Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Phishing

Fake Claude Max giveaway steals Google accounts

A convincing site offering free Claude Max subscriptions uses a fake Google sign-in window to steal login details, Malwarebytes warns.

By · Published · Updated · 9 min read

Fake Claude Max giveaway steals Google accounts

A fake giveaway promising free Claude Max subscriptions is stealing Google account logins, Malwarebytes reports.

How the scam works

  • The site claims Anthropic is giving away 10,000 free one-month Claude Max subscriptions to celebrate 100 million users.
  • A counter says fewer than 750 remain. It is fake — it is generated in your browser and resets when you reload.
  • It uses real logos, invented five-star reviews and a footer full of links to genuine Anthropic pages.
  • To "claim", you sign in through what looks like a Google login window. It is a fake page that sends your password to criminals.

Malwarebytes researcher Stefan Dasic, who first documented the campaign on September 23, 2026, noted that the lure is unusually polished: the page borrows real Anthropic branding and links almost entirely to genuine Anthropic pages, so that only the final sign-in step is fraudulent (Malwarebytes). Coverage of the campaign noted that the page also offers an "Apple" sign-in button that simply returns a "temporarily unavailable" message and an email field that silently discards whatever address is typed, funnelling every visitor toward the Google sign-in button regardless of what they choose (MalwareTips).

Timeline of the campaign

  • June 2026 — Microsoft's threat intelligence team warned that it was seeing a growing wave of phishing, malicious advertising and search-based scams impersonating AI brands including ChatGPT, Claude, DeepSeek and Copilot.
  • September 23, 2026 — Malwarebytes published its analysis of the fake Claude Max giveaway, describing the full attack chain from the landing page to the spoofed Google sign-in window.
  • Following days — Multiple outlets, including Digital Trends and news4hackers, republished and expanded on the findings, helping push awareness of the scam to a wider, non-technical audience (Digital Trends).

Part of a wider trend

Microsoft reported in June that it was seeing more phishing, malicious ads and search scams impersonating ChatGPT, Claude, DeepSeek and Copilot. Some fake failed payments; others push malware downloads. Reporting on the Claude Max scam pointed out that this particular campaign is different from many of those: it never asks for a credit card number and never offers a download, which makes it feel safer to a cautious user even though the endgame — handing over a Google password — can be more damaging than a one-off card scam (Digital Trends).

Why AI brands are now prime bait

AI tools have become everyday products for hundreds of millions of people, and paid plans can cost a lot each month. Claude's Max plan itself starts at $20 a month and rises considerably for higher usage tiers, according to Malwarebytes' writeup, which makes a "free" high-tier subscription a genuinely attractive offer rather than an obviously implausible one. Many users are still unfamiliar with how these companies run their promotions — which makes fake giveaways believable.

Researchers have also found fake AI apps and browser extensions that install malware, and fake AI websites promoted through search ads. As generative AI tools have become mainstream over the past two to three years, criminals have simply pointed existing phishing playbooks — fake giveaways, fake renewal notices, fake customer support portals — at the newest wave of popular software brands.

The fake Google login trick

The sign-in window in this scam is not a real browser pop-up. It is drawn inside the web page to look like one, a technique known as "browser-in-the-browser" (BitB). It can show a convincing address bar with accounts.google.com, even though you never left the scam site. The BitB technique has been publicly documented by security researchers since at least 2022 and has since been adopted widely because it defeats the simplest advice people are given — "check the address bar" — by faking the entire browser chrome, not just the page content.

One write-up of the Claude Max campaign noted that the fake window can be dragged around the page like a real window, and that its underlying code contained comments written in Russian referring to "victims," suggesting the phishing kit itself is a reusable, likely Russian-language criminal tool sold or shared among multiple operators rather than something built from scratch for this one campaign (ZeroHour).

A simple test: try to drag the "pop-up" outside the browser window. A real window will move; a fake one is trapped inside the page.

Why your Google account matters so much

Your Google account often unlocks Gmail, Drive, Photos, saved passwords and the password reset emails for many other services. Losing it can give a criminal a route into almost everything else. Because a Google login can also be linked to an Anthropic account that uses "Sign in with Google," a stolen credential in this specific campaign can hand an attacker both a victim's broader digital life and their AI chatbot history and billing details in one step.

Why no card details are needed

Unlike many scams that try to harvest a credit card number directly, this one profits purely from credential theft. A compromised Google account can be used for account takeover fraud, further phishing against the victim's contacts, resale on criminal marketplaces, or as a stepping stone into a workplace account if the victim reused the same login for business services.

How to stay safe

  • Check promotions on the company's official website or social media accounts — free upgrades from AI companies are announced there, not on third-party pages.
  • A real Google sign-in always shows accounts.google.com in the browser's address bar — check before typing, and remember a fake pop-up window can forge that text too.
  • Try dragging any sign-in pop-up outside the browser window; if it cannot leave the page, it is fake.
  • Turn on passkeys or two-step verification for your Google account so a stolen password alone is not enough to break in.
  • Use a password manager, which will not auto-fill credentials on a look-alike domain even if the page looks identical to the real one.
  • Review connected devices and third-party access in your Google account security page if you think you were caught out, and change your password immediately from a device you trust.

What readers should do

  • If you entered your Google password on a suspicious giveaway page, change it immediately from a separate, trusted device.
  • Check Google's "Recent security activity" page for sign-ins you do not recognize.
  • Revoke access for any unfamiliar connected apps under Google Account → Security → Third-party apps with account access.
  • Enable 2-Step Verification or, better, register a passkey, so a stolen password cannot be reused by an attacker.
  • Watch your email for password-reset attempts on other services, since criminals often pivot from a stolen Gmail login into banking, shopping and social media accounts.
  • Report the phishing site to Google Safe Browsing and to Anthropic, and warn friends or colleagues who might have seen the same ad or link.

Sources

Read next