HomeIntelligenceBrief
BREACH BRIEF 🟠 High ThreatIntel

Fake AI Subscription Sites Use Cheap Toolkit to Sell $2,000 Annual Plans

More than 100 look‑alike AI subscription sites were discovered using a shared web‑kit and Google sign‑in, offering costly annual plans without any verifiable vendor information. The scheme highlights the need for robust third‑party risk controls and continuous monitoring to protect procurement and audit readiness.

Verisq™ Intelligence · 📅 September 22, 2026 · 📰 malwarebytes.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
malwarebytes.com

Fake AI Subscription Sites Use Cheap Toolkit to Sell $2,000 Annual Plans

What Happened – Malwarebytes identified more than 100 look‑alike subscription sites that sell AI tools (e.g., “GPT‑6 Astra”, “PixAI”, “OpenCut”) for up to $2,000 a year. All sites share the same underlying web‑kit, identical developer email addresses, and a polished Google‑sign‑in flow, but none provide verifiable ownership or independent reviews.

Why It Matters for Trust & Control Assurance

  • The campaign exploits the assumption that a TLS‑protected site and a Google login automatically imply legitimacy – a gap that a continuous third‑party risk program is designed to surface and document.
  • Without systematic vendor vetting and evidence collection, organizations may inadvertently spend on fraudulent services, eroding financial controls and audit defensibility.

Who Is Affected – SaaS providers, AI‑focused startups, enterprise procurement teams, and any end‑users who purchase cloud‑based AI subscriptions.

Recommended Actions

  • Add the identified domains to your deny‑list and flag any procurement request that references them.
  • Enforce a vendor‑onboarding workflow that requires independent verification (e.g., business registration, third‑party attestations, proof of product demo) before any subscription is approved.
  • Deploy continuous monitoring of external web assets for brand‑impersonation patterns and collect evidence for audit trails.

Technical Notes – The fraudulent sites use valid TLS certificates, authentic‑looking Google OAuth screens, and identical HTML/JS bundles. No malware is delivered, but the payment flow is real, and some sites request uploads of documents or media for processing. Source: https://www.malwarebytes.com/blog/threat-intel/2026/09/the-fake-sites-using-a-cheap-toolkit-to-sell-2000-ai-subscriptions

📰 Original Source
https://www.malwarebytes.com/blog/threat-intel/2026/09/the-fake-sites-using-a-cheap-toolkit-to-sell-2000-ai-subscriptions

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →