Scammers Used Toolkit to Sell Fake AI Subscriptions
A new report identifies over 100 fraudulent websites using legitimate Google sign-in screens to harvest user credentials.
Updated on Sept. 22, 2026 in Artificial Intelligence

Live Poll
Do you trust the authenticity of AI subscription sign-in screens you encounter online?
Researchers have uncovered a network of more than 100 scam websites that use a $249 toolkit to peddle unverified AI subscriptions. These sites impersonate established products to deceive users into paying annual fees as high as $2,000.
Why it matters
The campaign exploits user trust in familiar authentication flows to bypass traditional security skepticism. By mimicking prominent platforms, these scams threaten to commoditize consumer credential theft under the guise of the current AI subscription surge.
The fraudulent network relies on a $249 software toolkit that generates convincing fake landing pages for services like GPT-6 Astra and PixAI. These sites leverage genuine Google sign-in interfaces to trick victims into authenticating through their own accounts.
The players
Malwarebytes
A cybersecurity firm specializing in anti-malware and threat intelligence software.
The details
The scam functions by integrating legitimate Google OAuth (Open Authorization) processes, which provide a familiar and trusted interface for victims. Once a user attempts to sign in, the site captures the interaction to facilitate unauthorized access or subscription billing for fake services. This automated toolkit allows operators to scale their deception across at least 100 distinct domains while masquerading as reputable AI or creative software providers.
Timeline
September 2026: Malwarebytes published the report detailing the AI subscription scam network.
The Tech Race
This campaign follows a broader trend where bad actors pivot toward the high-demand generative AI market to maximize the efficacy of phishing operations. It marks an escalation from simple domain spoofing to using verified third-party authentication to bypass standard security heuristics.
Users should exercise caution when prompted to sign in via Google on sites promising access to AI tools, specifically verifying the URL matches the official vendor. The scam targets consumers by masking fraudulent $2,000 annual subscriptions within legitimate-looking authentication interfaces.
The takeaway
The effectiveness of these scams relies on the user trust established by the Google sign-in screen, which has now become a central target for identity theft. Users should implement multi-factor authentication on all primary accounts and strictly avoid entering credentials on any domain that is not explicitly verified by the software manufacturer.
Further reading
For more on the current state of consumer security in the generative era, explore our Artificial Intelligence section.
Live Poll
Do you trust the authenticity of AI subscription sign-in screens you encounter online?






