Fake Free COD Points Scam Steals Logins and 2FA

Help Net Security · Low sophistication
Last updated August 3, 2026

A real phishing campaign targeted Call of Duty Mobile players by promising free in-game currency. Victims were tricked into entering their email and password, then providing a 2FA code on a follow-up page, enabling attackers to take over accounts.

How the Attack Worked

This campaign, flagged by Malwarebytes researchers, targeted Call of Duty Mobile players with a simple but effective lure: a promise of free Call of Duty Points (CP), the game's premium in-game currency. The attack unfolded in two steps. First, victims landed on a page impersonating a rewards or promotion offer and were asked to log in using their email address and password to "claim" the free points. Once credentials were entered, victims were redirected to a second page requesting their 2FA code, giving the attackers a real-time path to bypass multi-factor authentication and take over the account.

Why It Succeeded

The attack sophistication here is rated low, which is part of why it worked. There was no complex infrastructure or advanced technical trickery, just a believable reward hook aimed at a large, motivated audience of gamers. Anyone eager for free in-game currency, especially casual players who aren't thinking about account security in the moment, is a plausible target. The two-step design (credentials first, then 2FA) mimics a real login flow closely enough to catch users off guard, especially if they are not expecting the account-takeover attempt to continue past the first password prompt.

What to Watch For

Several red flags stand out in this scenario:

  • A "free points" or reward offer that requires entering an account password to claim
  • A follow-up page that asks for a 2FA code right after a login prompt
  • An unverified source promoting the giveaway, paired with urgency to claim a reward before it expires

These patterns are common signs of credential phishing designed to hijack an account rather than deliver an actual reward.

How to Build Resistance

The awareness takeaways from this case apply broadly, not just to gamers:

  • Treat any "free reward" giveaway as suspicious if it asks for a login
  • Never share an MFA or 2FA code with a website or person, especially right after a suspicious login prompt; stop and report it instead
  • Use unique passwords, ideally managed with a password manager, so a stolen gaming password cannot be reused to access work or other personal accounts

This case is a reminder that low-sophistication phishing can still succeed when it targets something people want (free rewards) and then immediately pushes for the second factor that is supposed to protect them. Recognizing the credential-plus-2FA pattern early, and refusing to hand over a one-time code outside of a trusted context, is the most reliable way to stop this kind of attack before an account is lost.

Key findings

  • The lure was a fake 'free Call of Duty Points' giveaway aimed at players.
  • Victims were prompted to enter account credentials (email and password).
  • A second step attempted to capture the victim’s 2FA code after the initial login prompt.

Who’s being targeted

  • Commonly targeted roles: All employees, Security awareness training audience, Helpdesk (for account-takeover reports).
  • Affected industries: Gaming, Consumer online services.
  • Attack channels: website.
  • Impersonated: Call of Duty Mobile promotion / rewards team.

Red flags to watch for

  • A “free points” offer that requires a password to claim a reward
  • A follow-up page requesting a 2FA code (likely to immediately hijack the account)
  • Unverified promotion source and urgency to “claim” rewards
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What was the lure used in this Call of Duty phishing campaign?

Attackers used a fake giveaway promising free Call of Duty Points (CP), the game's premium currency, to lure players into a phishing page.

What information did the attackers try to steal?

Victims were first asked to enter their email address and password, then redirected to a second page requesting their 2FA code, giving attackers everything needed to take over the account.

Why is a 2FA code request after a login page a red flag?

Legitimate rewards or giveaways do not need your account password or a live 2FA code, so a follow-up page asking for a 2FA code is a strong sign of an account-takeover attempt.

How can employees protect themselves from similar scams?

Avoid entering credentials on unverified giveaway pages, never share MFA/2FA codes, and use unique passwords so a stolen gaming password cannot be reused elsewhere.

Read the video transcript

See a “free Call of Duty Points giveaway” and think, easy win? That’s exactly how this scam starts. Malwarebytes found a phishing site posing as the Call of Duty Mobile rewards team. First page: "Log in with email and password to claim your free CP." Next page: it grabs your 2FA code to hijack the account on the spot. Here’s the aha: any "free points" offer that demands your password, then immediately asks for a 2FA code, isn’t a bonus, it’s a live account takeover. And if you reuse that password, they can try it on your work accounts too. If a promo site ever wants both your password and a 2FA code, bail out and report it, then change that password in your manager so it’s not reused anywhere, especially at work.

Similar attacks