{"id":419342,"date":"2026-09-27T12:10:23","date_gmt":"2026-09-27T12:10:23","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=419342"},"modified":"2026-09-27T12:10:23","modified_gmt":"2026-09-27T12:10:23","slug":"fake-claude-max-giveaway-google-login-scam","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/fake-claude-max-giveaway-google-login-scam\/","title":{"rendered":"Fake Claude Max Giveaway Steals Google Logins"},"content":{"rendered":"<p>A page offers a free month of Claude Max. There is a neat sign-in button, a familiar AI-service look, and a counter showing the last places disappearing.<\/p><div id=\"mwtad1951400351\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>It even says you will not need a credit card. For anyone tired of subscription pitches, that can feel like the reassuring detail.<\/p>\n<p>The fake Claude Max giveaway asks for something different, and the next screen is where a quick glance can be dangerously misleading.<\/p><div id=\"mwtad2777107301\" class=\"gas_fallback-ad_381396-ad_309685-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<figure><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/claudemax-1.png\" class=\"wp-image-419343 skip-lazy\" loading=\"eager\" alt=\"Reconstruction of a fake Claude Max free-month giveaway with a shrinking availability counter\" width=\"1672\" height=\"941\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/claudemax-1.png 1672w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/claudemax-1-300x169.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/claudemax-1-1024x576.png 1024w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/claudemax-1-1536x864.png 1536w\" sizes=\"(max-width: 1672px) 100vw, 1672px\" \/><\/figure>\n<div id=\"mwtad1579889554\" class=\"gas_fallback-ad_309746-ad_309685-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>The offer promises access but needs your Google account<\/h3>\n<p>In a <a href=\"https:\/\/www.malwarebytes.com\/blog\/threat-intel\/2026\/09\/fake-claude-max-giveaway-hides-a-google-account-phishing-trap\" target=\"_blank\" rel=\"noopener\">September 23, 2026 investigation<\/a>, Malwarebytes researchers examined a page claiming that Anthropic was celebrating 100 million users by giving away 10,000 one-month Claude Max subscriptions. The page was not an Anthropic promotion. Its sign-in flow was designed to capture Google credentials.<\/p>\n<p>The research describes an unusually polished lure: familiar colors, invented five-star reviews, and a footer linking mostly to real Anthropic pages. Those legitimate links do not make the giveaway legitimate. They simply let the page borrow credibility from destinations the operator does not control.<\/p>\n<p>No card form was necessary. The claimed prize created the reason to sign in, and the counterfeit sign-in screen created the opportunity to steal the account.<\/p><div id=\"mwtad2074244444\" class=\"gas_fallback-ad_309686-ad_309685-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<h3>The countdown is a prop<\/h3>\n<p>A counter claimed fewer than 750 places remained and continued falling. Malwarebytes found that the number was generated in the visitor&#8217;s browser and reset after a reload. That makes it a scripted urgency device, not evidence that real subscriptions are running out.<\/p>\n<p>The site presented more than one login option, but the alternatives did not work. The Apple button returned a prepared \u201ctemporarily unavailable\u201d message. The email field discarded the address and pushed the visitor toward the Google button. Different choices all led toward the path the operator wanted.<\/p>\n<ul>\n<li>A surprise free upgrade appears outside Anthropic&#8217;s verified channels.<\/li>\n<li>A shrinking counter makes waiting feel costly.<\/li>\n<li>Reviews and footer links mimic credibility without proving sponsorship.<\/li>\n<li>No payment card is requested, which lowers suspicion.<\/li>\n<li>Other sign-in options fail or redirect to Google.<\/li>\n<li>The supposed Google login appears inside the giveaway page.<\/li>\n<\/ul>\n<h3>This is a real phishing page, not a disputed subscription<\/h3>\n<p>Malwarebytes inspected the page&#8217;s behavior and found a fabricated browser window used to imitate Google sign-in. The images here are nonfunctional reconstructions with a reserved example domain. They show the two visual stages without directing readers to the active phishing site.<\/p><div id=\"mwtad582126254\" class=\"gas_fallback-ad_381401-ad_309685-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The published investigation does not give a verified count of people whose passwords were stolen. It establishes the malicious design of the page and the credential-collection route. We will not invent victim totals or claim that the genuine Claude or Google services were breached.<\/p>\n<p>Anthropic and Google are impersonated in the lure. The danger is the page that uses their appearance to obtain trust, not a flaw in a genuine Claude Max promotion.<\/p>\n<div id=\"mwtad1312057607\" class=\"gas_fallback-ad_309747-ad_309685-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>The Fake Browser Window Is the Clever Part<\/h2>\n<div id=\"mwtad2802086823\" class=\"gas_fallback-ad_381404-ad_309685-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>People have learned to inspect a sign-in address and look for a padlock. This scam draws both inside the webpage itself. After the visitor clicks the Google option, the page displays what looks like a separate browser window with a Google address bar.<\/p>\n<p>It is not a browser window. It is a drawing controlled by the site. The real address remains at the top of the actual browser, outside the fake pop-up. If you type into the drawn form, the information goes to the operator&#8217;s page, not to Google.<\/p>\n<p>Researchers call this a browser-in-the-browser technique. The visual trick works because a user can correctly remember \u201ccheck the URL\u201d and still inspect the wrong bar. The counterfeit bar may show the exact trusted domain while the genuine bar shows the giveaway site&#8217;s address.<\/p>\n<div id=\"mwtad24636327\" class=\"mwtadp5 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"8560433799\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>The fake window can be dragged inside the webpage, which adds to the illusion. A real separate window can move beyond the page boundary; a panel drawn inside a tab cannot. That simple boundary test can reveal the trick, although avoiding the unverified offer is safer than experimenting with its login form.<\/p>\n<p>There was also a human-verification stage before the credential request. A verification challenge can make the flow feel protective, while also making automated scanners work harder to reach the next screen. Passing it does not convert the page into a trusted Google service.<\/p>\n<p>Malwarebytes found that the window was loaded through a reusable sign-in widget from an outside service. That technical detail matters because the operator did not need to build a custom imitation from scratch. Similar visual deception can be reused with another offer or another brand.<\/p>\n<div id=\"mwtad1377230893\" class=\"mwtadp6 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"4034304343\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>The best independent clue is your password manager. It checks the genuine browser address, not the address drawn inside a webpage. If it normally fills your Google login but stays silent here, do not override that warning by typing manually.<\/p>\n<div id=\"mwtad1082968082\" class=\"gas_fallback-ad_309748-ad_309685-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why \u201cNo Credit Card Required\u201d Is Not Reassuring<\/h2>\n<p>Our earlier report on <a href=\"https:\/\/malwaretips.com\/blogs\/fake-claude-desktop-ads-malware\/\">fake Claude Desktop ads<\/a> describes a different impersonation route. Here, the examined lure is a giveaway and its documented goal is Google credentials. The shared brand does not make the two campaigns interchangeable.<\/p>\n<p>Many people expect a scam to ask for a card number. This page deliberately did not. Its promise that no payment details were needed was part of the lure&#8217;s credibility, not proof that the offer was safe.<\/p>\n<p>A Google account can be more valuable than one card form. It may contain email, files, contacts, saved recovery messages, and access to other services that use Google sign-in. The exact impact depends on the account and what other safeguards are enabled.<\/p>\n<p>If a criminal enters your email account, they may see password-reset notices and account alerts. That can help them target other services. If you also use Google sign-in for Claude, the same compromised identity may provide a route toward that paid account.<\/p>\n<p>The investigation does not show that every person who viewed the page had accounts compromised. Viewing a page and submitting credentials are different events. The appropriate response depends on whether you merely saw the offer, clicked through, entered a password, or approved a login prompt.<\/p>\n<p>A real promotional giveaway should be findable through the provider&#8217;s official site or authenticated account. You should not have to trust a countdown on a separate domain as the only proof that it exists.<\/p>\n<figure><img decoding=\"async\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" class=\"wp-image-419344 lazyload\" loading=\"lazy\" alt=\"Reconstruction of a fake Google sign-in window drawn inside a giveaway webpage\" width=\"1672\" height=\"941\" title=\"\" sizes=\"auto, (max-width: 1672px) 100vw, 1672px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/claudemax-2.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/claudemax-2.png 1672w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/claudemax-2-300x169.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/claudemax-2-1024x576.png 1024w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/claudemax-2-1536x864.png 1536w\"><\/figure>\n<div id=\"mwtad1831007892\" class=\"gas_fallback-ad_318930-ad_309685-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>The One Screen You Must Not Trust<\/h2>\n<p>The sign-in panel is where the page stops being merely an overgenerous offer and asks for control of a real account. A Google logo, a drawn address bar, and a padlock can all appear inside an ordinary webpage. They are pixels, not browser security indicators.<\/p>\n<p>Look above the page, at the actual browser bar. Better still, leave the offer and open Claude from a bookmark. If a free month is real, the provider should be able to confirm it without a third-party page collecting a password.<\/p>\n<div id=\"mwtad132445787\" class=\"gas_fallback-ad_381388-ad_309685-placement_406705\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3191649120\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the Fake Claude Max Giveaway Scam Works<\/h2>\n<h3>Step 1: An attractive free upgrade pulls the visitor in<\/h3>\n<p>The page claims there is a limited supply of one-month Max subscriptions. Because paid AI access can be expensive, the offer has an obvious audience. The destination does not need to promise impossible lifetime benefits; a free month is enough to invite a click.<\/p>\n<p>The researchers examined the page itself. They did not establish every traffic source that brought visitors there, so an ad, email, or search result should be treated as a possible route rather than a documented source for every visitor.<\/p>\n<h3>Step 2: Social proof and real links reduce doubt<\/h3>\n<p>The page uses ratings, testimonials, brand colors, and links to genuine pages. A cautious reader who clicks a footer link may land on a real Anthropic site and conclude that the giveaway page must also be official.<\/p>\n<p>That conclusion does not follow. Anyone can link to an authentic website. The important question is whether the provider links back to the offer from a verified channel.<\/p>\n<h3>Step 3: The timer pressures the decision<\/h3>\n<p>The availability counter falls while the visitor reads. It suggests that verification must happen now or the prize will disappear. Malwarebytes found the count reset on reload, exposing it as a locally generated display.<\/p>\n<p>That discovery is stronger than a vague suspicion about urgency. The page&#8217;s own behavior contradicts the idea that it is tracking a real pool of remaining subscriptions.<\/p>\n<h3>Step 4: Sign-in alternatives collapse to one route<\/h3>\n<p>Apple sign-in says it is unavailable, and the email box steers back to Google. The visitor is funneled toward the specific imitation the attacker built.<\/p>\n<p>A broken sign-in option on its own can happen on an ordinary site. Here, combined with a fake giveaway and the counterfeit Google window, it is part of the observed phishing mechanism.<\/p>\n<h3>Step 5: A webpage pretends to be a Google window<\/h3>\n<p>The drawn pop-up shows an internal address bar and a padlock. It asks the visitor to complete verification and then provide login information. The real browser bar still belongs to the giveaway site.<\/p>\n<p>At this stage, a password manager may decline to fill credentials. That is a good reason to stop. Do not copy a password from your vault into the form merely to \u201cmake it work.\u201d<\/p>\n<h3>Step 6: The stolen identity can be used elsewhere<\/h3>\n<p>Once credentials are submitted, the account owner should assume the password is exposed and secure Google directly. A criminal may attempt to sign in, change recovery settings, or use the mailbox for further impersonation.<\/p>\n<p>Those are potential consequences, not outcomes documented for every visitor. Prompt account recovery can reduce the harm even if the original giveaway page is later removed.<\/p>\n<div id=\"mwtad451997351\" class=\"gas_fallback-ad_381392-ad_309685-placement_406664\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Site, Address, Support, and Account Checks<\/h2>\n<h3>Is the giveaway run by Anthropic?<\/h3>\n<p>Find the promotion on Anthropic&#8217;s official site or inside your genuine account. A page using familiar colors and product wording is not the same as a provider announcement. Malwarebytes identified the examined page as a phishing operation, not an authorized giveaway.<\/p>\n<p>Do not confuse the fake offer with Anthropic&#8217;s legitimate paid products. A brand can be real while a page claiming to speak for it is fraudulent.<\/p>\n<h3>What does the actual address bar say?<\/h3>\n<p>Look at the top-level browser address, not the bar drawn inside a pop-up. If the real address is the giveaway site, a fake \u201caccounts.google.com\u201d label inside the page does not move you to Google.<\/p>\n<p>Some malicious pages rotate domains. Memorizing one old address is less useful than checking the relationship between the current real tab and the service you intended to visit.<\/p>\n<h3>Is there independent support for the offer?<\/h3>\n<p>Contact Anthropic through its published support route from a new tab or saved bookmark. Do not use a chat widget on the suspicious page as the only verifier. Its operator controls both the offer and that conversation.<\/p>\n<p>Ask whether the promotion exists and whether it requires Google sign-in on a third-party site. If no official announcement can be found, there is no reason to risk account credentials.<\/p>\n<h3>Can the promised subscription be traced?<\/h3>\n<p>A genuine upgrade should be visible in your real account after you claim it through the provider&#8217;s approved flow. A counter, badge, or confirmation screen on the separate page is not account entitlement.<\/p>\n<p>Do not provide documents, card details, or recovery codes if the site adds another requirement. The observed sample targeted Google login, and a changed future variant may ask for more.<\/p>\n<div id=\"mwtad368752860\" class=\"gas_fallback-ad_381392-ad_309685-placement_406665\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li><strong>If you only viewed the page, close it.<\/strong> Do not sign in through its button. Seeing the offer is not the same as submitting a password.<\/li>\n<li><strong>If you entered Google credentials, change the password immediately.<\/strong> Open Google&#8217;s account security page yourself, not through the giveaway. Use a strong unique password.<\/li>\n<li><strong>Sign out other sessions and review devices.<\/strong> Remove unfamiliar sessions and check recent security activity, recovery email, recovery phone, and forwarding settings.<\/li>\n<li><strong>Strengthen multifactor protection.<\/strong> Turn on a trusted second factor and reject any approval request you did not initiate. If you entered a one-time code on the page, tell account support.<\/li>\n<li><strong>Check connected services.<\/strong> Review applications linked to Google and remove anything unfamiliar. Inspect Claude separately if you use Google sign-in there.<\/li>\n<li><strong>Warn your contacts if email was accessed.<\/strong> Attackers can send follow-up lures from a real account. A short warning helps people avoid links that appear to come from you.<\/li>\n<li><strong>Preserve and report the page.<\/strong> Keep its URL, screenshots, time, and messages that led you there. Report it to the relevant platform, Google, Anthropic, and your local fraud authority.<\/li>\n<li><strong>Check the device if you downloaded anything.<\/strong> This sample was described as credential phishing, not an installer. If a later variant asks for software, use Malwarebytes to scan the device. AdGuard can help block known malicious destinations, but neither tool restores a stolen password by itself.<\/li>\n<li><strong>Ignore rescue messages.<\/strong> Anyone promising to unlock your Google or Claude account for a fee outside official recovery channels may be trying to exploit the same incident again.<\/li>\n<\/ol>\n<h2>Frequently Asked Questions<\/h2>\n<h3>Was there really a free Claude Max giveaway?<\/h3>\n<p>Malwarebytes found the examined page to be a phishing lure, not an official Anthropic promotion. Verify any future offer on Anthropic&#8217;s own site before signing in.<\/p>\n<h3>Why did the page say no card was needed?<\/h3>\n<p>The target was Google login information. Avoiding a card request made the offer look safer while still asking for something valuable.<\/p>\n<h3>Does the Google-looking window prove I am on Google?<\/h3>\n<p>No. The scam draws a fake window inside its webpage. Check the actual browser&#8217;s top-level address and use your password manager as an additional clue.<\/p>\n<h3>Is the shrinking number of spots real?<\/h3>\n<p>In the investigated page, it was scripted inside the browser and reset when the page reloaded. It did not count genuine subscriptions.<\/p>\n<h3>I typed my email but not my password. What should I do?<\/h3>\n<p>Be alert for follow-up phishing messages, but a typed email alone is not the same as a stolen password. If you also entered a password or code, secure the account immediately.<\/p>\n<h3>Could this page affect my actual Claude subscription?<\/h3>\n<p>If you use the compromised Google account to sign in to Claude, it may expose that account too. Review sessions and billing inside the genuine service after securing Google.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>The fake Claude Max giveaway is a credential-theft page wrapped in a friendly free-month offer. Its most convincing detail, the Google-looking sign-in window, is part of the deception.<\/p>\n<p>Ignore the counter, open the real provider yourself, and never enter your Google password into a window drawn inside a third-party webpage.<\/p>\n<div id=\"mwtad4187108660\" class=\"gas_fallback-ad_176819-ad_309685-placement_406666\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A page offers a free month of Claude Max. There is a neat sign-in button, a familiar AI-service look, and a counter showing the last places disappearing. It even says you will not need a &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Fake Claude Max Giveaway Steals Google Logins\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/fake-claude-max-giveaway-google-login-scam\/#more-419342\" aria-label=\"Read more about Fake Claude Max Giveaway Steals Google Logins\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":419343,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-419342","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/419342","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=419342"}],"version-history":[{"count":2,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/419342\/revisions"}],"predecessor-version":[{"id":419392,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/419342\/revisions\/419392"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/419343"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=419342"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=419342"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=419342"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}