do not offer trial versions of their products and require users to upload personal documents for processing. This scheme raises significant concerns about consumer fraud and the difficulty in verifying the legitimacy of the services offered.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Elsevier and CVE-2026-7273 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Chinese Hackers Exploit Zyxel Switch Vulnerability CVE-2026-7273 A Chinese-speaking threat actor has exploited a stack-based buffer overflow vulnerability (CVE-2026-7273) in Zyxel GS1900 switches, compromising 996 devices across 48 countries since August 17, 2026. The vulnerability allows unauthenticated attackers to execute OS commands via crafted HTTP requests. Zyxel released…
Cisco Talos Launches CAIRN to Combat AI-Integrated Malware On September 22, 2026, Cisco Talos released CAIRN, an open-source toolkit designed to hunt, classify, and track AI-integrated malware. The first documented malware analyzed with CAIRN is CLOSEDQUORUM, a Windows implant that autonomously delegates command-and-control decisions to commercial large language models…