Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Fake Claude Max Giveaway Phishing Harvests Google Credentials

A spoofed Claude Max giveaway site tricks users into entering Google credentials through a draggable browser‑in‑the‑browser window. The incident highlights the need for robust identity‑access controls and security‑awareness training to meet audit‑ready control objectives.

LiveThreat™ Intelligence · 📅 September 24, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
helpnetsecurity.com

Fake Claude Max Giveaway Phishing Harvests Google Credentials

What Happened — A malicious site masquerading as an Anthropic “Claude Max” giveaway displays a draggable, browser‑in‑the‑browser window that mimics a Google sign‑in page. Victims who click “Sign in with Google” unknowingly surrender their Google account credentials, giving attackers access to email, documents, and any services that accept Google SSO.

Why It Matters for Trust & Control Assurance

  • This attack exemplifies the credential‑theft scenario that a continuous identity‑and‑access‑control program is built to prevent and evidence.
  • Demonstrates the need for documented security‑awareness training and phishing‑simulation evidence to show due diligence in user behavior controls.
  • Provides a concrete incident that can be logged as part of an audit‑ready control‑monitoring trail for the “access control” objective.

Who Is Affected – AI SaaS platforms (Claude, ChatGPT, Copilot) and their enterprise users, especially organizations that rely on Google Workspace for authentication.

Recommended Actions

  • Enforce MFA on all Google accounts and require it for SSO into third‑party services.
  • Deploy regular security‑awareness training that includes “browser‑in‑the‑browser” phishing simulations.
  • Implement continuous monitoring for anomalous sign‑in activity and maintain audit logs as evidence of control effectiveness.

Technical Notes – The campaign uses a “browser‑in‑the‑browser” technique first documented in 2022. No malware is delivered; the sole vector is a crafted HTML/JS page that generates a countdown timer client‑side and hijacks the Google sign‑in button. Source: Help Net Security

📰 Original Source
https://www.helpnetsecurity.com/2026/09/23/fake-claude-max-giveaway-phishing/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →