
Fake Free CP Giveaway Steals CoD Mobile Accounts
Researchers reported a real phishing campaign targeting Call of Duty Mobile players with a fake “free Call of Duty Points” giveaway site. Victims are tricked…
A phishing campaign targets Call of Duty Mobile players by promising free Call of Duty Points (CP). Victims are tricked into entering their email, password, and then their 2FA code on a fake site that impersonates an official promotion. The attackers use the captured credentials to take over Activision accounts, potentially exposing linked gaming accounts and stored payment methods.
This scam targets Call of Duty Mobile players with the promise of 10,800 free Call of Duty Points, the game's premium currency. Instead of offering a redemption code, the fake promotion page asks victims to log in with their full email address and password. Once credentials are entered, victims are redirected to a second page that asks for their two-factor authentication code. According to the source, this redirect follows a technique known as a real-time credential relay, where the phishing site immediately submits the stolen password to the real Activision login page and then captures the resulting one-time code as the victim types it in.
The end result is that the victim hands over everything needed to access their real account: the password and the one-time code that is supposed to keep attackers out. The source notes that stolen Activision logins may expose linked platforms such as Xbox, PlayStation, and Battle.net, and potentially stored payment methods and purchase history.
The pretext works because it targets a strong incentive, free in-game currency, and frames the request as a normal part of claiming a reward. Asking for a full login instead of a redemption code is unusual for legitimate promotions, but it can look plausible to someone excited about a giveaway. The two-step flow also mimics a real sign-in experience closely enough that victims may not question why a promotional page needs their 2FA code at all.
The most effective defense is to reach known sites directly by typing the address into a browser or using the official app, rather than clicking links from posts, ads, or messages. Users should treat any 2FA code request as something that should only happen during a sign-in they personally initiated on an official site. Awareness training for gaming communities, customer support teams, and general employees should reinforce that legitimate promotions rarely require a full password submission, and that checking the address bar before entering credentials is a simple, effective habit.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Victims are told they can claim 10,800 free Call of Duty Points by logging in with their email and password on a fake site, then are asked to enter a two-factor authentication code, which the attackers relay in real time to the real Activision login page.
A stolen Activision login may expose linked platforms like Xbox, PlayStation, and Battle.net, along with potentially stored payment methods and purchase history.
The site uses a real-time credential relay, meaning it forwards the stolen password to the real login page and captures the resulting 2FA prompt, so the victim ends up handing over both the password and the one-time code needed to access their real account.
Legitimate promotions typically use redemption codes rather than asking for a full account login, and this fake page also had grammatical errors like GET FREE POINT and a live chat widget seemingly added just to appear legitimate.
You see a site shouting “GET 10,800 FREE CoD POINT” if you just log in with your Activision account. It looks like a Call of Duty Mobile promo, but the site isn’t Activision at all. First it takes your email and password, then instantly jumps to a second page demanding your 2FA code to 'confirm' the reward. Behind the scenes, that’s a real-time credential relay: they use your password to trigger a real Activision 2FA prompt, then you hand over the one-time code. Now they can walk into your Activision, Xbox, PlayStation, even payment details. Here’s the move: if a 'free CP' offer wants your full login or 2FA code, bail out and only sign in from the official app or by typing activision.com yourself.

Researchers reported a real phishing campaign targeting Call of Duty Mobile players with a fake “free Call of Duty Points” giveaway site. Victims are tricked…

Authorities dismantled “Kratos,” a phishing-as-a-service platform used at scale to steal Microsoft account credentials and even bypass MFA by stealing session…

Criminal groups are stealing Meta Business Manager and Google Ads accounts using phishing that arrives through trusted platforms like Salesforce, Google…

Apple warns that scammers are placing unsolicited FaceTime calls and sending urgent-looking messages that appear to come from “Apple Support” or a bank. The…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through…