Gunjo · Business Intelligence for the AI Era
← Sticker Wall SCAM · DETAIL

Fake LLM Account Black-Market Top-Up Phishing Scam: Cheap International Membership Recharges Are Actually Empty Shells for Unauthorized Deductions

The victim demographic primarily consists of white-collar workers, college students, and independent developers who have a strong demand for generative AI tools but lack cross-border payment capabilities. Their psychological weakness lies in their eagerness to acquire advanced productivity tools to cope with academic or workplace competition, while being deterred by official monthly fees of tens of dollars. The moment they see promotions such as half-price mutual assistance or low-price monthly subscriptions, they let down their guard. Furthermore, due to most people's lack of understanding of overseas platform account-sharing mechanisms and underlying API call principles, compounded by the psychological expectation that cross-border rights protection is extremely difficult, they easily fall into the sunk cost trap when facing black-market top-up services in overseas instant messaging apps. Ultimately, they not only fail to obtain usage rights, but also suffer consecutive unauthorized charges on their payment accounts and even the leakage of sensitive identity information.

SCAM

Key Fields

FIELD STAMPS
IndustryAI / LLM
RegionChina(全国)
ScaleGray Market
ChannelOther
⚠️ This entry compiles scam tactics and public reporting; it is not investment or legal advice. Content is organized from public reporting and third-party complaint platforms; this site does not make any finding of illegality against the parties involved, who may contact us for correction if they object. If you encounter fraud, report it to the police immediately (110 / anti-fraud hotline 96110 in mainland China; local police overseas).

Who Gets Targeted

The victim demographic primarily consists of white-collar workers, college students, and independent developers who have a strong demand for generative AI tools but lack cross-border payment capabilities. Their psychological weakness lies in their eagerness to acquire advanced productivity tools to cope with academic or workplace competition, while being deterred by official monthly fees of tens of dollars. The moment they see promotions such as half-price mutual assistance or low-price monthly subscriptions, they let down their guard. Furthermore, due to most people's lack of understanding of overseas platform account-sharing mechanisms and underlying API call principles, compounded by the psychological expectation that cross-border rights protection is extremely difficult, they easily fall into the sunk cost trap when facing black-market top-up services in overseas instant messaging apps. Ultimately, they not only fail to obtain usage rights, but also suffer consecutive unauthorized charges on their payment accounts and even the leakage of sensitive identity information.

骗局怎么运作

  • Traffic redirection and low-price temptation: Fraud syndicates publish massive ads on social platforms for cheap top-ups and monthly subscriptions of advanced LLMs, priced at only half or even lower than official subscription fees, claiming full after-sales return and exchange guarantees and stable non-disconnecting service. They exploit significant information asymmetry and price advantages to hook users who urgently need advanced productivity tools but face payment barriers.
  • Counterfeit control panels and login interfaces: After victims pay, scammers do not provide official genuine accounts, but instead send phishing web panel links. The frontend of these panels adopts open-source chat frontend frameworks, while the backend has no actual model invocation. Mechanically, they create the illusion of computation through fake page loading animations; when users try multiple times and encounter network errors, they falsely claim that customers need to add customer service to pay a supplementary advanced version authorization fee.
  • Bundling malicious deductions and automatic renewal agreements: During payment, scammers guide users to sign concealed automatic renewal agreements through self-built collection QR codes or illegal third-party payment links, or solicit credit card security codes under the guise of verifying account security. The sales pitch often claims it is only for testing the channel; once authorized, the backend deducts weekly fees through overseas illegal payment gateways while the frontend panel fails a few days later.
  • Brainwashing via official authorized partner scripts: To further dispel victims' doubts, scammers forge backend collaboration screenshots with overseas AI companies in chats, claiming to be compliant computing power distributors. Mechanically, they boost trust through forged English authorization letters and fictitious overseas enterprise registration qualifications, while planting multiple shills in groups to post purchased use screenshots, creating a sense of scarce slots.
  • Group disbandment, runner escape, and black-market monetization cycle: When victims find accounts unusable and question this in the group, scammers immediately kick them out, block them, and rapidly dissolve chat groups of hundreds of people, completing a round of harvesting. Afterward, the syndicate packages collected payment vouchers, mobile numbers, and chat logs, transferring them to other black-market teams for targeted pushing of other paid courses or further precise scams, forming a complete black-market recurrence closed loop.

红旗信号(看到这些快跑)

  • 🚩 Far below official subscription prices: Claiming to provide international advanced LLM membership services at monthly fees lower than half of official pricing—or even as low as ten yuan—while demanding payment strictly through unofficial personal collection QR codes or cryptocurrency transfers, refusing to provide formal corporate invoices.
  • 🚩 Mandatory login via designated third-party clients: Refusing to disclose the official website login method for accounts, forcing users to download installation packages of unknown origin or visit unfiled URLs for the experience, with programs often over-requesting mobile contacts and storage permissions in the background.
  • 🚩 Customer service strictly via specific overseas chat tools: When victims request after-sales refunds, customer service never replies via official email, contacting users exclusively through overseas instant messaging software equipped with burn-after-reading functions, and frequently changing customer service accounts and group addresses to evade tracking.
  • 🚩 Demanding sensitive binding information casually: Under the pretext of account binding or real-name filing, users are asked to provide complete front and back photos of credit cards, payment platform login SMS verification codes, and other core sensitive credentials, and are even lured into entering real passwords on unofficial links.
  • 🚩 Extremely unstable service with zero after-sales support: After purchase, accounts frequently prompt remote logins and get kicked offline, control panels suddenly crash or show a white screen within two to three days, after-sales specialists contacted during payment are entirely offline, and discussion groups are set to all-mute before being dissolved.

真实案例

  • In August 2026, cybersecurity monitoring agencies reported that a large number of fake account transaction scams were spreading across overseas instant messaging platforms. According to the report, a domestic developer A transferred over one hundred yuan to a seller to purchase a monthly account in order to obtain access to a well-known LLM. As a result, the account was banned after two days of use, the seller blocked them and dissolved the group, and the registration information filled in was used to register on other unknown virtual currency exchanges. (Source: [https://www.80aj.com/2026/08/07/ai-scam-telegram-claude/](https://www.80aj.com/2026/08/07/ai-scam-telegram-claude/))
  • In June 2026, third-party low-price LLM membership scams triggered warnings. Victims in multiple regions who purchased so-called shared alternative accounts on social platforms were induced to download a certain speed-edition skin application. This app was actually a Trojan horse program; after installation, users experienced frequent disconnections, unresponsiveness, and abnormal mobile phone bill deductions. Following strict official inspection and removal requirements, some victims suffered single-month phone bill losses approaching nearly one thousand yuan. (Source: [https://www.80aj.com/2026/06/13/chatgpt-scam-warning/](https://www.80aj.com/2026/06/13/chatgpt-scam-warning/))
  • On March 15, 2025, according to Sina Finance reports, over 3,000 copycat websites emerged parasitizing well-known LLMs for profit. A woman clicked a high-ranking ad link after searching for the LLM and spent over one hundred yuan to buy a permanent membership local deployment service. After downloading, she found it was merely a simple networked conversation script that not only failed to work, but also had her computer browser homepage hijacked to continuously pop up gambling advertisements. (Source: [https://finance.sina.com.cn/jjxw/2025-03-15/doc-inepsvus3088900.shtml](https://finance.sina.com.cn/jjxw/2025-03-15/doc-inepsvus3088900.shtml))
  • In August 2026, a tech community Linux.do exposed an AI account black-market top-up phishing case: a user found an ad in a Telegram group claiming to provide Claude LLM black-market top-up services at a low price of 500 yuan, accessed a fake platform and filled in registration information per instructions, and subsequently faced account bans. The seller blocked them and dissolved the group. With manufacturers like OpenAI recently upgrading device fingerprint recognition and payment behavior analysis algorithms, grey-market accounts obtained through bulk registration and abnormal payment paths face large-scale purging. (Source: [https://www.80aj.com/2026/08/07/ai-scam-telegram-claude/](https://www.80aj.com/2026/08/07/ai-scam-telegram-claude/))
  • In March 2025, Sina Finance investigative reports revealed 3,000 copycat websites parasitizing DeepSeek for profit: consumers downloading DeepSeek in app stores encountered fake apps resembling genuine ones, being scammed of 198 yuan by permanent membership pitches; others mistakenly believed local deployment pitches and paid 49 yuan only to download fake installation packages. OpenAI's official ChatGPT Plus priced at 20 USD (approx. 141 yuan) per month was also resold at a markup. Hangzhou DeepSeek company stated that all features are completely free and any paid items are scams. (Source: [https://finance.sina.com.cn/jjxw/2025-03-15/doc-inepsvus3088900.shtml](https://finance.sina.com.cn/jjxw/2025-03-15/doc-inepsvus3088900.shtml))

Official Stance

  • On August 2026, cybersecurity industry observation self-media published a warning notice calling for vigilance against empty-shell phishing services topping up AI LLM accounts via overseas instant messaging software, reminding the general public not to transfer money to unverified third-party individuals to prevent payment information leakage and subsequent unauthorized charges.
  • On June 13, 2026, multiple technology security monitoring platforms jointly issued a warning, pointing out that third-party low-price LLM top-up channels are mostly phishing traps behind the scenes. So-called official promotional accounts are actually black-market cards opened by stealing others' credit cards, which are easily banned in batches by foreign platform risk control systems, directly exposing consumers to property losses.
  • On March 15, 2025, Sina Finance and several other authoritative media outlets published in-depth investigative reports exposing chaos surrounding tens-of-yuan local deployments and hundreds-of-yuan permanent memberships wrapped around famous open-source LLMs, reminding the public to recognize official open-source repositories and prevent copycat software under the banner of LLMs from stealing privacy and making disguised deductions.

How to Protect Yourself

  • ✅ Be sure to download and install clients through well-known AI enterprise official websites or regular app stores. Maintain vigilance against recommendation links with advertising labels in search engines, and never casually click on URLs that have not undergone security checks, so as to avoid falling into the trap of high-imitation phishing websites.
  • ✅ Reject any top-up service priced far below official subscription rates that requires transfers via personal WeChat, Alipay, or virtual currency. Especially actions requesting credit card back-side security codes under the guise of verifying channels are highly likely building automatic renewal traps; transaction should be terminated immediately and screenshots retained as evidence.
  • ✅ For client installation packages of unknown origin, conduct a complete scan with antivirus software prior to installation, and strictly review requested device permissions in mobile system settings. If abnormal permission requests such as reading contacts or background location retrieval are discovered, resolutely refuse and uninstall.
  • ✅ Once you realize you have been scammed, immediately apply for transaction interception and complaints through the payment platform and freeze associated bank cards or credit cards. At the same time, organize chat logs, transfer vouchers, and relevant links, report the case to local public security organs, and provide black-market clues through reporting channels such as 12315 or the Cyberspace Administration.