Gunjo · Business Intelligence for the AI Era
← Sticker Wall SCAM · DETAIL

Fraudulent AI SaaS Licensing and API Proxy Scams: Reselling Unauthorized Large Model Interfaces to Defraud Enterprises

The primary victims are SME owners, IT procurement managers, and independent developers who are eager for digital transformation but lack the technical expertise to verify large model authenticity. Their psychological vulnerability lies in the pursuit of low costs and rapid access to top-tier AI capabilities. They are often lured by 'cracked' versions or deep-discount licenses, easily deceived by forged official authorization letters, promises of unlimited tokens, and fake test interfaces. By bypassing official channels to purchase enterprise packages, they face data security risks from potential account suspensions and may incur joint legal liability for using infringing software.

SCAM

Key Fields

FIELD STAMPS
IndustrySaaS / Enterprise Software
RegionChina(中国大陆)
ScaleSME
ChannelOther
⚠️ This entry compiles scam tactics and public reporting; it is not investment or legal advice. Content is organized from public reporting and third-party complaint platforms; this site does not make any finding of illegality against the parties involved, who may contact us for correction if they object. If you encounter fraud, report it to the police immediately (110 / anti-fraud hotline 96110 in mainland China; local police overseas).

Who Gets Targeted

The primary victims are SME owners, IT procurement managers, and independent developers who are eager for digital transformation but lack the technical expertise to verify large model authenticity. Their psychological vulnerability lies in the pursuit of low costs and rapid access to top-tier AI capabilities. They are often lured by 'cracked' versions or deep-discount licenses, easily deceived by forged official authorization letters, promises of unlimited tokens, and fake test interfaces. By bypassing official channels to purchase enterprise packages, they face data security risks from potential account suspensions and may incur joint legal liability for using infringing software.

骗局怎么运作

  • Packaging Authorization Credentials: Scammers typically register shell companies with names implying 'intelligent technology' or 'data services,' forge partnership agreements or agency authorization letters from major AI firms, and even build professional-looking official websites. They claim to have internal channels or enterprise-grade API distribution rights, offering SaaS enterprise licenses or unlimited token quotas at prices far below official rates.
  • Lead Generation and Low-Price Bait: Advertisements are placed in enterprise networking groups, developer communities, and via SEO bidding, using hooks like '1 Yuan for Unlimited Tokens' or 'ChatGPT Enterprise at 30% off.' Salespeople emphasize the high cost and complex compliance requirements of official interfaces, claiming their proxy stations have already handled compliance, allowing enterprises to bypass tedious audits—directly targeting the SME pain point of cost reduction and efficiency.
  • Setting Up Private Proxy Interfaces: Technically, scammers build their own proxy stations using illegally bulk-registered personal accounts or stolen API keys. The 'enterprise-independent keys' provided to victims are actually shared interfaces routed through secondary forwarding. Initial tests show fast response times, and they may even provide customized control panels to trick victims into believing they have purchased independent computing and server resources.
  • Inducing Long-term Prepaid Packages: After victims test a small number of interfaces and confirm they work, scammers use tactics like 'limited-time offers' or 'node expansion fees' to induce enterprises to pay for six months or a year of SaaS usage upfront. Contracts often contain hidden predatory clauses, or they may simply request WeChat transfers without signing formal corporate contracts, paving the way for them to disappear or evade responsibility later.
  • Extracting Residual Value and Disappearing: As victim usage increases or official crackdowns intensify, proxy nodes frequently drop or become throttled. When clients complain, scammers demand 'maintenance fees' for server upgrades to extract more money, or blame the downstream interface providers. Once the fund pool reaches a certain scale or they face police scrutiny, they shut down the website, dissolve the shell company, and block the victims' contact information to complete the harvest.

红旗信号(看到这些快跑)

  • 🚩 Claims of providing unlimited tokens or ChatGPT Enterprise at deep discounts (e.g., 30% off) that cannot be verified in the official vendor's agent directory.
  • 🚩 Refusal to sign formal corporate procurement contracts, insisting on personal WeChat or Alipay transfers, or discrepancies between the contract entity and the shell company issuing the invoice.
  • 🚩 The assigned API domain is not the official URL of a major AI firm but a self-built proxy link, with no access to an official enterprise-grade console for account verification.
  • 🚩 Salespeople deliberately avoid discussing official compliance and filing requirements, using 'internal channels' or 'direct connection without filing' as a core selling point, with authorization documents lacking security watermarks.
  • 🚩 Frequent interface drops after a period of use, with customer service demanding additional 'server maintenance' or 'node expansion' fees to restore service, contradicting the original one-time contract promise.

真实案例

  • Between 2024 and 2026, the Cyberspace Administration of China reported the crackdown on the website www.4stoken.cn. The site was illegally operating AI large model API interfaces without proper qualifications, profiting from reselling access, and was subsequently shut down with those responsible held legally accountable.
  • In early 2026, Hangzhou police summoned the operator of an AI model proxy station. The operator was running an unauthorized low-cost interface forwarding service, reselling illegally obtained API keys to SMEs. Following reports, the station was forced to shut down and issue refunds, and the operator faced administrative penalties. (Source: https://www.zhujib.com/hangzhou-police-ai-proxy-shutdown-compliance-warning.html)
  • In July 2026, a local court announced an infringement case involving the impersonation of iFlytek. A criminal syndicate operated a full-chain production and sales operation for forged iFlytek-branded software and services. 19 associated shell companies were ordered to pay over 8.3 million RMB in damages, with many victims being SMEs that unknowingly purchased the SaaS services.
  • In June 2026, media exposed a third-party low-cost ChatGPT Pro scam. Numerous victims reported that their 'low-cost' ChatGPT enterprise accounts frequently dropped within days, with customer service making excuses about 'official crackdowns' before going silent. Multiple business owners lost thousands to tens of thousands of RMB in service fees. (Source: https://www.80aj.com/2026/06/13/chatgpt-scam-warning/)
  • On June 13, 2026, the Cyberspace Administration of China issued a notice stating that various low-cost 'bulk' ChatGPT Pro account scams affected over 3,500 people, with total payments reaching 1,200,000 RMB. Scammers distributed 'official' accounts via third-party app stores for 9 RMB, using forged payment screens to deceive consumers. (Source: https://www.80aj.com/2026/06/13/chatgpt-scam-warning/)
  • On June 13, 2026, tech media 80aj reported on a third-party low-cost ChatGPT Pro scam: A user spent approximately 460 RMB on a third-party channel called 'Mai Men Store' for a subscription, which failed within 24 hours due to official account risk controls. The report noted that this mass failure was directly related to OpenAI's updated device fingerprinting and payment behavior analysis algorithms, signaling a massive purge of gray-market accounts relying on loopholes. (Source: https://www.80aj.com/2026/06/13/chatgpt-scam-warning/)

Official Stance

  • In 2026, the Cyberspace Administration of China reported on the crackdown of the www.4stoken.cn website for the illegal operation of AI large model API interfaces, explicitly stating that operating such interfaces without permission is illegal.
  • In 2026, Hangzhou police launched a severe crackdown on gray-market AI model proxy stations, summoning multiple operators and issuing compliance warnings requiring practitioners to immediately shut down illegal operations.
  • In July 2026, national intellectual property and judicial authorities reported on the punishment of cases involving the impersonation of well-known AI companies, strictly holding those accountable for trademark infringement and the sale of unauthorized software, with over 8.3 million RMB in damages awarded.

How to Protect Yourself

  • ✅ When procuring AI SaaS software and API interfaces, always verify the provider's qualifications through the official agent inquiry system on the major vendor's website; do not trust paper authorization letters or WeChat screenshots provided unilaterally by salespeople.
  • ✅ Refuse private transfer transactions; insist on paying via corporate accounts and require the counterparty to issue VAT invoices matching the contracting entity to ensure a complete and legally traceable transaction chain.
  • ✅ Technically verify the source of the interface by checking if the assigned API request address is an official domain. If the domain resolves to a personal server or an unfamiliar proxy station, stop access immediately and demand a refund.
  • ✅ Be wary of prepaid traps; do not purchase long-term packages exceeding one month at once. Use small amounts to test interface stability and customer service response speed first, and if anomalies like speed throttling or drops occur, cut losses and report to the authorities.