Fake Claude Max Promo Steals Google Logins

Help Net Security · Medium sophistication
Last updated September 24, 2026

Researchers found a real phishing campaign offering a “free” Claude Max upgrade to trick people into signing in with Google. The site uses a fake, draggable Google login pop-up (“browser-in-the-browser”) that looks legitimate and captures credentials. A stolen Google account can expose email and documents and can be used to access other services through password resets.

How the attack worked

The campaign impersonated an Anthropic Claude promotion, offering a free one-month upgrade to Claude Max. Instead of processing a normal signup, the page asked visitors to sign in with their Google account. Clicking the Google button did not open a real Google sign-in window. Instead, the page drew a browser window within the existing tab, complete with a padlock icon and a correctly spelled Google sign-in address, and the fake window could be dragged around the page like a real popup.

The flow also opened with a human verification step before showing a credential entry field, likely to build trust and reduce automated scanning by security tools. Only the Google sign-in option actually functioned. The Apple button displayed a message saying the method was temporarily unavailable, and an email entry box discarded whatever text was typed and redirected the visitor back to the Google button.

Why it succeeded

Several design choices increased the odds of success. Claude's paid plans start at $20 a month, making a free upgrade an attractive lure. The site also created urgency with a countdown claiming fewer than 760 of 10,000 slots remained, a number generated in the visitor's browser that reset on reload. Combined with copied Claude branding and a convincing fake login window, the page was built to push visitors toward one action: entering Google credentials.

What to watch for

  • Free upgrade offers for tools that normally require payment, especially when they demand an immediate login
  • Countdown timers or

Key findings

  • Attackers lured victims with a “free upgrade” to Claude Max and prompted them to “sign in with your Google account.”
  • The phishing site copied Claude branding and created urgency with a countdown and “limited slots” remaining.
  • The Google sign-in step was a fake “browser-in-the-browser” window with a padlock icon and a correctly spelled Google sign-in address, and it was draggable to appear real.
  • The flow started with a “human verification” step before showing credential entry, likely to build trust and reduce automated scanning.
  • Only the Google sign-in option actually worked; other options were disabled or forced users back to Google sign-in.
  • Compromising a Google account can expose email, documents, and password-reset messages for other services, and can also be used to sign into Claude.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Sales, Marketing, HR, Anyone using AI tools or signing into SaaS services with Google SSO.
  • Affected industries: Technology / SaaS, Online services (consumer accounts), Any organization where employees use Google accounts.
  • Attack channels: website.
  • Impersonated: Anthropic / Claude promotion page (with Google sign-in), Google sign-in window (fake, embedded in the page).

Red flags to watch for

  • Too-good-to-be-true free upgrade for a paid plan
  • Artificial urgency: countdown/limited remaining slots that reset on reload
  • Login prompt appears inside the page (draggable pop-up) instead of a normal Google login flow
  • Unexpected verification step in an embedded sign-in window
  • Padlock and address shown inside a page-drawn window (not the browser’s real address bar)
  • Sign-in options manipulated (Apple unavailable; email field discarded) to push Google login
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the fake Claude Max phishing attack?

It is a phishing site that lures victims with a fake free upgrade to Claude Max and then asks them to sign in with their Google account through a fake, draggable browser-in-the-browser login window.

How does the fake Google login window trick people?

The page draws a browser window within the existing tab, complete with a padlock icon and a correctly spelled Google sign-in address, and the window can be dragged around the page to look authentic.

Why is a compromised Google account dangerous?

A compromised Google account gives attackers access to the victim's email and documents, along with password reset messages for other services, and can also be used to sign into Claude.

What red flags should employees watch for?

Watch for too-good-to-be-true free upgrade offers, artificial urgency like countdown timers or limited slots, and login prompts that appear inside a web page instead of a normal browser window.

Read the video transcript

You see a page saying Anthropic hit 100 million users and is giving away 10,000 free Claude Max upgrades… if you sign in with Google. You click, and a perfect-looking Google login pops up inside the page, padlock, correct URL, even draggable. This is a "browser-in-the-browser" fake built to steal your Google password. The flow even starts with a "human verification" screen, and only the Google button really works. Type your password here and they get your email, your docs, and password resets for everything tied to Google. Here’s the move: if a Claude promo or upgrade page asks you to log in with Google inside a draggable pop-up, close the tab and go to claude.ai directly instead.

Categories

Similar attacks

Fake Claude Max Promo Steals Google Logins

Fake Claude Max Promo Steals Google Logins

Researchers found a phishing campaign offering a “free” upgrade to Claude Max to trick people into signing in with Google. The page uses a convincing fake, draggable Google login window (“browser-in-the-browser”) to capture credentials, potentially giving criminals access to email, documents, and…

September 23, 2026
AI Brands Used as Bait in Phishing Waves

AI Brands Used as Bait in Phishing Waves

Microsoft Threat Intelligence reports real campaigns where attackers impersonate popular AI tools (like ChatGPT, Copilot, DeepSeek, and Claude) to trick people into clicking links, installing fake software, or entering payment and login details. One campaign sent up to 100,000 emails in a day to…

September 10, 2026
Fake Helpdesk Passkey Setup Steals Cloud Access

Fake Helpdesk Passkey Setup Steals Cloud Access

The article describes real intrusions where attackers impersonate a company helpdesk and lure employees into "passkey, MFA, or SSO setup" steps. Victims are sent links via text (often to personal phones), leading to account takeover through adversary-in-the-middle phishing or device-code…

September 16, 2026
AI Browser Tricked into Spamming WhatsApp, Shopping

AI Browser Tricked into Spamming WhatsApp, Shopping

Researchers showed how a malicious web page could trick OpenAI’s Atlas AI-enabled browser into taking actions a user didn’t intend, like spamming WhatsApp contacts or modifying an Amazon account. The attacks used prompt-injection style instructions hidden in a seemingly legitimate “newsletter…

August 6, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit…

July 28, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment failed” billing email to drive victims to a credit-card theft page. The report also notes other brand-impersonation scams using cloned stores…

July 24, 2026