Fake CoD Points Giveaway Steals Accounts

Malwarebytes · Medium sophistication
Last updated July 30, 2026

A phishing campaign targets Call of Duty Mobile players by promising free Call of Duty Points (CP). Victims are tricked into entering their email, password, and then their 2FA code on a fake site that impersonates an official promotion. The attackers use the captured credentials to take over Activision accounts, potentially exposing linked gaming accounts and stored payment methods.

How the attack worked

This scam targets Call of Duty Mobile players with the promise of 10,800 free Call of Duty Points, the game's premium currency. Instead of offering a redemption code, the fake promotion page asks victims to log in with their full email address and password. Once credentials are entered, victims are redirected to a second page that asks for their two-factor authentication code. According to the source, this redirect follows a technique known as a real-time credential relay, where the phishing site immediately submits the stolen password to the real Activision login page and then captures the resulting one-time code as the victim types it in.

The end result is that the victim hands over everything needed to access their real account: the password and the one-time code that is supposed to keep attackers out. The source notes that stolen Activision logins may expose linked platforms such as Xbox, PlayStation, and Battle.net, and potentially stored payment methods and purchase history.

Why it succeeded

The pretext works because it targets a strong incentive, free in-game currency, and frames the request as a normal part of claiming a reward. Asking for a full login instead of a redemption code is unusual for legitimate promotions, but it can look plausible to someone excited about a giveaway. The two-step flow also mimics a real sign-in experience closely enough that victims may not question why a promotional page needs their 2FA code at all.

What to watch for

  • Any "free rewards" offer that requires a full account login rather than a simple redemption code
  • Being redirected to a second page asking for a 2FA or one-time code right after entering a password
  • Grammatical errors, such as the page reading "GET FREE POINT" instead of "GET FREE POINTS"
  • Awkwardly worded instructions or unnecessary trust signals like a live chat widget that seems added only to look legitimate
  • Landing on an unfamiliar website rather than the official app or known domain

How to build resistance

The most effective defense is to reach known sites directly by typing the address into a browser or using the official app, rather than clicking links from posts, ads, or messages. Users should treat any 2FA code request as something that should only happen during a sign-in they personally initiated on an official site. Awareness training for gaming communities, customer support teams, and general employees should reinforce that legitimate promotions rarely require a full password submission, and that checking the address bar before entering credentials is a simple, effective habit.

Key findings

  • The scam poses as a free Call of Duty Points (CP) giveaway and asks victims to log in with their email and password.
  • After credentials are entered, victims are redirected to a second page that asks for a two-factor authentication (2FA) code.
  • The phishing flow uses a “real-time credential relay” so the victim receives a real 2FA prompt and then hands over the one-time code.
  • Stolen Activision logins may expose linked platforms (Xbox, PlayStation, Battle.net) and potentially stored payment methods and purchase history.
  • The fake page includes telltales like grammatical errors (e.g., “GET FREE POINT”) and legitimacy cues like a live chat widget.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance (for payment-method risk awareness), Customer support / community teams, IT/Security awareness trainees who use MFA.
  • Affected industries: Gaming, Consumer Online Services.
  • Attack channels: website.
  • Impersonated: Call of Duty Mobile / Activision promotion page, Activision login / Call of Duty Mobile verification page.

Red flags to watch for

  • Promotion asks for a full account login rather than a redemption code
  • Poor wording/grammar and suspicious UI elements meant to look legitimate
  • Unfamiliar website hosting the sign-in flow
  • Site immediately asks for a one-time 2FA code after collecting username/password
  • Time pressure elements (delays or timers) used to reduce scrutiny
  • The process happens on an unfamiliar website rather than the official app/site
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does the fake Call of Duty Points scam work?

Victims are told they can claim 10,800 free Call of Duty Points by logging in with their email and password on a fake site, then are asked to enter a two-factor authentication code, which the attackers relay in real time to the real Activision login page.

What can attackers do with a stolen Activision account?

A stolen Activision login may expose linked platforms like Xbox, PlayStation, and Battle.net, along with potentially stored payment methods and purchase history.

Why is entering a 2FA code on this fake page dangerous?

The site uses a real-time credential relay, meaning it forwards the stolen password to the real login page and captures the resulting 2FA prompt, so the victim ends up handing over both the password and the one-time code needed to access their real account.

What are red flags of this type of scam?

Legitimate promotions typically use redemption codes rather than asking for a full account login, and this fake page also had grammatical errors like GET FREE POINT and a live chat widget seemingly added just to appear legitimate.

Read the video transcript

You see a site shouting “GET 10,800 FREE CoD POINT” if you just log in with your Activision account. It looks like a Call of Duty Mobile promo, but the site isn’t Activision at all. First it takes your email and password, then instantly jumps to a second page demanding your 2FA code to 'confirm' the reward. Behind the scenes, that’s a real-time credential relay: they use your password to trigger a real Activision 2FA prompt, then you hand over the one-time code. Now they can walk into your Activision, Xbox, PlayStation, even payment details. Here’s the move: if a 'free CP' offer wants your full login or 2FA code, bail out and only sign in from the official app or by typing activision.com yourself.

Similar attacks

Kratos PhaaS Fueled MFA-Bypass Phishing

Kratos PhaaS Fueled MFA-Bypass Phishing

Authorities dismantled “Kratos,” a phishing-as-a-service platform used at scale to steal Microsoft account credentials and even bypass MFA by stealing session…

July 24, 2026