Updated
Updated · Computerworld · Sep 22
Malwarebytes Finds Fake AI Sites Charging Up to $2,000, Risking Enterprise Data
Updated
Updated · Computerworld · Sep 22

Malwarebytes Finds Fake AI Sites Charging Up to $2,000, Risking Enterprise Data

1 articles · Updated · Computerworld · Sep 22

Summary

  • Malwarebytes identified polished fake subscription sites posing as AI tools and software brands, charging from $10 a month to $2,000 a year while inviting users to upload documents, recordings or other files.
  • The main enterprise risk is data leakage through shadow IT: staff may buy the services outside IT review, handing sensitive material to operators whose identities cannot be independently verified.
  • Google sign-in was used to boost credibility, but the sites sent users to genuine Google consent screens that exposed suspicious developer details such as free webmail addresses rather than official company domains.
  • Malwarebytes said the sites likely come from one group because they share the same website kit, underlying files and related developer emails; the commercial kit itself offers billing, storage and templates for about $2 each.
  • The researchers urged users to verify who runs an AI service, inspect Google authentication details, avoid uploading sensitive data to unfamiliar platforms and remove untrusted Google-connected apps from their accounts.

Insights

How did a simple website kit spawn a massive network of fake AI tools capable of silently stealing thousands from unsuspecting enterprises?
Could your trusted Google login be the very trap that exposes your company's most sensitive data to fake AI platforms?
Are strict corporate IT policies actually driving employees straight into the hands of dangerous shadow AI scams?