Safety & Security

Phishing Scam Dangles Free Claude Max to Harvest Google Logins

A convincing phishing page offers 10,000 users a free month of Claude Max, then steals Google logins via a browser-in-the-browser fake, Malwarebytes reports.

New Phishing Attack Promises Claude Max, but Steals Your Google Credentials Instead
New Phishing Attack Promises Claude Max, but Steals Your Google Credentials InsteadAI-generated
By Sophie Lindqvist4 min read

Updated

Why it matters

  • Malwarebytes reports a phishing scam offering 10,000 users a free month of Claude Max with x20 limits, worth about $200, to mark a fake 100-million-user milestone
  • The fake login page uses a browser-in-a-browser trick with a padlock and a correctly spelled Google sign-in address, and a disabled Apple login forces the Google option
  • Malwarebytes' Stefan Dasic says the site traces to a UK-registered company with a rented server, and developer comments in Russian are weak evidence of attribution

A phishing campaign is offering victims a free month of Anthropic's Claude Max plan with x20 limits — roughly $200 in value — and stealing their Google credentials in exchange.

The scam, reported by cybersecurity firm Malwarebytes, claims Anthropic is celebrating 100 million users by giving 10,000 people a free month of Claude Max, complete with "extended thinking" and "priority access to Opus and Sonnet, no caps." The offer does not exist. Clicking through leads to a fake Google login page designed to harvest usernames and passwords. Because many people link Gmail, Google Docs and third-party accounts to their Google identity, the real cost of the "free" month could be access to nearly everything in their digital lives.

The campaign stands out for its polish, Malwarebytes said in its report.

"The presentation is careful, down to the real logo and colors, invented five-star reviews, and a long footer whose links lead almost entirely to genuine Anthropic pages," wrote Stefan Dasic, senior malware research engineer at Malwarebytes. The page even displays a running counter showing how many of the fake 10,000 accounts have supposedly been claimed.

Victims who click the offer land on a page prompting them to upgrade a Claude account. An Apple login option appears but is disabled, funneling users toward a single button: "Sign in with Google." The page then uses a browser-in-a-browser trick that Dasic said is convincing enough to fool anyone who does not inspect it closely.

"The page draws a browser window inside the existing tab, complete with a padlock and a correctly spelled Google sign-in address. It can even be dragged around the page," Dasic wrote.

In a message to CNET, Dasic explained why this overlap is particularly damaging. Claude has no password of its own — users sign in either by continuing with Google or through a login link sent to their email. "So if someone's Claude account is tied to the Google account that was phished, the attacker reaches it either way," he said.

The attack matters beyond Claude users because it weaponizes a real structural weakness in modern authentication: single sign-on. As more AI services and productivity tools rely on Google as an identity provider, one phished credential can cascade across dozens of connected accounts. That makes polished fakes like this one a higher-stakes threat than a typical credential form.

What investigators know so far

It is too early to tell how widespread the scam is or how many people it has reached, Dasic told CNET. The investigation has traced the site to a UK-registered company, but the server is rented. "Which tells us where the server was rented, not who rented it," he said.

Some components of the web page contain developer comments written in Russian. Dasic cautioned against reading much into that. The code could be part of a phishing kit built by someone unconnected to this particular campaign. "Language in code is weak evidence on its own and has been planted before to misdirect," he added.

How to spot a fake browser window

Malwarebytes offered several concrete checks in its post:

  • Drag the popup outside the browser. A real popup will not be trapped inside the web page. A fake in-tab browser window cannot escape the page that contains it.
  • Watch your password manager. If it refuses to populate the username and password fields, that is a strong signal the site is not legitimate.
  • Verify the offer independently. If you arrived via a link, look for the promotion on the company's actual website. This giveaway does not appear anywhere on Anthropic's site.
  • Be suspicious of single sign-in options. The disabled Apple login is a red flag that the scammer is steering victims into the Google trap.
  • Ignore slot counters and countdowns. A ticking number of remaining accounts is a pressure tactic, not proof that a website or offer is real.

The scam's reliance on Anthropic branding reflects a broader pattern: as AI subscriptions like Claude Max become status items with waiting lists and premium tiers, they join the ranks of products scammers can dangle as bait. Dasic's investigation is ongoing, and the rented UK server means attribution remains unknown for now.

Original: malwarebytes.com

Share this article:

More from Sophie Lindqvist

Sophie Lindqvist

Show full bio

Staff writer covering marketplaces and e-commerce at AI In Context.

115 articles

Related articles

  1. Microsoft Disrupts EvilTokens, AI Chatbot Platform Behind 12,000 Account Hacks
  2. Nvidia Launches Open Agent Safety Platform to Contain Rogue AI Agents
  3. OpenAI Agents Hit UN Trade API 16,500 Times via Google Game
  4. OpenAI halts frontier-model training after agent escapes sandbox via DNS
  5. Pinker Rejects AI Doomsday Debate, Calls for Safety Engineering

Next article »