Fake Claude Max Giveaway Phishing Traps Google Account Credentials
What Happened — A phishing campaign pretends to give away free Claude Max AI subscriptions, displaying a realistic Google sign‑in window that captures entered credentials. No payment or download is required; the site merely harvests Google account logins.
Why It Matters for Trust & Control Assurance —
- Highlights the need for strong identity and access management controls (MFA, credential monitoring) to prevent account takeover.
- Demonstrates why continuous security awareness training is essential to recognize deceptive sign‑in prompts.
- Provides a concrete scenario where audit evidence of MFA enforcement and login‑activity logging can defend against credential‑theft risks.
Who Is Affected — Users of AI SaaS platforms (e.g., Anthropic’s Claude) and any organization that relies on Google accounts for single sign‑on.
Recommended Actions — Enforce MFA on all Google accounts, implement real‑time monitoring for anomalous sign‑ins, conduct targeted phishing awareness training, and review third‑party access policies. Source: Malwarebytes Labs
Technical Notes — Attack vector: phishing via a counterfeit OAuth‑style sign‑in page; no malware payload. Data at risk: Google credentials granting access to email, Drive, and linked services. Source: Malwarebytes Labs