Yes, fake ChatGPT apps are common. Install AI apps only from the vendor's own website or the store listing it links to, check the publisher is the real company (OpenAI, Anthropic, Google, Microsoft), never download through a search ad, and for extensions read the permissions: anything that can read all websites can read your AI chats.
Ratings and badges don't settle it. At the turn of 2026, researchers reported two Chrome extensions copying ChatGPT and DeepSeek conversations from about 900,000 users; the larger one carried Google's Featured badge. Another Featured extension, a free VPN rated 4.7 stars, had been harvesting AI chats since an update in July 2025, across publisher extensions with roughly 8 million users.
Four ways fake and risky AI tools reach a small business
Knowing the pattern helps staff recognise it. Almost every case falls into one of these four.
1. Lookalike apps that charge for something free
App stores carry "AI chat" apps with names and icons close to ChatGPT, Gemini or Claude. Many are thin wrappers around another company's model, sold on weekly subscriptions. Security firms have documented coordinated networks of these on desktop and mobile stores, some harmless apart from the price, some collecting far more data than a chat app needs. The genuine ChatGPT app is free to download and lists OpenAI as the developer; paying a third party for basic ChatGPT access is a sign you are in the wrong place.
2. Malware delivered through search adverts
In late May 2026, researchers at Push Security and Malwarebytes described a campaign that bought sponsored search ads for phrases like "ChatGPT desktop app". The ads led to real chatgpt.com shared-conversation links that displayed a fake outage notice, then pushed visitors to a lookalike download site. The download installed password-stealing malware on Windows and Mac, after which attackers could reuse saved browser passwords and session tokens. The official ChatGPT desktop app comes from OpenAI's own site or the Microsoft Store, never from a page you reached through an ad.
3. Extensions built to collect your chats
The two extensions in the 900,000-user case imitated a legitimate AI sidebar product. According to OX Security, they asked users to agree to "anonymous, non-identifiable analytics", then sent complete ChatGPT and DeepSeek conversations and the address of every open tab to the attackers' servers every 30 minutes. For a business, that means every client name, price and draft contract anyone typed into an AI chat.
4. Good extensions that turn bad
This is the hardest one to spot, because you did nothing wrong at install time. On Christmas Day 2024, an attacker phished a Cyberhaven employee into approving a malicious app that could publish to the Chrome Web Store, then pushed an update of the company's extension that stole cookies and login sessions for social media and AI platforms. It was live for under 24 hours, but researchers linked it to a wider campaign affecting dozens of extensions. The VPN case above was similar: earlier versions were clean, and the chat collection arrived through an automatic update.
The lesson from the fourth pattern is that "it was fine when we installed it" isn't a defence. Fewer extensions means fewer chances for one of them to change hands or be compromised.
A 60-second check before installing any AI app
Run through these before anyone installs an AI app or extension on a work device. Each takes seconds.
- Start from the vendor, not a search. Type the vendor's address yourself (chatgpt.com, claude.ai, gemini.google.com) and use the download or store link on that site. Why: it skips ads and lookalike domains entirely.
- Check the publisher name exactly. The developer line should be the real company. Why: fakes copy the icon and title, rarely the verified developer name.
- Check the address bar spelling on any download page. Why: lookalike domains add a letter or swap the ending, and a padlock icon only means the connection is encrypted, not that the site is genuine.
- Look at the price model. A subscription just to open the app, or a pop-up demanding payment before the first question, is a warning sign for a tool whose maker offers a free tier.
- Read the one-star reviews. Why: complaints about surprise charges or "this isn't the real one" appear there first.
- Read the permissions or privacy section. Chrome Web Store listings have a privacy practices section where the developer declares what data it collects. Why: an AI writing tool that collects "website content" and "web history" can see far more than your drafts.
- Ask whether you need it at all. Why: the web version of most AI assistants does the job with no install.
The address check deserves an example, because lookalike domains are built to pass a quick glance. Illustrative pairs of the kind attackers register: a real chatgpt.com against a fake with an extra word or a different ending; a real claude.ai against one with a hyphen added; a real openai.com download page against a site whose name only starts with "open". If the domain isn't exactly the one on the vendor's own site, close the tab.
An illustrative side-by-side of two store listings shows how small the differences can look:
| Detail | Genuine listing | Lookalike listing |
|---|---|---|
| Title | ChatGPT | Chat AI - GPT Assistant |
| Developer | OpenAI | An unfamiliar company name |
| Price | Free, with paid plans inside | Weekly subscription after a 3-day trial |
| How you found it | Link on chatgpt.com | Top result for "chatgpt app" in the store search |
| Reviews | Mixed, about features | Many mention unexpected charges |
Reading an extension's permissions like a contract
Chrome shows a permission warning when you add an extension. Most people click through it. It is the most useful ten seconds of the whole process.
| Warning you see | What it means | Reasonable for |
|---|---|---|
| Read and change all your data on all websites | It can see and alter every page in every tab, including AI chats, webmail, accounting and banking | Only tools that genuinely work on every site, from a company you already trust |
| Read your browsing history | It sees every address you visit | Rarely needed by an AI writing or summary tool |
| Read and change data on a list of named sites | Access limited to those sites | A tool that only works on, say, your CRM |
| Manage your downloads | It can see and start downloads | Download managers, not AI assistants |
| Manage your apps, extensions, and themes | It can switch other extensions on or off | Almost never needed; treat as a red flag |
On the badges: Google says the Featured badge means Chrome staff reviewed the extension against its best practices, and Established Publisher means the developer's identity is verified with a good compliance record. Both are useful signals, but the chat-stealing cases show they describe the extension when it was reviewed, not what its next update will do.
Auditing the browsers you already have: a locksmith's office
Here is an illustrative audit. A four-person locksmith business has two office PCs used for bookings, quotes and supplier orders, plus the owner's laptop. The office PCs are shared by two people. The owner typed chrome://extensions into the address bar on each machine (on Edge, edge://extensions) and listed what was there.
Across three machines there were 14 extensions. The ones that needed a decision:
- Two different AI sidebar extensions, both with "read and change all your data on all websites". One had been installed to summarise supplier price lists. Both removed; staff use the ChatGPT Business web app instead, where the firm's data isn't used for training.
- A free VPN extension a staff member had added to watch a sports stream. Removed.
- A coupon finder that also read all sites. Removed.
- An AI grammar checker signed in with a former employee's email. Removed, and the owner added it to the leaver list for next time.
- The booking system's own extension, limited to the booking site. Kept.
- The password manager extension. Kept.
The finding that mattered most was the combination: shared PCs, sidebar extensions that could read every tab, and a bookings screen that shows customers' home addresses and, for some jobs, notes about alarm systems and key safes. For a business whose customers trust it with physical access, chat collection of that kind is a serious exposure. The audit took 25 minutes. The owner then asked each person to check their own phone for AI apps installed from search results, which turned up one lookalike chat app with a weekly subscription, cancelled the same day.
If your audit turns up AI tools people installed because the approved ones felt slower, that is a sign of a wider habit; stopping shadow AI deals with the cause rather than the symptom. And extensions are only one kind of access: apps connected to your Google or Microsoft accounts are covered in checking which apps can access your business accounts.
Phones: the AI apps staff install themselves
Work phones and personal phones used for work get less attention than office PCs, and they are where most lookalike chat apps end up. A five-minute phone check covers three things:
- Subscriptions. On iPhone, open Settings, tap your name, then Subscriptions; on Android, open the Play Store, tap your profile, then Payments & subscriptions. Any "AI chat" subscription that isn't the genuine vendor's plan should go. Deleting an app doesn't cancel its subscription, which is how people keep paying for months.
- Permissions. A chat app asking for your contacts, text messages or constant location has no need for them. On Android, be especially wary of any app asking to be turned on under accessibility settings; that permission lets an app read and control what is on screen, and malware disguised as useful apps is known to request it.
- Where it came from. Apps installed from a link in a message, a pop-up or a file outside the official store should be removed on a work phone, whatever they claim to be.
For the locksmith, one engineer's phone had an "AI Chat Pro" app at a weekly subscription, installed after searching the store for "chatgpt". It had been charging for nine weeks. Cancelling it and installing the genuine app from the link on chatgpt.com took two minutes; the money already spent was a lesson in checking the developer line.
Put company browsers on an allowlist
Once you know what you need, stop the list growing back. If your business uses Google Workspace and Chrome, you can manage browsers from the Admin console: under Devices, then Chrome, then Apps & extensions, then Users & browsers, set the allow/block mode to "Block all apps, admin manages allowlist, users may request extensions", then add the handful you approved. Google's Chrome Enterprise help on allowing or blocking extensions covers the options, including force-installing the password manager so it is always there. Microsoft Edge can be managed in a similar way through Microsoft's device management tools.
For the locksmith, the allowlist is three items: the password manager, the booking system's extension and a PDF tool. Staff can request others, and the owner checks each request against the 60-second list above. A realistic cost is an hour to set up and a few minutes a month to answer requests.
AI browser agents, the newer tools that click and type on web pages for you, raise the same questions with higher stakes, since they can act as well as read; whether staff should use an AI browser agent goes through them.
If someone installed a bad one
Here is a realistic way it happens. An office assistant wants the ChatGPT desktop app, searches for it, clicks the top sponsored result, sees an "outage" message on what looks like ChatGPT's own site and downloads the "desktop version" it offers. A few days later, the business email account starts sending invoice requests to customers that nobody wrote.
Work through this in order, the same day:
- Disconnect and remove. Uninstall the extension or app. If a program was downloaded and run on a computer, take that machine off the network and get it checked or reinstalled by whoever handles your IT; password-stealing malware is not reliably removed by deleting one file.
- Sign out everywhere. From a clean device, sign the affected person out of all sessions on email, AI tools, banking and your booking or accounting system.
- Change passwords and second factors, starting with email, then any account whose password was saved in that browser.
- Rotate API keys the person could see, and review recent usage on each AI platform for calls you don't recognise.
- Check what was exposed. Look through the person's AI chat history for client details, prices and documents. That tells you whose data may have been taken.
- Warn customers if your email was used, especially about payment requests, so nobody pays a fake invoice. Staff awareness of AI-written fake emails is covered in training staff to spot AI-written phishing.
- Take advice from your data-protection adviser if client personal data may have been exposed, and keep a dated note of each step.
A week later, check the clean-up held. Look at the email account's sent folder and sign-in history for anything after the password change, the AI platforms' usage pages for unfamiliar activity, and the browser's extension list on the affected machine. If all three are quiet, close the incident note with the date. If any of them shows activity you can't explain, repeat the sign-out and password steps and bring in whoever manages your IT before doing anything else.
A short note to send your team
AI apps and browser add-ons: our rules
1. Get AI apps from the maker's own website (chatgpt.com, claude.ai,
gemini.google.com) - never from a search ad or a pop-up.
2. Don't add browser extensions to work computers. If you need one,
send me the link and I'll check it the same day.
3. Never pay for an AI app yourself to use at work. Ask first.
4. If a page says the website version is "down" and offers a download,
close it and tell me.
5. Our approved tools: ChatGPT Business (web and official app),
password manager, booking system extension.
Keep it that short. The point is a habit, not a policy document, and the fifth line matters most: people install lookalikes when they don't know which tool is the approved one.
Questions about fake AI apps and extensions
How can I tell if the ChatGPT app on my phone is the real one?
Open chatgpt.com in your phone's browser and follow its link to the app store, then compare the listing with the app you have. The genuine app lists OpenAI as the developer and is free to download, with paid plans sold inside it. If your app came from a search result, charges a subscription just to open, or lists another developer, delete it and cancel any subscription through your app store account.
Are AI sidebar extensions safe to use at work?
Some are, but they need the broadest permission there is, the ability to read every page you open, which includes your AI chats, webmail and banking. Only allow ones from a company you already trust, with a clear privacy policy and a business reason. For most small teams the AI tool's own website or desktop app does the same job without that exposure.
What if someone already typed client details into a fake AI app?
Remove the app or extension, sign that person out of all sessions on email and AI accounts, change their passwords and rotate any API keys. Then work out what was entered and whose data it was. If personal data about clients may have been exposed, take advice from your data-protection adviser on whether you must notify anyone, and keep notes of what you found and when.
Further reads
- How to Spot Deepfake Voice and Video Scams Aimed at Your Business — The other AI-powered scam aimed at small firms, and how to verify callers.
- How to Turn On Two-Factor Authentication for Every AI Account — Limits the damage if a fake app captures a password.
- How to Write an AI Usage Policy for Your Small Business — Put the approved-apps rule in your staff policy.
- Does Cyber Insurance Cover AI Incidents? What Insurers Ask — What insurers ask about controls like browser allowlists.
- Staff Offboarding Checklist for AI Tools and Shared Accounts — Remove extensions and AI logins when people leave.
- AI Security Risks for Small Businesses and How to Close Them — Eleven AI security risks in a small business, each with a real-world example, how to close it, how to check it's closed, and when to do it.
- Shadow AI: Is Your Team Using AI Without Telling You? — How to find the AI tools your staff use without telling you: an amnesty survey, five afternoon checks, and a keep-move-stop rule for each thing you find.
- Is Instagram DM Automation Safe? What Gets Accounts Banned — How to tell an official DM tool from a password bot, the rules Meta's API enforces, the behaviours that still trigger restrictions, and a setup risk score.
- How to Use Claude With Excel and Google Sheets Safely — The three ways Claude reaches a spreadsheet, what each sends, the prompt-injection warning in Anthropic's own docs, and a formula check routine.
- Are Chat-With-PDF Tools Safe for Contracts and Client Files? — Which chat-with-PDF tools keep, train on or delete your contracts and client files, and how to check the answers before you rely on them.
- How to Choose a Managed IT Provider That Can Support AI Tools — A two-site garage's AI tools, eight questions for IT providers and a first-month audit that found six problems: how to pick an MSP that can support AI properly.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: OX Security research on two Chrome extensions exfiltrating ChatGPT and DeepSeek chats (reported to Google December 2025); Koi Security research on Urban VPN Proxy harvesting AI conversations (December 2025); Cyberhaven's incident statement (December 2024); Malwarebytes and Push Security reports on the fake ChatGPT desktop download campaign (May 2026); Chrome Web Store documentation on Featured and Established Publisher badges; Chrome Enterprise Help (allow or block apps and extensions).