Fake Claude Max Promo Steals Google Logins

Malwarebytes · High sophistication
Last updated September 24, 2026

Researchers found a phishing campaign offering a “free” upgrade to Claude Max to trick people into signing in with Google. The page uses a convincing fake, draggable Google login window (“browser-in-the-browser”) to capture credentials, potentially giving criminals access to email, documents, and password resets.

How the Attack Worked

The campaign begins with a website posing as a promotion from Anthropic, claiming the company has passed 100 million users and is giving away 10,000 free one-month subscriptions to Claude Max. Visitors who want to claim the offer are steered toward a "Sign in with Google" button, while the page presents Apple sign-in as unavailable. This narrows victims toward the one credential type the attackers actually want: a Google login.

Clicking the Google button does not open a real Google sign-in window. Instead, the page draws a fake browser window inside the existing tab, complete with a padlock icon and a correctly spelled Google sign-in address, a technique known as browser-in-the-browser. Before asking for a password, the page shows a human-verification step, which may reassure visitors and also helps deter automated security scanners from detecting the phishing flow.

Why It Succeeded

Several design choices work together to build trust and reduce suspicion. A countdown showing slots dropping from a starting number of 10,000 creates manufactured urgency, pushing people to act quickly rather than examine the page closely. The fake sign-in window mimics real Google branding closely enough, including the padlock and address text, that a quick glance would not reveal anything wrong. Limiting sign-in to Google only, framed as Apple being unavailable, funnels victims toward the credential type attackers want without raising an obvious red flag.

What to Watch For

  • A countdown or "limited slots remaining" counter urging immediate action
  • Only one sign-in option working, with another option claimed to be unavailable
  • A padlock or address shown inside the webpage itself, rather than in the browser's own address bar
  • A verification step appearing before any password field

How to Build Resistance

The real browser address bar at the top of the screen is the only one that matters. Throughout this type of attack, that real address bar continues to show the phishing site's domain, not Google's, even while the fake window inside the page displays a Google-looking address.

A simple way to test a suspicious sign-in popup is the drag test: try to drag the window beyond the edge of the webpage. A genuine browser window will move freely, while a fake one embedded in the page will stop at the page's edge because it is trapped inside it.

Password managers can serve as an additional signal. A password manager should not offer to autofill Google credentials on a site that does not actually belong to Google, so a missing autofill prompt is worth treating as a warning rather than a mere inconvenience.

Finally, treat countdowns, slot counters, and "only one sign-in option works" messaging as scam indicators. When in doubt about a promotional offer, navigate directly to the official site rather than clicking through from an email or ad.

Key findings

  • Attackers used a fake “Claude Max giveaway” to lure victims with a free one-month subscription.
  • The phishing site intentionally steers victims to “Sign in with Google,” while Apple sign-in is presented as unavailable.
  • The campaign uses a “browser-in-the-browser” fake Google sign-in window, including a padlock icon and a correctly spelled Google address inside the page.
  • A “human-verification step” is shown before credential entry, likely to build trust and deter automated scanning.
  • Stolen Google credentials could expose email, documents, and password-reset messages for other accounts, and could also be used to access Claude accounts tied to Google sign-in.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Anyone using Google Workspace or Google sign-in, Security awareness training participants.
  • Affected industries: Technology / AI services, General public / consumers, Any organization using Google Workspace.
  • Attack channels: website.
  • Impersonated: Anthropic (Claude), Google sign-in (within a fake popup).

Red flags to watch for

  • A “limited slots” counter creates urgency (manufactured scarcity).
  • Only one sign-in option actually works; Apple sign-in is claimed to be unavailable.
  • The browser’s real address bar continues to show the phishing domain, not Google.
  • A “padlock” and “Google address” appear inside the page (not in the real browser UI).
  • The fake login window is draggable but trapped inside the page area.
  • Password manager should not offer to fill Google credentials on a non-Google site.
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the fake Claude Max giveaway scam?

It is a phishing site that lures victims with a fake offer of a free one-month Claude Max subscription, then pushes them to sign in with Google to steal their credentials.

What is a browser-in-the-browser attack?

It is a fake sign-in window drawn inside a webpage, complete with a fake padlock and address bar, designed to look like a real Google login popup even though it is not.

How can I tell if a Google sign-in popup is fake?

Try dragging the window beyond the edge of the webpage. A real browser window can move freely, while a fake one is trapped inside the page that created it and stops at its edge.

Why does the scam only offer Google sign-in?

The phishing page presents Apple sign-in as unavailable and steers victims exclusively toward Google sign-in because that is the credential the attackers are trying to steal.

Read the video transcript

You see a site saying Anthropic hit 100 million users and is giving away 10,000 free Claude Max upgrades. Fewer than 750 slots left, ticking down. It pushes you to "Sign in with Google" to claim it. Apple sign‑in is grayed out. But clicking Google doesn’t open a real window, it draws a fake Google login inside the page. This is a "browser‑in‑the‑browser" trick. The only address bar that matters is your real browser’s, at the top. A real Google login can move outside the page; this fake one is trapped inside it, and your password manager won’t autofill. If a promo pushes Google sign‑in, countdowns, or a weird popup, don’t log in there. Close it, open anthropic.com or claude.ai yourself, and check any offers from the real site.

Categories

Similar attacks

Fake Claude Max Promo Steals Google Logins

Fake Claude Max Promo Steals Google Logins

Researchers found a real phishing campaign offering a “free” Claude Max upgrade to trick people into signing in with Google. The site uses a fake, draggable Google login pop-up (“browser-in-the-browser”) that looks legitimate and captures credentials. A stolen Google account can expose email and…

September 23, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit…

July 28, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment failed” billing email to drive victims to a credit-card theft page. The report also notes other brand-impersonation scams using cloned stores…

July 24, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Fake Helpdesk Passkey Setup Steals Cloud Access

Fake Helpdesk Passkey Setup Steals Cloud Access

The article describes real intrusions where attackers impersonate a company helpdesk and lure employees into "passkey, MFA, or SSO setup" steps. Victims are sent links via text (often to personal phones), leading to account takeover through adversary-in-the-middle phishing or device-code…

September 16, 2026
Phish Login, Then Add Your Own Google Passkey

Phish Login, Then Add Your Own Google Passkey

Researchers describe a phishing workflow where an attacker logs into a victim’s Google account using stolen password + authenticator code, then quickly enrolls a new passkey to keep access even if the password is changed. The trick relies on victims choosing a weaker sign-in fallback (one-time…

August 26, 2026