Beware these fake websites selling subscriptions to AI assistants
Summary
Fake websites are impersonating legitimate AI tools and software services, using polished designs and genuine Google sign-in pages to trick users into paying for subscriptions that don't exist. The danger is especially serious for businesses when employees bypass IT departments to purchase these fake services, risking the loss of sensitive company data since there's no way to know where uploaded documents and files will end up.
Solution / Mitigation
Malwarebytes recommends that users verify a service's legitimacy by checking who operates it, looking for verifiable company information, and examining developer details shown during Google authentication. Users should also avoid uploading sensitive documents to unfamiliar AI services that cannot be independently verified. For services connected through Google, users can review the connections in their Google Account and remove services they no longer trust or recognize to prevent future access.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://www.csoonline.com/article/4224923/beware-these-fake-websites-selling-subscriptions-to-ai-assistants-2.html
First tracked: September 22, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 82%