Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Fake Claude Max Giveaway Phishing Traps Google Account Credentials

A new phishing campaign masquerades as a free Claude Max AI subscription giveaway, using a counterfeit Google sign‑in window to steal users’ Google credentials. The scheme targets AI service users, potentially exposing email, documents, and other linked accounts. This highlights the need for robust identity controls and user awareness in audit readiness.

LiveThreat™ Intelligence · 📅 September 25, 2026· 📰 malwarebytes.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
1 recommended
📰
Source
malwarebytes.com

Fake Claude Max Giveaway Phishing Traps Google Account Credentials

What Happened — A phishing campaign pretends to give away free Claude Max AI subscriptions, displaying a realistic Google sign‑in window that captures entered credentials. No payment or download is required; the site merely harvests Google account logins.

Why It Matters for Trust & Control Assurance —

  • Highlights the need for strong identity and access management controls (MFA, credential monitoring) to prevent account takeover.
  • Demonstrates why continuous security awareness training is essential to recognize deceptive sign‑in prompts.
  • Provides a concrete scenario where audit evidence of MFA enforcement and login‑activity logging can defend against credential‑theft risks.

Who Is Affected — Users of AI SaaS platforms (e.g., Anthropic’s Claude) and any organization that relies on Google accounts for single sign‑on.

Recommended Actions — Enforce MFA on all Google accounts, implement real‑time monitoring for anomalous sign‑ins, conduct targeted phishing awareness training, and review third‑party access policies. Source: Malwarebytes Labs

Technical Notes — Attack vector: phishing via a counterfeit OAuth‑style sign‑in page; no malware payload. Data at risk: Google credentials granting access to email, Drive, and linked services. Source: Malwarebytes Labs

📰 Original Source
https://www.malwarebytes.com/blog/threat-intel/2026/09/fake-claude-max-giveaway-hides-a-google-account-phishing-trap ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Could you prove your access controls held up here?

Credential and access failures map directly to identity and access-control requirements in every major framework. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →