Skip to main content
Promotional banner for the pentest readiness checklist
Genesis Tech Takedown: Subscription Fraud at ScaleRegulatory Bodies
4 min readFor Compliance Officers

Genesis Tech Takedown: Subscription Fraud at Scale

What Happened

The Federal Trade Commission (FTC) secured a temporary halt against Genesis Tech, a network of 15 corporations and eight individuals running deceptive subscription schemes. Led by Vladimir Mnogoletny and Vasily Ulianov, the enterprise marketed products from ADHD self-help programs to PDF editing tools, all while hiding subscription terms, charging consumers without consent, and obstructing cancellations. From early 2023 to mid-2025, five of their products generated nearly $250 million globally through these practices.

The operation used a complex corporate structure: Cyprus-registered marketing entities targeted U.S. consumers, Delaware-incorporated payment processors, and a cycle of new company registrations and merchant accounts to evade fraud detection.

Timeline

Early 2023, Mid-2025: Genesis Tech's core products (MadMuscles, Harna, Unimeal, Wisey, PDF Guru, PDF Master, Lumi, and Nebula) amassed nearly $250 million in global revenue through deceptive practices.

Throughout operation: The enterprise launched new products, registered fresh corporate identities in Cyprus and Delaware, and opened new merchant accounts to avoid fraud monitoring.

Legal action: The FTC filed a complaint in U.S. District Court for the Northern District of California, securing a temporary halt to operations.

Which Controls Failed or Were Missing

Disclosure Controls: Genesis Tech advertised products as free or for one-time fees while hiding subscription terms in fine print. Their websites didn't clearly present material terms before purchase. Consumers couldn't find recurring charge disclosures before clicking "buy."

Transaction Authorization: The enterprise charged consumers for unauthorized subscriptions, double-billed for the same product, and added products without consent. No step verified consumer understanding of auto-renewing subscriptions.

Cancellation Mechanisms: Consumers faced missing cancellation options, mandatory justification requirements, and continued charges post-cancellation. The enterprise designed friction into every exit point.

Corporate Transparency: The Cyprus-Delaware shell structure obscured ownership and routed funds across borders to hide assets. Payment processors couldn't identify the common enterprise behind seemingly unrelated merchant accounts.

Continuous Monitoring: As fraud detection systems flagged accounts, Genesis Tech registered new entities and opened fresh accounts. No control prevented the same operators from re-entering the payment ecosystem under different names.

What the Relevant Standards Require

The Restore Online Shoppers' Confidence Act (ROSCA) sets specific requirements for negative option marketing:

  • Clear and conspicuous disclosure of all material terms before obtaining billing information, including recurring charges.
  • Express informed consent to the charges, separate from any other transaction part.
  • Simple cancellation mechanism as easy as the subscription method.

The FTC Act's prohibition against unfair or deceptive practices extends these requirements. You can't hide material terms in fine print, charge consumers for unauthorized items, or make cancellation difficult.

For your subscription business, ROSCA compliance requires:

  1. Presenting subscription terms before payment information collection: Display recurring charges, charge amount, frequency, and cancellation policy near the purchase button or form submission.

  2. Obtaining affirmative consent: A pre-checked box doesn't meet this requirement. Consumers must take an action showing they understand they're enrolling in a subscription.

  3. Providing cancellation mechanisms as accessible as signup: If consumers can subscribe through your website, they must be able to cancel through it. If they can subscribe through your app, they must be able to cancel through it. Requiring phone calls or email explanations when signup was self-service violates ROSCA.

Lessons and Action Items for Your Team

Audit your subscription flow today. Walk through your purchase path as a consumer. Can you identify the recurring charge before entering payment information? Is the subscription term disclosed as prominently as the initial price? If your answer is "it's in the terms of service" or "it's mentioned in the footer," you're not compliant.

Test your cancellation process quarterly. Create test accounts and attempt to cancel them using only consumer-available mechanisms. Time the process. Count the clicks or screens required. Compare this to your signup flow. If cancellation requires more steps than signup, you've built ROSCA risk into your product.

Map your corporate structure for payment processors. If you operate multiple entities or brands, document the common ownership and control relationships. Payment processors need this visibility for effective fraud monitoring. The Genesis Tech approach of obscuring these connections through shell companies wasn't just deceptive to consumers; it was designed to evade fraud detection systems.

Review authorization controls for subscription modifications. Genesis Tech charged consumers for products they never ordered and double-billed for the same service. Your systems must require explicit authorization before adding products to an existing subscription or processing duplicate charges. Implement transaction-level verification that matches the charge to a specific consumer action.

Document your disclosure testing. When you update subscription terms or pricing, conduct user testing to demonstrate consumer understanding of material terms before purchase. Keep records of this testing. If the FTC investigates, you'll need evidence that your disclosures were effective, not just technically present on the page.

Monitor your merchant account health. If you're seeing elevated chargeback rates, dispute patterns, or fraud flags, don't respond by opening new accounts under different entity names. That pattern signals intent to evade detection. Instead, fix the underlying disclosure and authorization problems causing the disputes.

The Genesis Tech case shows that subscription fraud at scale requires deliberate architectural choices: shell companies, cross-border fund transfers, continuous entity registration. If your compliance program treats these as separate operational decisions rather than connected fraud indicators, you're missing the pattern. Your job isn't just to check the ROSCA boxes on your current checkout flow. It's to ensure your corporate structure, payment processing relationships, and product development cycles don't enable the systematic evasion Genesis Tech built into their business model.

Promotional banner highlighting failures found in PCI audits and how to spot the gaps

You Might Also Like