Fake Claude Max Giveaway Phishing Harvests Google Credentials
What Happened — A malicious site masquerading as an Anthropic “Claude Max” giveaway displays a draggable, browser‑in‑the‑browser window that mimics a Google sign‑in page. Victims who click “Sign in with Google” unknowingly surrender their Google account credentials, giving attackers access to email, documents, and any services that accept Google SSO.
Why It Matters for Trust & Control Assurance
- This attack exemplifies the credential‑theft scenario that a continuous identity‑and‑access‑control program is built to prevent and evidence.
- Demonstrates the need for documented security‑awareness training and phishing‑simulation evidence to show due diligence in user behavior controls.
- Provides a concrete incident that can be logged as part of an audit‑ready control‑monitoring trail for the “access control” objective.
Who Is Affected – AI SaaS platforms (Claude, ChatGPT, Copilot) and their enterprise users, especially organizations that rely on Google Workspace for authentication.
Recommended Actions
- Enforce MFA on all Google accounts and require it for SSO into third‑party services.
- Deploy regular security‑awareness training that includes “browser‑in‑the‑browser” phishing simulations.
- Implement continuous monitoring for anomalous sign‑in activity and maintain audit logs as evidence of control effectiveness.
Technical Notes – The campaign uses a “browser‑in‑the‑browser” technique first documented in 2022. No malware is delivered; the sole vector is a crafted HTML/JS page that generates a countdown timer client‑side and hijacks the Google sign‑in button. Source: Help Net Security