Fake AI Subscription Sites Push $2,000 Plans

Malwarebytes · Medium sophistication
Last updated September 22, 2026

Researchers found a network of 100+ polished look‑alike subscription websites that impersonate real products (and invent new ones) to sell expensive “AI” plans. The sites rely on professional landing pages and a real Google sign-in flow to appear legitimate, then steer visitors into paid subscriptions and file uploads despite unclear ownership and support details.

How the attack worked

Researchers identified more than 100 subscription websites linked by identical underlying files and closely related developer email addresses, suggesting a single operator or connected group runs many of them. Some sites impersonate well-known products, including GPT-6 Astra, DaVinci Resolve, PixAI, OpenCut, and Omegle. Rather than relying on fake password forms or malware, the sites use polished product pages and a genuine Google sign-in flow to build trust. After signing in, visitors are shown paid plans, usage credits, and payment histories, with pricing ranging from less than $10 a month to more than $2,000 a year.

Why it succeeded

The scam works because the visible signals people are trained to trust, such as HTTPS padlocks, professional design, and confident marketing language, are all present. The Google sign-in step adds a further layer of false confidence: because the password is entered on Google's own site, visitors assume the underlying service must also be legitimate. In reality, a genuine sign-in page only confirms the connection is encrypted and that Google authenticated the login, not that the branded service is who it claims to be. Consent screens in examined cases listed support contacts using free webmail addresses rather than addresses tied to the displayed brand.

What to watch for

  • A polished, secure-looking site with no verifiable company name, business address, or ownership details.
  • A Google consent screen where the developer or support contact does not match the brand or product you intended to use.
  • No trial or working demo before you are pushed toward an annual payment plan.
  • Requests to upload documents, recordings, or other files before the service has proven it is legitimate.

How to build resistance

Employees across marketing, creative, procurement, and finance roles are common targets for this pattern since they routinely evaluate and purchase software tools. Encourage staff to check consent screen details against the intended brand before approving access, to look for independently verifiable company information before subscribing, and to avoid annual commitments or file uploads to services that cannot demonstrate legitimacy. IT helpdesk teams can support this by giving simple guidance on reading OAuth consent screens and reporting suspicious subscription offers before purchases go through, particularly in expense approval and vendor management workflows (see attack.mitre.org/techniques/T1598 for related reconnaissance techniques and attack.mitre.org/techniques/T1204/001 for the malicious link execution pattern).

Key findings

  • A network of “more than 100 subscription websites” appears linked by identical underlying files and closely related developer email addresses, suggesting a single operator or connected group.
  • Some sites impersonate well-known products/brands (e.g., “GPT-6 Astra,” “DaVinci Resolve,” “PixAI,” “OpenCut,” and “Omegle”).
  • The scam does not rely on fake password pages or malware downloads; it uses “polished product pages and genuine Google sign-in screens” to build trust.
  • After Google sign-in, visitors are shown paid plans and credits; pricing ranges from “less than $10 a month to more than $2,000 a year.”
  • Google consent screens show developer/support contacts; in examined cases these were “free webmail addresses,” which is a trust red flag for a supposedly established service.
  • The sites provide little to no verifiable company ownership information, making refunds/charge disputes harder and increasing risk if users upload sensitive files.

Who’s being targeted

  • Commonly targeted roles: All employees, Creative/Design teams, Marketing/Comms, Procurement/Vendor management, Finance (expense review/approvals), IT helpdesk (user guidance on OAuth/consent screens).
  • Affected industries: Software/SaaS users, General consumers, Creative professionals (video, voice, AI tools), Corporate employees purchasing online subscriptions.
  • Attack channels: website.
  • Impersonated: A well-known AI/productivity or creative software brand (e.g., “GPT-6 Astra,” DaVinci Resolve, PixAI, OpenCut), Google sign-in + the displayed brand on the fake site (the attacker controls the third-party app identity shown on the consent screen).

Red flags to watch for

  • The site is polished but ownership is unclear (no registered company/address).
  • Google consent screen shows mismatched app/developer/support details (e.g., free webmail support).
  • No trial or working demo, site pushes payment immediately after sign-in.
  • A real Google sign-in page doesn’t prove the service is official.
  • Consent screen developer/support contact is a free webmail address.
  • App name/domain on the consent screen doesn’t match the site/product you intended to use.
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How do these fake AI subscription sites trick users if they use real Google sign-in?

The sites send visitors to a genuine Google sign-in page where the password is entered on Google's own website, but a real sign-in page does not confirm the service itself is official or connected to the brand it displays.

What brands are being impersonated by these fake subscription sites?

Researchers found sites impersonating well-known products and brands including GPT-6 Astra, DaVinci Resolve, PixAI, OpenCut, and Omegle.

What red flags indicate a subscription site might be fraudulent?

Warning signs include a Google consent screen listing a free webmail support address instead of a company address, no way to test the product before paying, and no verifiable business name or registered address.

Why is it risky to upload files to these unverified services?

Several of the sites ask users to upload documents or recordings for processing, meaning users may share account information and sensitive material with an operator whose identity they cannot confirm.

Read the video transcript

You land on “GPT-6 Astra” or a shiny DaVinci Resolve AI page, hit Get started, and it looks totally legit. Behind that Get started button is a subscription service. These sites send you to a genuine Google sign‑in page, then hit you with plans from under ten bucks a month to over two thousand a year. Here’s the catch: a real Google sign‑in doesn’t prove the service is real. The consent screen lists a random free webmail support address, no real company name, no trial, but it wants your Google profile, your card, and even your file uploads. Your move: before you pay or upload anything, pause on the Google consent screen and check who actually owns the app. If the developer email or company name doesn’t match the brand you expect, close the tab.

Categories

Similar attacks

Phishers Hijack Meta/Google Ad Accounts for Profit

Phishers Hijack Meta/Google Ad Accounts for Profit

Criminal groups are stealing Meta Business Manager and Google Ads accounts using phishing that arrives through trusted platforms like Salesforce, Google Workspace mail-merge, and SharePoint links. The stolen accounts are valuable not just for the budget inside them, but because older accounts with…

July 29, 2026
Fake ChatGPT Billing Email Steals OpenAI Logins

Fake ChatGPT Billing Email Steals OpenAI Logins

A phishing email posing as a ChatGPT billing notice pressures users to “update payment information” to avoid service interruption. The button routes through a Google redirect and lands on a fake OpenAI login page that captures usernames and passwords before sending victims to an error page.

September 17, 2026
Fake ChatGPT Invoice Steals Login Credentials

Fake ChatGPT Invoice Steals Login Credentials

Cofense observed a real phishing email that impersonates OpenAI/ChatGPT billing to trick users into “updating” payment details. The email uses the real ChatGPT logo, urgency (“48 hours”), and a prominent button to drive clicks to a lookalike ChatGPT login page. Any credentials entered are harvested…

September 17, 2026
Fake T-Mobile Points Expiry Texts Hit Phones

Fake T-Mobile Points Expiry Texts Hit Phones

A large phishing (smishing) campaign is sending messages that claim a T-Mobile customer’s rewards points are about to expire. The texts use urgency, made-up point balances, and lookalike “t-mobile.*.top” links to push people into clicking and entering sensitive information. Malwarebytes observed…

September 17, 2026
Hidden ChatGPT Tasks Leak Data Across Accounts

Hidden ChatGPT Tasks Leak Data Across Accounts

Check Point researchers demonstrated a real proof-of-concept where a victim’s ChatGPT session could be tricked into running hidden, attacker-controlled tasks in parallel with the user’s normal request. In the demo, the attacker used a covert cross-account channel to make ChatGPT access the victim’s…

September 8, 2026
Phish Login, Then Add Your Own Google Passkey

Phish Login, Then Add Your Own Google Passkey

Researchers describe a phishing workflow where an attacker logs into a victim’s Google account using stolen password + authenticator code, then quickly enrolls a new passkey to keep access even if the password is changed. The trick relies on victims choosing a weaker sign-in fallback (one-time…

August 26, 2026