
Fake CoD Points Giveaway Steals Accounts
A phishing campaign targets Call of Duty Mobile players by promising free Call of Duty Points (CP). Victims are tricked into entering their email, password,…
Researchers reported a real phishing campaign targeting Call of Duty Mobile players with a fake “free Call of Duty Points” giveaway site. Victims are tricked into entering their email/password and then a one-time 2FA code, allowing attackers to take over accounts and potentially access linked gaming profiles and stored payment methods.
This campaign impersonates the official Call of Duty Mobile site with a promise of 10,800 free Call of Duty Points, the game's premium currency. Instead of a legitimate redemption code, the page asks victims to log in with their email address and password. After submitting those credentials, victims are redirected to a second page that requests their one-time 2FA code. Behind the scenes, the attack uses a real-time credential relay that forwards the stolen credentials to the real Activision login, which triggers a genuine 2FA challenge. When the victim enters that code on the fake page, it is relayed too, giving attackers everything needed to take over the real account.
The lure works because it plays on a common desire among mobile gamers, free in-game currency, and mimics the structure of a legitimate login flow closely enough to feel routine. Asking for a 2FA code immediately after login can feel normal to users who are used to two-step verification prompts on many sites, especially when the credential relay produces a real, valid 2FA request from the actual game publisher. This blurs the line between a fake prompt and a real one, making the scam harder to spot in the moment.
Because many gaming accounts are linked to other services, a successful takeover can expose connected Xbox, PlayStation, or Battle.net profiles, along with stored payment methods and purchase history. This makes the scam relevant not just to individual gamers but also to teams supporting customer or community accounts, and to anyone whose gaming account may share credentials with other services.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
A fake site impersonating the official Call of Duty Mobile page offers 10,800 free Call of Duty Points and asks victims to log in with their email and password, then requests the one-time 2FA code on a second page.
The credentials and code are relayed in real time to the real Activision login, letting attackers complete account takeover and potentially access linked Xbox, PlayStation, or Battle.net profiles and payment information.
Look for awkward wording like GET FREE POINT, a request for password instead of a redemption code, and a chat widget that seems included only to appear more legitimate.
Change the Activision password immediately, treat the account as compromised if a 2FA code was entered, review recent account activity, sign out of all sessions, and check linked payment methods for unauthorized charges.
See a website yelling “GET FREE POINT” and promising 10,800 free Call of Duty Points? That’s the trap. The fake site looks like Call of Duty Mobile, even has a chat widget, but it asks for your email and password, then a second page demands your 2FA code. The moment you type that code, they can log in to your real Activision account, plus linked Xbox, PlayStation, or Battle.net profiles and stored payment methods. If a promo wants your password or 2FA code, back out and only claim rewards by opening the official app or typing the publisher’s site in yourself.

A phishing campaign targets Call of Duty Mobile players by promising free Call of Duty Points (CP). Victims are tricked into entering their email, password,…

Criminal groups are stealing Meta Business Manager and Google Ads accounts using phishing that arrives through trusted platforms like Salesforce, Google…

Apple warns that scammers are placing unsolicited FaceTime calls and sending urgent-looking messages that appear to come from “Apple Support” or a bank. The…

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through…

Researchers tracked a large scam wave abusing interest in the 2026 FIFA World Cup, including fake merchandise stores, cloned ticket sites, and bogus “free…

Researchers reported a real spearphishing campaign that impersonates DocuSign emails to trick tech executives into clicking “Review Document” links and…