Close Menu
Web StatWeb Stat
  • Home
  • News
  • United Kingdom
  • Misinformation
  • Disinformation
  • AI Fake News
  • False News
  • Guides
Trending

Dave Portnoy accuses Caleb Williams of spreading misinformation

September 22, 2026

Beware these fake websites selling subscriptions to AI assistants

September 22, 2026

Colombian citizen indicted for false voter registration in Wisconsin

September 22, 2026
Facebook X (Twitter) Instagram
Web StatWeb Stat
  • Home
  • News
  • United Kingdom
  • Misinformation
  • Disinformation
  • AI Fake News
  • False News
  • Guides
Subscribe
Web StatWeb Stat
Home»AI Fake News
AI Fake News

Beware these fake websites selling subscriptions to AI assistants

News RoomBy News RoomSeptember 22, 2026Updated:September 22, 20269 Mins Read
Facebook Twitter Pinterest WhatsApp Telegram Email LinkedIn Tumblr

There’s a quiet irony in the way modern scams are built. You’d think that something as deceptive as a fraudulent website would be cobbled together in some dark corner of the internet, using stolen code and sketchy servers. But according to cybersecurity researchers at Malwarebytes, many of these fake sites are being assembled with perfectly legitimate, commercial website creation kits. These are the same kinds of tools that small business owners and hobbyists use every day to put together a clean-looking webpage in an afternoon. The kits come with account management, billing systems, file storage, and all the other administrative conveniences that make running a website easy. The companies behind these products advertise that you can launch a site in about an hour, and once you pay the one-time setup fee, additional templates cost only around two dollars each. That affordability and ease of use is a dream for honest entrepreneurs, but it’s also a playground for bad actors. Scammers don’t need to write code from scratch anymore. They don’t need to hide in obscure corners of the web. They can simply subscribe to a legal service, pick a template, and set up something that looks shockingly professional. And because the underlying infrastructure is legitimate, the fake websites don’t trigger the gut-level alarms that people might feel when landing on a sketchy, poorly designed page. The site looks real because it is real, only the intent behind it is fake.

That’s the part that makes these scams so unsettling: they borrow trust from reputable platforms and then repurpose it to deceive. Malwarebytes examined a handful of these fraudulent operations and found a common pattern. The fake websites all promised access to some kind of artificial intelligence service, usually one that people have heard of or at least heard buzz about. There were pages pretending to offer subscriptions to well-known AI-powered tools, and there were also pages pushing brands that sound plausible but are actually completely unfamiliar. In both cases, the goal was to get visitors to pay for a subscription, often on a recurring basis, for a service that either didn’t exist or wasn’t what it claimed to be. The scammers used the website builder’s billing functions to collect credit card payments, and they used its file storage to host whatever content was necessary to make the illusion hold together. For the victim, the experience feels normal. You land on a clean, modern-looking page. There’s a logo, a description of the product, maybe a few testimonials, and a clear call to action. You think you’re buying access to a useful AI tool. In reality, you’re handing your payment details to someone who has no intention of delivering anything except a lighter wallet and a lesson learned.

What sets this particular scam apart, however, is how the fake sites handle something as seemingly risky as logging in with Google. In the past, phishing sites often tried to trick users with fake password forms. They’d present a cleverly designed page that looked like Google’s login screen, and if you typed your email and password, the scammers would capture those credentials and use them to break into your real accounts. These new fake sites don’t do any of that. Instead, they use genuine Google sign-in pages. When you click the Google login button on one of these fraudulent AI sites, you are actually taken to Google’s real authentication page. You type your real password, and Google itself verifies it. The scammers never see your password, because there’s no fake form involved. What they’re doing is much more subtle and, in a way, much more clever. They’re using Google’s official OAuth system, the same mechanism that thousands of legitimate apps use to let you sign in with your Google account. By requesting certain permissions, these fraudulent sites can ask Google to share a small amount of your personal information with them. And Google will do exactly that, because you’ve just given your consent by logging in.

The researchers at Malwarebytes noted that the fake websites they examined didn’t request anything particularly invasive. They weren’t asking for access to your Gmail inbox or your Google Drive files. The permissions were limited to basic profile information: your name, your email address, and your profile picture. On the surface, that might seem harmless. After all, apps of all kinds ask for that information all the time, and most people click through without a second thought. But think about what that means in this context. The scammers now have a confirmed, verified email address associated with your real identity, plus your name and a photo. They also already have your credit card information from the fake subscription payment. That combination is gold for someone running a fraud operation. They can use your email address for targeted phishing campaigns, sell it to other scammers, or use it to make the next round of fake sites look even more legitimate by claiming that “your account is active” or “your subscription has been confirmed.” The fact that they didn’t ask for Gmail access isn’t generosity, it’s calculation. They know that the more innocent the request looks, the more likely you are to say yes. By using real Google pages, they also eliminate a major red flag: the suspicious-looking URL that doesn’t quite match google.com. Everything about the login process feels right, because everything about it actually is right. And that’s precisely the danger.

There are clues, though, and this is where it gets interesting. Google’s consent screen, the page that appears after you log in and asks whether you want to allow the application to access your information, is designed to provide transparency. It shows you the name of the application that’s requesting access, and it provides developer contact details. On legitimate apps, those details usually point to a real company with a real website and a professional email address. But on the fake sites examined by Malwarebytes, something was off. The developer contact information displayed on Google’s consent screen consisted of free webmail addresses, like [email protected] or [email protected], rather than addresses tied to the company’s own domain. That’s a massive red flag. A legitimate business with a genuine AI product doesn’t need to use a free Gmail address as its official developer contact. It would have its own domain, its own email system, and a trail of verifiable information that people could check. The free webmail address tells you that whoever created this application doesn’t really have a business behind it. They just have a website builder account, a stack of stolen or low-quality payment schemes, and enough technical knowledge to register a Google API project. For the unfamiliar AI brands, the situation was even worse. The websites offered almost no independently verifiable information about the people or companies selling the subscriptions. No real office address, no press coverage, no credible reviews, no way to confirm that the product actually existed beyond a landing page and a payment button.

This deliberate use of genuine Google sign-in pages represents a troubling evolution in how scams operate. For years, we’ve been taught to recognize phishing by looking for fake login pages. We check the URL, we look for the padlock icon, we hover over links to see where they really lead. Those instincts are still useful, but they don’t protect you when the login page is real. The scam isn’t happening at the password level. It’s happening at the permission level. You’re not giving the scammers your password; you’re giving them access to a slice of your digital identity, and you’re doing it voluntarily because the whole process looks official. That’s why these schemes are so hard to spot. Even a savvy user can be fooled if they’re not paying close attention. The authentication flow is exactly what it should be. The site uses Google’s actual infrastructure, so technical signals check out. The only way to catch it is to look at the larger context. What is the application actually asking for? Who developed it? Why is the developer contact a free webmail address? Does this product have any real presence outside of a single website? Those are the questions that can save you from becoming a victim, but they require a level of mindfulness that most people don’t have when they’re in a hurry to sign up for a new tool.

At the end of the day, the story here isn’t just about a particular scam or a particular cybersecurity firm’s findings. It’s about how modern trust is manufactured and exploited. We want to believe that the internet is full of legitimate, helpful tools, and for the most part, it is. But that abundance of goodness also creates cover for people who are willing to fake it. They hide behind real website building platforms, real payment systems, and real Google authentication because those things give their fraud a sheen of credibility. The best defense is not to stop using the internet or to become paranoid about every login. That would be exhausting and unnecessary. Instead, the defense is a shift in mindset. When you’re asked to pay for something online, especially something that promises the next big thing in AI, slow down. Look at the details that are easy to ignore. Check the developer information on the consent screen. Search for the company name along with words like “review,” “scam,” or “legitimate.” See if there’s a real human being you can contact, a real office, a real track record. And remember that Google will show you what an app wants to access, so take the ten seconds to read it. The scammers using these website creation kits are not master criminals. They’re just taking advantage of the gaps between convenience, urgency, and attention. Close those gaps, and their job gets a lot harder. In the end, the most powerful security tool you have isn’t a password manager or an antivirus program. It’s the willingness to ask a few uncomfortable questions before you hand over your money and your personal information. That small habit can make all the difference.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
News Room
  • Website

Keep Reading

A Highly Trafficked Space News Site Invented a Fake NASA Engineer and Used Her Name to Publish to AI-Generated Slop

Local city warns of AI fake property video scam – WHIO TV

Tasmanian justice department review under way after AI and fake citation used in murderer’s parole decision | Tasmania

Google says its Gemini AI model hacked three other companies | Google

Could AI wipe out humans and how might it do it?

Fake AI trading bot tutorials steal 274.6 ETH from 224 victims

Editors Picks

Beware these fake websites selling subscriptions to AI assistants

September 22, 2026

Colombian citizen indicted for false voter registration in Wisconsin

September 22, 2026

Honoring Jane Goodall’s conservation legacy and combatting misinformation

September 22, 2026

False Advertising: Albanese, Digital Safety and Australia’s Security Council Bid

September 22, 2026

BBC accused of misinformation over ‘crocodile-infested’ Olympic rowing site

September 22, 2026

Latest Articles

Fazzrudin urges Sarawakians to help dispel misinformation, false perceptions about the state

September 22, 2026

DA demands presidential answers over Special Forces operation and possible false court evidence

September 22, 2026

Government urged to tackle energy misinformation as MPs call for ‘net zero’ rethink

September 22, 2026

Subscribe to News

Get the latest news and updates directly to your inbox.

Facebook X (Twitter) Pinterest TikTok Instagram
Copyright © 2026 Web Stat. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Contact

Type above and press Enter to search. Press Esc to cancel.