Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

How fake signups drive AI fraud

0
Medium
Published: 08/05/2026 (08/05/2026, 18:54:29 UTC)
Source: AlienVault OTX General

Description

A thriving gray market has emerged offering discounted access to AI models through fraudulent account registrations that exploit free trials and startup credits. Services like Poison Claude and Ecomagent offer 70-90% discounts by creating fake accounts on platforms such as AWS Bedrock and Google Cloud, then reselling access through custom API endpoints. The demand is driven by cost considerations, access restrictions in regions like China, and desire for anonymity. Fraudulent registration campaigns targeting AI video services show over 105,000 brute-force signup attempts using bots, VPNs, and disposable email domains. The operations leverage residential proxies to evade detection and accept cryptocurrency payments. These services operate through sophisticated AI gateways and are advertised on underground forums and messaging platforms, particularly in Chinese-language markets, representing a significant platform abuse challenge for AI service providers.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/06/2026, 11:32:55 UTC

Technical Analysis

This campaign involves fraudulent registrations to exploit free trials and startup credits on AI service platforms, enabling discounted reselling of AI model access. Operators use automated bots, VPNs, disposable email domains, and residential proxies to create fake accounts on cloud platforms such as AWS Bedrock and Google Cloud. These accounts are then monetized by reselling access through custom API gateways, with discounts ranging from 70-90%. The campaign targets AI video services with over 105,000 brute-force signup attempts documented. Payment is accepted in cryptocurrency, and the services are promoted on underground forums and messaging platforms, particularly in Chinese-language markets. This activity constitutes a form of platform abuse rather than a software vulnerability and poses operational and financial risks to AI service providers.

Potential Impact

The fraudulent account creation and resale of AI service access lead to significant platform abuse, financial losses due to misuse of free trials and startup credits, and potential degradation of service quality for legitimate users. The use of bots and proxies complicates detection and mitigation efforts. The campaign also undermines trust in AI service platforms and may affect regional access policies due to abuse originating from specific countries.

Defensive Guidance

No official patch or fix applies as this is a platform abuse campaign rather than a software vulnerability. AI service providers should enhance fraud detection mechanisms, including monitoring for high volumes of signup attempts, use of disposable email domains, VPNs, and residential proxies. Implementing stricter identity verification and limiting the abuse of free trials and startup credits can reduce impact. Providers should also monitor underground forums and threat intelligence sources for emerging tactics and indicators such as the identified domains. Collaboration with payment processors to detect suspicious cryptocurrency transactions may help disrupt these operations.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.okta.com/blog/threat-intelligence/free_tokens_for_sale"]
Adversary
null
Pulse Id
6a7386e5ce9f6bd78c7da52b
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainpoison-claude.bitsender.top
domainapi.claudeopus.shop
domainratixq.com
domainclaudeopus.shop

Threat ID: 6a744c2ebf8831d539758e96

Added to database: 08/06/2026, 08:56:14 UTC

Last enriched: 08/06/2026, 11:32:55 UTC

Last updated: 08/07/2026, 00:23:03 UTC

Views: 18

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses