AI Safety Guide

How to spot a fake AI app before it steals your data

Fake ChatGPT, Claude and Gemini downloads were one of 2026’s most common malware lures. Here are the warning signs, a two-minute check before you install, and what to do if you have been caught.

Flat line illustration of two similar phones showing chat apps, one marked with a green tick and one with an orange warning triangle, beside a magnifying glass.

How to spot a fake AI app: the short answer

Fake AI apps copy the names of ChatGPT, Claude and Gemini to spread malware or steal data. The safest habit is simple: install AI apps only from the company’s own website or official app store listing, check the developer name, be suspicious of ads and “free download” links, and never paste commands a video or stranger tells you to run. If you already installed a fake, disconnect, scan and change passwords.

The more popular an app becomes, the more people try to copy it. AI assistants are now among the most searched-for apps in the world, and criminals have noticed. Security researchers have spent 2026 documenting fake “ChatGPT”, “Claude” and “Gemini” downloads, fake browser extensions that quietly copy your chats, and video tutorials that lead people into installing malware.

The good news is that most fake AI apps rely on the same few tricks, and a handful of habits will protect you from nearly all of them. This guide explains what researchers have found, the warning signs to look for, how to check an app before you install it, and what to do if you think you have already been caught.

It is based on published security research and official guidance from Apple, Google, OpenAI and the US Federal Trade Commission, checked in September 2026. TheJusGrow has not tested any of the apps or tools mentioned.

How big is the fake AI app problem?

Big enough to take seriously. In May 2026, the security company Kaspersky said it had detected more than 92,000 malware and unwanted-software attacks disguised as AI services between January and early May 2026. Fake ChatGPT lures accounted for 49% of those, and fake Claude and fake Gemini lures for 18% each, according to the company. Kaspersky also said it had identified more than 15,000 malware samples posing as “agentic AI” software.

Those figures come from one vendor’s own detection data, so they describe what its products saw rather than the whole internet. But they line up with a string of separate reports this year:

  • Fake download sites. In May 2026, Malwarebytes described a fake ChatGPT download site that people reached through search results, ads and social posts. Windows users received password-stealing malware; Mac users received a different stealer that went after saved passwords, browser data and cryptocurrency wallets.
  • Fake installers on code-sharing sites. Also in May, Help Net Security reported Malwarebytes research into fake ChatGPT and Claude installers hosted on GitHub and SourceForge, promoted through compromised YouTube channels with AI-generated videos that had gathered more than 50,000 views.
  • Fake browser extensions. In January 2026, SecurityWeek reported research by OX Security on two Chrome extensions, with around 900,000 downloads combined, that impersonated a legitimate AI sidebar tool and harvested users’ ChatGPT and DeepSeek conversations along with their browsing activity.
  • Fake mobile apps. Mobile security firm Zimperium reported in April 2026 on malicious Android apps posing as ChatGPT tools, often promoted through unofficial channels, that could steal credentials and sensitive data.

The pattern is clear: criminals are using the excitement around AI assistants, and the fact that many people do not yet know where the real apps live.

What do fake AI apps actually do?

Not every fake is equally dangerous, but the reported types fall into a few groups:

Type of fakeHow people usually find itWhat it may do
Fake desktop downloadSearch ads, look-alike websites, social postsInstall password stealers or remote-access malware
Fake installer on a code siteYouTube tutorials, links in commentsInstall malware that can take control of the computer
Fake or malicious browser extensionExtension store searches, “enhance ChatGPT” promisesCopy your AI chats, browsing history and session data
Fake mobile appThird-party app sites, messaging linksSteal logins and personal data
Copycat “AI” app with a real listingOfficial stores, adsWrap a genuine AI service in heavy subscriptions or excessive data collection

The first four rows reflect the 2026 research above; the last row is our editorial observation rather than a finding from those reports. Not every unofficial AI app is malware. Many are legitimate third-party products that use an AI company’s technology. The problem arises when an app pretends to be the official one, or when it charges a lot for something the official app offers for free. The warning signs below help you tell these apart.

What are the warning signs of a fake AI app?

None of these proves an app is fake on its own, but two or more together should make you stop.

  • The developer name is wrong. The real ChatGPT app is published by OpenAI, Claude by Anthropic, and Gemini by Google. A listing called “Chat GPT AI Assistant” from an unknown developer is not the official app, whatever its icon looks like.
  • You found it through an ad. The FTC’s guidance on malware specifically advises people not to click on ads for software and instead to type the company’s web address directly. Fake download sites have repeatedly used paid search ads to appear above the real one.
  • The download comes from somewhere unusual. Official desktop apps come from the company’s own website or a major app store. A zip file on a file-sharing site, a GitHub page you were sent to by a video, or a link in a chat message is a red flag.
  • You are asked to paste a command. Several 2026 campaigns asked people to copy a line of text into their computer’s terminal to “install” the app. Ordinary consumer apps do not install this way. Treat any instruction to paste a command from a video or website you do not fully trust as a stop sign.
  • It promises something the real app does not. “Unlimited GPT free forever”, “premium unlocked” or “no login needed” are classic lures.
  • It asks for far more access than it needs. An AI chat app has no obvious reason to request access to your text messages, call logs or accessibility controls.
  • It pushes you to pay immediately. A hard paywall the moment you open the app, particularly a weekly subscription, is a common sign of a copycat trying to earn money from confusion.
  • Your security software warns you. On a Mac, Apple says an “unidentified developer” warning means the developer cannot be verified or the app has not been notarised. On Android, Google Play Protect may warn about harmful apps. Take these warnings seriously rather than clicking past them.

How do you check an AI app before installing it?

A two-minute check is enough for almost every case.

  1. Start from the company’s own website. Type the address yourself instead of searching for “download”. OpenAI’s official download page, for example, links to its iOS and Android apps in the Apple App Store and Google Play, and to its Mac and Windows apps. Following the company’s own links is the single most effective protection.
  2. Check the developer name on the store listing. It should be the company you expect (OpenAI, Anthropic, Google, Microsoft and so on).
  3. Look at the listing details. Apple points users to Privacy Nutrition Labels, which show how an app may collect data such as location, browsing history and contacts, and to ratings and reviews from other users. Look for recent, specific reviews rather than a wall of identical five-star ones.
  4. Check the permissions it asks for. If a request does not make sense for what the app does, deny it or uninstall.
  5. Be extra careful with browser extensions. Given the 2026 reports about extensions harvesting AI chats, install as few as possible, check who publishes them, and remove any you no longer use. An extension that can “read and change data on all websites” can see everything you type into a web-based AI assistant.

If you use AI agents that connect to your email, calendar or files, the same caution applies to the apps and services you link to them. Our guide on reviewing apps connected to your accounts explains how to audit those links.

What protections do app stores and operating systems provide?

Official stores and operating systems add real layers of protection, though none is perfect.

Apple says every app in the App Store is reviewed by a member of its App Review team, and that it monitors and investigates fraudulent activity daily. On Macs, Apple’s Gatekeeper checks that software downloaded outside the App Store comes from an identified developer and has been notarised, which Apple describes as meaning it checked the software for malicious components and found none. Apple warns that running software that has not been signed and notarised may expose your computer and personal information to malware.

Google says Play Protect runs a safety check on apps from the Play Store before you download them, checks your device for potentially harmful apps from other sources, can warn you about apps that break its policies, and may deactivate or remove harmful apps. It is on by default, and Google recommends keeping it on. You can confirm this in the Play Store by tapping your profile icon, choosing Play Protect and checking that app scanning is switched on.

These systems catch a lot, but the 2026 extension cases show that harmful software can still reach official stores for a time. Think of store protections as a safety net, not a guarantee.

Why do fake AI apps target your chats?

AI chats are unusually revealing. People paste in work documents, health questions, family plans, passwords by mistake, and personal worries. A malicious extension that copies those conversations collects exactly the kind of material scammers can use for convincing phishing or blackmail.

That is also why the risk grows as assistants become agents. When an AI app can connect to your email, calendar or payment methods, a fake version is not only a privacy problem but a potential route into your accounts. Our explainer on whether AI agents are safe covers that wider picture, and our guide to AI agent scams describes other tricks that use the same excitement.

It is also a reason to review what your real AI assistant remembers about you. If you have ever pasted something sensitive, our guide to what AI memory stores and how to delete it shows where to look.

What should you do if you installed a fake AI app?

If you suspect a fake, act quickly but calmly. The FTC’s general advice on malware includes these steps:

  • Stop using the device to log in to sensitive accounts such as banking or email.
  • Update or install security software from a trusted source and run a full scan.
  • Uninstall the suspicious app or extension.
  • From a different, clean device, change your passwords and turn on two-step verification, starting with email (since email can reset everything else).
  • Get help from the device maker, a trusted technician, or your employer’s IT team if it is a work device.

Malwarebytes, describing the fake ChatGPT download campaign, advised affected users to sign out of all accounts and change passwords, move any cryptocurrency to a clean device, and, in serious cases, reinstall the operating system. That is a heavier response, appropriate when the malware was designed to steal credentials.

Also watch your bank and card statements for unfamiliar payments, and cancel any subscription a copycat app signed you up to through your app store’s subscription settings. In the US, you can report fraud to the FTC at ReportFraud.ftc.gov; Apple lets you report a problem with an App Store purchase at reportaproblem.apple.com. Other countries have their own national fraud-reporting services.

Who is most at risk, and how can you protect family members?

Anyone can be caught, but a few groups are more exposed: people trying AI for the first time who do not know where the official apps live, students looking for “free premium” versions, and anyone who installs lots of browser extensions to boost productivity. People who use AI tools at work should be especially careful, because a fake installed on a work laptop can expose company data.

If you help older relatives or teenagers with technology, the most useful thing you can do is install the official apps for them and show them the developer name to look for. A short family rule works well: “We only install AI apps from the official website or store, and we ask before installing anything a video tells us to.” The same household habits that defend against voice-cloning scams, such as those in our guide to a family code word, apply here too.

A quick checklist to keep:

  • Get AI apps from the company’s own site or its official store listing.
  • Check the developer name every time.
  • Skip ads and “free premium” offers.
  • Never paste terminal commands from videos or strangers.
  • Keep extensions to a minimum and review them regularly.
  • Keep Play Protect and your operating system’s security features switched on.

Key takeaways

  • Security researchers documented tens of thousands of attacks disguised as AI services in 2026, with ChatGPT the most imitated, according to Kaspersky.
  • Fakes arrive through search ads, look-alike sites, code-sharing pages promoted on YouTube, browser extensions and unofficial app downloads.
  • The strongest defence is starting from the AI company’s own website and checking the developer name on any store listing.
  • Treat requests to paste commands, “premium unlocked” promises and heavy permission requests as red flags.
  • If you installed a fake, stop using sensitive accounts on that device, scan and remove it, and change passwords from a clean device.

Fake AI app FAQs

How can I tell if a ChatGPT app is fake?

Check the developer name. The real ChatGPT app is published by OpenAI, Claude by Anthropic and Gemini by Google. If the listing shows anyone else, it is not the official app.

Can a fake AI app get into the official app stores?

Occasionally. Apple and Google review apps, but harmful browser extensions have reached official stores for a time. Store checks are a safety net, not a guarantee.

What should I do first if I installed a fake AI app?

Stop logging in to sensitive accounts on that device, run a security scan and remove the app. Then change your passwords from a clean device, starting with email.

Sources