More than 100 fraudulent websites are exploiting authentic Google sign-in systems to scam customers who believe they're purchasing discounted access to well-known AI services, according to researchers at Malwarebytes. The sites pose as legitimate AI transcription tools, image generators, and digital assistants, potentially exposing corporate information to unknown parties. All of the deceptive platforms were professionally designed and integrated real Google authentication features to appear trustworthy while charging visitors between $10 monthly and up to $2,000 annually for access to AI and software services that don't exist.

The fraudulent sites impersonate AI products with established reputations, including GPT-6 Astra, DaVinci Resolve, PixAI, and OpenCut, alongside some that have been discontinued—such as Omegle, a chat service that closed in 2023—or are less credible. The platforms employ legitimate Google sign-in pages instead of fake password forms, with users entering their credentials on Google's actual website while the applications request basic details such as name, email address, and profile picture. Several of the sites prompted users to upload documents, recordings, or other files to access the advertised services. Google's consent screen typically identifies the application requesting access and shows developer details, but on these fake websites, that screen displayed free webmail addresses for developer contacts rather than addresses associated with the established AI services being promoted.

Malwarebytes researchers believe all the fake subscription sites they found are operated by the same individual or organization, since they were all built using an identical website creation kit based on the same underlying files and with closely related developer email addresses shared among them. "The sites we examined did not use fake password forms or push malware downloads," the researchers said. The website creation kit is a legitimate commercial product that offers account management, billing, file storage, and other administrative functions, with its makers claiming it can launch a website in an hour and that, following a one-time purchase, additional templates cost only around $2 each.

The risk for businesses emerges when employees believe they're securing a bargain for their departmental budget and choose not to involve IT in the purchase process, according to the report. Shadow IT presents enough challenges when the products are genuine, but in these situations there's no way to know where the collected information will ultimately be stored or used. The researchers noted that the sites examined didn't request access to Gmail or Google Drive, and in the case of unfamiliar AI brands, the platforms provided minimal independently verifiable details about the businesses selling the subscriptions.

Malwarebytes recommends users look beyond a site's design and the presence of familiar authentication options when evaluating whether an AI service is legitimate, including checking who operates the service, searching for verifiable company information, and examining the developer details shown during Google authentication. The report also warned against uploading sensitive documents, recordings, or other data to unfamiliar AI services, particularly when the business behind the site can't be independently verified. For services connected through Google, users can review the connections in their Google Account and remove services they no longer trust or recognize to prevent future access. The scale of this operation suggests that credential-based fraud has evolved beyond traditional phishing into a more sophisticated model that weaponizes trust in established authentication systems. Enterprises that rely solely on employee judgment to distinguish legitimate SaaS vendors from imposters may find that no amount of security awareness training can fully compensate for the absence of centralized procurement oversight.