Gunjo · Business Intelligence for the AI Era
← Sticker Wall SCAM · DETAIL

Phishing Scams Involving Low-Cost Third-Party Top-ups for Overseas AI Models: Claims of Cracked Versions or Discounted Subscriptions for ChatGPT and Claude are Often Account Theft or Phishing Schemes

The victims are primarily domestic developers, content creators, and university students who are eager to use advanced overseas AI tools but lack experience with cross-border payments. Driven by enthusiasm for technology and a desire for cheap, convenient access, they fall for claims of 'team-shared low-cost accounts' or 'cracked versions unlocking all features.' Their psychological vulnerabilities are twofold: first, a blind trust in domestic community-based top-up traditions coupled with a lack of risk awareness; second, the scammers exploit the victims' reluctance to report the fraud to authorities, fearing repercussions for using unauthorized tools or VPNs.

SCAM

Key Fields

FIELD STAMPS
IndustryAI / LLM
RegionChina(全国)
ScaleGray Market
ChannelOther
⚠️ This entry compiles scam tactics and public reporting; it is not investment or legal advice. Content is organized from public reporting and third-party complaint platforms; this site does not make any finding of illegality against the parties involved, who may contact us for correction if they object. If you encounter fraud, report it to the police immediately (110 / anti-fraud hotline 96110 in mainland China; local police overseas).

Who Gets Targeted

The victims are primarily domestic developers, content creators, and university students who are eager to use advanced overseas AI tools but lack experience with cross-border payments. Driven by enthusiasm for technology and a desire for cheap, convenient access, they fall for claims of 'team-shared low-cost accounts' or 'cracked versions unlocking all features.' Their psychological vulnerabilities are twofold: first, a blind trust in domestic community-based top-up traditions coupled with a lack of risk awareness; second, the scammers exploit the victims' reluctance to report the fraud to authorities, fearing repercussions for using unauthorized tools or VPNs.

骗局怎么运作

  • Scammers post highly enticing advertisements on second-hand trading platforms and instant messaging apps, claiming to have access to official internal channels to provide low-cost top-up services or cracked application packages. They often use tactics like 'half-price monthly subscriptions' or 'shared enterprise beta access' to lure targets, setting prices at one-third to one-fifth of the official cost to quickly build trust.
  • Once a victim contacts the seller, they are instructed to move to an encrypted messaging app for private transactions to bypass platform oversight and chat history monitoring. Scammers claim this is for faster delivery and better after-sales support, effectively isolating the victim from the safety of the official platform to facilitate fraud without leaving traceable records.
  • Scammers send victims so-called 'special client' installation packages or phishing links, requesting them to enter their account credentials or payment information. These interfaces are often highly realistic clones of official sites; once credentials are entered, the backend silently steals the data. Sometimes, scammers simply send an already expired shared group account to defraud the victim of a small initial payment.
  • After successfully obtaining the initial payment, scammers provide a short period of service—such as a shared account that only works for a few days—to lower the victim's guard. When the victim reports that the account is blocked or disconnected, the scammers demand additional 'security deposits' to unfreeze or restore access, citing system upgrades or risk control, before blocking the victim and disappearing once they have extracted all possible value.
  • For stolen, legitimate paid accounts, scammers quickly resell them or use them for other illicit gray-market activities to monetize them further. Even if a victim manages to recover their account, the scammers use the anonymity of encrypted messaging to evade detection, deleting their accounts and discarding their personas to start a new cycle of luring and harvesting new users.

红旗信号(看到这些快跑)

  • 🚩 The seller insists on moving away from platforms with transaction guarantees, directing users to non-real-name, unprotected encrypted messaging apps for communication and direct transfers.
  • 🚩 The selling price is significantly lower than official subscription rates, yet the seller claims to provide independent accounts or unrestricted access, sometimes even claiming no special network environment is required.
  • 🚩 The seller requires the installation of third-party client packages not found in official app stores, or asks users to enter official account verification codes and login credentials on non-official websites.
  • 🚩 Shortly after the initial payment, the account frequently triggers 'login from a different location' warnings or is forced offline, with the seller blaming it on 'automatic system monitoring' and using it as a pretext to demand additional unfreezing or upgrade fees.
  • 🚩 The screenshots of 'successful customers' are highly homogeneous, and positive reviews can be easily generated via software; there is also unusually high customer service activity during late-night hours.

真实案例

  • In June 2026, multiple users on second-hand platforms purchased low-cost 'Pro' top-up services for AI models, only to have their accounts frequently disconnected and eventually banned by the official provider. The service fees, ranging from tens to hundreds of yuan, were lost, and the sellers blocked the buyers immediately after receiving payment. Industry reports indicated that official crackdowns made these shared, unauthorized accounts highly unstable.
  • In August 2026, security agencies received reports of cybercriminal groups on encrypted messaging apps offering low-cost Claude top-ups, which were actually phishing links. Multiple victims entered their emails and phone numbers as instructed, failing to receive service and instead exposing their passwords for other platforms.
  • In August 2025, media exposed a surge of fake listings on second-hand platforms for high-end AI model gift cards. Many victims found the card codes invalid, and their real phone numbers used for verification were linked to and exploited by cybercriminals, who deleted their accounts immediately after receiving payment.
  • In December 2023, the Shanghai Municipal Administration for Market Regulation reported a case involving Shanghai Entropy Cloud Network Technology Co., Ltd., which impersonated ChatGPT. The company operated a WeChat official account called 'ChatGPT Online,' claiming to be the 'ChatGPT Chinese Version' and charging per use. It had 4,231 registered paying users with illegal revenue totaling 125,385.44 yuan, resulting in a fine of 62,692.7 yuan by the Xuhui District Administration for Market Regulation. (Source: https://www.jiemian.com/article/10569698.html)
  • In October 2024, the Zhangjiagang Public Security Bureau reported a phishing scam on Xianyu involving 0.01 yuan membership top-ups. A Mr. Yang from Suzhou clicked a link provided by a seller, and after scanning a QR code for a 0.01 yuan payment, his Alipay was drained through 10 consecutive unauthorized transactions, totaling 966 yuan. Similar losses were reported by a Mr. Gu in Nanjing (776 yuan) and a Mr. Tang in Wuxi (996 yuan). (Source: https://www.zjg.gov.cn/zjgszwz/yjxx/202411/da6c3cc1fb3f4828a0536f60e1a8ee48.shtml)

Official Stance

  • On June 13, 2026, tech security media '80 Degree Security' issued a warning, advising the public to be wary of third-party low-cost AI model 'Pro' top-up scams, noting that such fake accounts are highly unstable and prone to stealing user privacy.
  • On August 7, 2026, '80 Degree Security' issued another warning, cautioning that top-up services on encrypted messaging apps are actually phishing sites, and urged the public not to disclose account passwords.
  • In August 2025, a product research organization issued an emergency alert, pointing out that a large number of fake AI model gift cards on second-hand platforms carry risks of account theft and fraud, with many people already falling victim.

How to Protect Yourself

  • ✅ Refuse all requests for private transactions outside of major e-commerce platforms, especially those involving a move to non-real-name encrypted messaging apps. If a purchase is necessary, ensure all communication and fund transfers are completed within a platform that provides transaction guarantees.
  • ✅ Always download applications and complete subscriptions through official websites or officially authorized app stores. Never install third-party modified packages provided by sellers under the guise of 'unlocking full features' or 'fixing domestic connection issues.'
  • ✅ Enable two-factor authentication (2FA) and bind an independent hardware security key. Never disclose account passwords, verification codes, or secret keys to any top-up seller. If abnormal account activity is detected, change the password immediately and revoke historical authorizations.
  • ✅ Be wary of marketing claims that defy common business sense, such as 'lifetime memberships' at low prices. For sudden, frequent disconnections of overseas AI models, verify the account status through official support channels rather than believing a seller's claims about needing additional fees to 'unfreeze' the account.