Phishing Scam Hijacks Call of Duty Mobile Accounts via Fake Free Points Giveaway
What Happened — Attackers published a counterfeit “free Call of Duty Points” landing page that collected users’ email addresses, passwords, and subsequently their 2FA codes. The site relays credentials in real‑time to Activision’s legitimate login page, allowing the scammers to capture the one‑time code and take full control of the account. Victims can lose in‑game currency, linked payment methods, and personal purchase history.
Why It Matters for Compliance & Audit Readiness
- Demonstrates a classic failure of SOC 2 Access Control safeguards: inadequate verification of credential‑submission channels and missing controls around credential‑relay attacks.
- Highlights the need for continuous monitoring of authentication logs and evidence that MFA enforcement is both configured and verified, a core requirement of the SOC 2 CC6.1 (Logical Access) criterion.
- Underlines the importance of Security Awareness Training that teaches users to verify URLs and avoid credential‑phishing, satisfying the SOC 2 CC6.2 (Security Awareness) control.
Who Is Affected — Mobile gaming companies, digital entertainment platforms, and any service that relies on linked third‑party accounts (e.g., Xbox, PlayStation, Battle.net).
Recommended Actions
- Immediately enforce a password reset for any account that may have entered credentials on the fake site.
- Re‑issue or invalidate existing 2FA tokens and require re‑enrollment for affected users.
- Conduct a log‑review for anomalous login activity and terminate all active sessions.
- Update your phishing‑simulation program to include a “fake in‑game reward” scenario and track completion rates as audit evidence.
- Document the incident response steps in your SOC 2 evidence repository to demonstrate due diligence.
Technical Notes — The campaign uses a phishing vector with a real‑time credential relay that forwards entered credentials to Activision’s login endpoint, then captures the generated 2FA code on a second spoofed page. No CVE is involved; the threat relies on social engineering and credential‑theft techniques.
Source: Help Net Security