A page offers a free month of Claude Max. There is a neat sign-in button, a familiar AI-service look, and a counter showing the last places disappearing.
It even says you will not need a credit card. For anyone tired of subscription pitches, that can feel like the reassuring detail.
The fake Claude Max giveaway asks for something different, and the next screen is where a quick glance can be dangerously misleading.

Overview
The offer promises access but needs your Google account
In a September 23, 2026 investigation, Malwarebytes researchers examined a page claiming that Anthropic was celebrating 100 million users by giving away 10,000 one-month Claude Max subscriptions. The page was not an Anthropic promotion. Its sign-in flow was designed to capture Google credentials.
The research describes an unusually polished lure: familiar colors, invented five-star reviews, and a footer linking mostly to real Anthropic pages. Those legitimate links do not make the giveaway legitimate. They simply let the page borrow credibility from destinations the operator does not control.
No card form was necessary. The claimed prize created the reason to sign in, and the counterfeit sign-in screen created the opportunity to steal the account.
The countdown is a prop
A counter claimed fewer than 750 places remained and continued falling. Malwarebytes found that the number was generated in the visitor’s browser and reset after a reload. That makes it a scripted urgency device, not evidence that real subscriptions are running out.
The site presented more than one login option, but the alternatives did not work. The Apple button returned a prepared “temporarily unavailable” message. The email field discarded the address and pushed the visitor toward the Google button. Different choices all led toward the path the operator wanted.
- A surprise free upgrade appears outside Anthropic’s verified channels.
- A shrinking counter makes waiting feel costly.
- Reviews and footer links mimic credibility without proving sponsorship.
- No payment card is requested, which lowers suspicion.
- Other sign-in options fail or redirect to Google.
- The supposed Google login appears inside the giveaway page.
This is a real phishing page, not a disputed subscription
Malwarebytes inspected the page’s behavior and found a fabricated browser window used to imitate Google sign-in. The images here are nonfunctional reconstructions with a reserved example domain. They show the two visual stages without directing readers to the active phishing site.
The published investigation does not give a verified count of people whose passwords were stolen. It establishes the malicious design of the page and the credential-collection route. We will not invent victim totals or claim that the genuine Claude or Google services were breached.
Anthropic and Google are impersonated in the lure. The danger is the page that uses their appearance to obtain trust, not a flaw in a genuine Claude Max promotion.
The Fake Browser Window Is the Clever Part
People have learned to inspect a sign-in address and look for a padlock. This scam draws both inside the webpage itself. After the visitor clicks the Google option, the page displays what looks like a separate browser window with a Google address bar.
It is not a browser window. It is a drawing controlled by the site. The real address remains at the top of the actual browser, outside the fake pop-up. If you type into the drawn form, the information goes to the operator’s page, not to Google.
Researchers call this a browser-in-the-browser technique. The visual trick works because a user can correctly remember “check the URL” and still inspect the wrong bar. The counterfeit bar may show the exact trusted domain while the genuine bar shows the giveaway site’s address.
The fake window can be dragged inside the webpage, which adds to the illusion. A real separate window can move beyond the page boundary; a panel drawn inside a tab cannot. That simple boundary test can reveal the trick, although avoiding the unverified offer is safer than experimenting with its login form.
There was also a human-verification stage before the credential request. A verification challenge can make the flow feel protective, while also making automated scanners work harder to reach the next screen. Passing it does not convert the page into a trusted Google service.
Malwarebytes found that the window was loaded through a reusable sign-in widget from an outside service. That technical detail matters because the operator did not need to build a custom imitation from scratch. Similar visual deception can be reused with another offer or another brand.
The best independent clue is your password manager. It checks the genuine browser address, not the address drawn inside a webpage. If it normally fills your Google login but stays silent here, do not override that warning by typing manually.
Why “No Credit Card Required” Is Not Reassuring
Our earlier report on fake Claude Desktop ads describes a different impersonation route. Here, the examined lure is a giveaway and its documented goal is Google credentials. The shared brand does not make the two campaigns interchangeable.
Many people expect a scam to ask for a card number. This page deliberately did not. Its promise that no payment details were needed was part of the lure’s credibility, not proof that the offer was safe.
A Google account can be more valuable than one card form. It may contain email, files, contacts, saved recovery messages, and access to other services that use Google sign-in. The exact impact depends on the account and what other safeguards are enabled.
If a criminal enters your email account, they may see password-reset notices and account alerts. That can help them target other services. If you also use Google sign-in for Claude, the same compromised identity may provide a route toward that paid account.
The investigation does not show that every person who viewed the page had accounts compromised. Viewing a page and submitting credentials are different events. The appropriate response depends on whether you merely saw the offer, clicked through, entered a password, or approved a login prompt.
A real promotional giveaway should be findable through the provider’s official site or authenticated account. You should not have to trust a countdown on a separate domain as the only proof that it exists.

The One Screen You Must Not Trust
The sign-in panel is where the page stops being merely an overgenerous offer and asks for control of a real account. A Google logo, a drawn address bar, and a padlock can all appear inside an ordinary webpage. They are pixels, not browser security indicators.
Look above the page, at the actual browser bar. Better still, leave the offer and open Claude from a bookmark. If a free month is real, the provider should be able to confirm it without a third-party page collecting a password.
How the Fake Claude Max Giveaway Scam Works
Step 1: An attractive free upgrade pulls the visitor in
The page claims there is a limited supply of one-month Max subscriptions. Because paid AI access can be expensive, the offer has an obvious audience. The destination does not need to promise impossible lifetime benefits; a free month is enough to invite a click.
The researchers examined the page itself. They did not establish every traffic source that brought visitors there, so an ad, email, or search result should be treated as a possible route rather than a documented source for every visitor.
Step 2: Social proof and real links reduce doubt
The page uses ratings, testimonials, brand colors, and links to genuine pages. A cautious reader who clicks a footer link may land on a real Anthropic site and conclude that the giveaway page must also be official.
That conclusion does not follow. Anyone can link to an authentic website. The important question is whether the provider links back to the offer from a verified channel.
Step 3: The timer pressures the decision
The availability counter falls while the visitor reads. It suggests that verification must happen now or the prize will disappear. Malwarebytes found the count reset on reload, exposing it as a locally generated display.
That discovery is stronger than a vague suspicion about urgency. The page’s own behavior contradicts the idea that it is tracking a real pool of remaining subscriptions.
Step 4: Sign-in alternatives collapse to one route
Apple sign-in says it is unavailable, and the email box steers back to Google. The visitor is funneled toward the specific imitation the attacker built.
A broken sign-in option on its own can happen on an ordinary site. Here, combined with a fake giveaway and the counterfeit Google window, it is part of the observed phishing mechanism.
Step 5: A webpage pretends to be a Google window
The drawn pop-up shows an internal address bar and a padlock. It asks the visitor to complete verification and then provide login information. The real browser bar still belongs to the giveaway site.
At this stage, a password manager may decline to fill credentials. That is a good reason to stop. Do not copy a password from your vault into the form merely to “make it work.”
Step 6: The stolen identity can be used elsewhere
Once credentials are submitted, the account owner should assume the password is exposed and secure Google directly. A criminal may attempt to sign in, change recovery settings, or use the mailbox for further impersonation.
Those are potential consequences, not outcomes documented for every visitor. Prompt account recovery can reduce the harm even if the original giveaway page is later removed.
Site, Address, Support, and Account Checks
Is the giveaway run by Anthropic?
Find the promotion on Anthropic’s official site or inside your genuine account. A page using familiar colors and product wording is not the same as a provider announcement. Malwarebytes identified the examined page as a phishing operation, not an authorized giveaway.
Do not confuse the fake offer with Anthropic’s legitimate paid products. A brand can be real while a page claiming to speak for it is fraudulent.
What does the actual address bar say?
Look at the top-level browser address, not the bar drawn inside a pop-up. If the real address is the giveaway site, a fake “accounts.google.com” label inside the page does not move you to Google.
Some malicious pages rotate domains. Memorizing one old address is less useful than checking the relationship between the current real tab and the service you intended to visit.
Is there independent support for the offer?
Contact Anthropic through its published support route from a new tab or saved bookmark. Do not use a chat widget on the suspicious page as the only verifier. Its operator controls both the offer and that conversation.
Ask whether the promotion exists and whether it requires Google sign-in on a third-party site. If no official announcement can be found, there is no reason to risk account credentials.
Can the promised subscription be traced?
A genuine upgrade should be visible in your real account after you claim it through the provider’s approved flow. A counter, badge, or confirmation screen on the separate page is not account entitlement.
Do not provide documents, card details, or recovery codes if the site adds another requirement. The observed sample targeted Google login, and a changed future variant may ask for more.
What to Do if You Have Fallen Victim to This Scam
- If you only viewed the page, close it. Do not sign in through its button. Seeing the offer is not the same as submitting a password.
- If you entered Google credentials, change the password immediately. Open Google’s account security page yourself, not through the giveaway. Use a strong unique password.
- Sign out other sessions and review devices. Remove unfamiliar sessions and check recent security activity, recovery email, recovery phone, and forwarding settings.
- Strengthen multifactor protection. Turn on a trusted second factor and reject any approval request you did not initiate. If you entered a one-time code on the page, tell account support.
- Check connected services. Review applications linked to Google and remove anything unfamiliar. Inspect Claude separately if you use Google sign-in there.
- Warn your contacts if email was accessed. Attackers can send follow-up lures from a real account. A short warning helps people avoid links that appear to come from you.
- Preserve and report the page. Keep its URL, screenshots, time, and messages that led you there. Report it to the relevant platform, Google, Anthropic, and your local fraud authority.
- Check the device if you downloaded anything. This sample was described as credential phishing, not an installer. If a later variant asks for software, use Malwarebytes to scan the device. AdGuard can help block known malicious destinations, but neither tool restores a stolen password by itself.
- Ignore rescue messages. Anyone promising to unlock your Google or Claude account for a fee outside official recovery channels may be trying to exploit the same incident again.
Frequently Asked Questions
Was there really a free Claude Max giveaway?
Malwarebytes found the examined page to be a phishing lure, not an official Anthropic promotion. Verify any future offer on Anthropic’s own site before signing in.
Why did the page say no card was needed?
The target was Google login information. Avoiding a card request made the offer look safer while still asking for something valuable.
Does the Google-looking window prove I am on Google?
No. The scam draws a fake window inside its webpage. Check the actual browser’s top-level address and use your password manager as an additional clue.
Is the shrinking number of spots real?
In the investigated page, it was scripted inside the browser and reset when the page reloaded. It did not count genuine subscriptions.
I typed my email but not my password. What should I do?
Be alert for follow-up phishing messages, but a typed email alone is not the same as a stolen password. If you also entered a password or code, secure the account immediately.
Could this page affect my actual Claude subscription?
If you use the compromised Google account to sign in to Claude, it may expose that account too. Review sessions and billing inside the genuine service after securing Google.
The Bottom Line
The fake Claude Max giveaway is a credential-theft page wrapped in a friendly free-month offer. Its most convincing detail, the Google-looking sign-in window, is part of the deception.
Ignore the counter, open the real provider yourself, and never enter your Google password into a window drawn inside a third-party webpage.