
ChatGPT Billing Phish and Fake Snap Support Scams
This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted…
A real phishing campaign targeted Call of Duty Mobile players by promising free in-game currency. Victims were tricked into entering their email and password, then providing a 2FA code on a follow-up page, enabling attackers to take over accounts.
This campaign, flagged by Malwarebytes researchers, targeted Call of Duty Mobile players with a simple but effective lure: a promise of free Call of Duty Points (CP), the game's premium in-game currency. The attack unfolded in two steps. First, victims landed on a page impersonating a rewards or promotion offer and were asked to log in using their email address and password to "claim" the free points. Once credentials were entered, victims were redirected to a second page requesting their 2FA code, giving the attackers a real-time path to bypass multi-factor authentication and take over the account.
The attack sophistication here is rated low, which is part of why it worked. There was no complex infrastructure or advanced technical trickery, just a believable reward hook aimed at a large, motivated audience of gamers. Anyone eager for free in-game currency, especially casual players who aren't thinking about account security in the moment, is a plausible target. The two-step design (credentials first, then 2FA) mimics a real login flow closely enough to catch users off guard, especially if they are not expecting the account-takeover attempt to continue past the first password prompt.
Several red flags stand out in this scenario:
These patterns are common signs of credential phishing designed to hijack an account rather than deliver an actual reward.
The awareness takeaways from this case apply broadly, not just to gamers:
This case is a reminder that low-sophistication phishing can still succeed when it targets something people want (free rewards) and then immediately pushes for the second factor that is supposed to protect them. Recognizing the credential-plus-2FA pattern early, and refusing to hand over a one-time code outside of a trusted context, is the most reliable way to stop this kind of attack before an account is lost.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Attackers used a fake giveaway promising free Call of Duty Points (CP), the game's premium currency, to lure players into a phishing page.
Victims were first asked to enter their email address and password, then redirected to a second page requesting their 2FA code, giving attackers everything needed to take over the account.
Legitimate rewards or giveaways do not need your account password or a live 2FA code, so a follow-up page asking for a 2FA code is a strong sign of an account-takeover attempt.
Avoid entering credentials on unverified giveaway pages, never share MFA/2FA codes, and use unique passwords so a stolen gaming password cannot be reused elsewhere.
See a “free Call of Duty Points giveaway” and think, easy win? That’s exactly how this scam starts. Malwarebytes found a phishing site posing as the Call of Duty Mobile rewards team. First page: "Log in with email and password to claim your free CP." Next page: it grabs your 2FA code to hijack the account on the spot. Here’s the aha: any "free points" offer that demands your password, then immediately asks for a 2FA code, isn’t a bonus, it’s a live account takeover. And if you reuse that password, they can try it on your work accounts too. If a promo site ever wants both your password and a 2FA code, bail out and report it, then change that password in your manager so it’s not reused anywhere, especially at work.

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted…

Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in…

A voicemail-themed phishing campaign (“Kali365 Ringer”) targeted financial and insurance organizations using a missed-call notification and a Google Sites page…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…