{"id":419710,"date":"2026-09-27T12:06:11","date_gmt":"2026-09-27T12:06:11","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=419710"},"modified":"2026-09-27T12:06:11","modified_gmt":"2026-09-27T12:06:11","slug":"fake-call-of-duty-points-giveaway-accounts","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/fake-call-of-duty-points-giveaway-accounts\/","title":{"rendered":"Fake Call of Duty Points Giveaway Steals Accounts"},"content":{"rendered":"<p>A page promises 10,800 free Call of Duty Points. It looks like a game promotion, right down to the familiar dark colors and a helpful-looking support bubble.<\/p><div id=\"mwtad3500136360\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The offer asks for your game login first. Then another screen appears, asking for the fresh authentication code that just arrived in your email.<\/p>\n<p>That second screen is where the fake Call of Duty Points giveaway becomes something else.<\/p><div id=\"mwtad3773010099\" class=\"gas_fallback-ad_381396-ad_309685-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<figure class=\"wp-block-image size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"1536\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/cod-offer-reconstruction.png\" class=\"wp-image-419711 skip-lazy\" loading=\"eager\" alt=\"Illustrative reconstruction of a fake 10800 game-points giveaway requesting email and password\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/cod-offer-reconstruction.png 1024w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/cod-offer-reconstruction-200x300.png 200w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/cod-offer-reconstruction-683x1024.png 683w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<div id=\"mwtad3046288396\" class=\"gas_fallback-ad_309746-ad_309685-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>The prize is a cover for account theft<\/h3>\n<p>The fake Call of Duty Points giveaway is a phishing campaign targeting Call of Duty: Mobile players. <a href=\"https:\/\/www.malwarebytes.com\/blog\/threat-intel\/2026\/07\/call-of-duty-mobile-scam-uses-fake-free-points-to-steal-player-accounts\" target=\"_blank\" rel=\"noopener\">Malwarebytes researchers examined a page<\/a> offering 10,800 points in exchange for an email address and password. It then showed a separate form asking for a two-factor authentication code. The site was not connected to Activision.<\/p>\n<p>Call of Duty Points, often shortened to CP, are real in-game currency. That real term helps the fake offer sound plausible. So does the suggestion that a claimed reward may take four to eight hours to appear. The delay gives the operator time while the player waits for a prize that the page cannot deliver.<\/p>\n<p>The first image is a nonfunctional reconstruction using a fictional `.example` address and generic game styling. It does not reproduce the actual phishing page. The second image later in this article is an authentic research capture of the attack&#8217;s code-entry screen. Neither image should be used to type real credentials.<\/p><div id=\"mwtad3706668119\" class=\"gas_fallback-ad_309686-ad_309685-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<h3>The code request defeats the protection it imitates<\/h3>\n<p>After the victim enters a username and password, the phishing site can relay those details to the genuine Activision login. That real attempt may trigger a genuine one-time code. The attacker-controlled page then asks the victim to type the code into its own form before it expires.<\/p>\n<p>This is why the incoming code can be confusing. A message from the real account provider does not mean the giveaway is genuine. It may mean somebody is attempting to sign in with credentials you just supplied to a fake page.<\/p>\n<p>The code belongs in a login you started on the official site, not in an unfamiliar promotion flow.<\/p><div id=\"mwtad1869020394\" class=\"gas_fallback-ad_381401-ad_309685-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Malwarebytes described this as a real-time credential relay. The name is technical; the idea is simple. The fake page sits between the player and the real login, collecting each piece of the sign-in as it happens.<\/p>\n<h3>What is confirmed about this campaign<\/h3>\n<p>The researchers captured both the offer page and the follow-up code form. They found a phishing process aimed at taking Activision accounts, not a legitimate free-point event or a complaint about Call of Duty pricing. The evidence does not show how many players were compromised, so the article makes no claim about a victim total.<\/p>\n<div id=\"mwtad785726471\" class=\"gas_fallback-ad_381404-ad_309685-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>Activision accounts may have linked platforms, purchases, and saved information. Those make an account valuable beyond its current points balance. The exact damage depends on what the attacker can access after sign-in. A stolen login is the immediate concern; any unauthorized purchases or further account links should be checked individually.<\/p>\n<ul>\n<li><strong>Fake reward:<\/strong> 10,800 Call of Duty Points.<\/li>\n<li><strong>First collection:<\/strong> email address and account password.<\/li>\n<li><strong>Second collection:<\/strong> a live two-factor authentication code.<\/li>\n<li><strong>Claimed delay:<\/strong> reward confirmation in four to eight hours.<\/li>\n<li><strong>Safe destination:<\/strong> the official game app or Activision website reached independently.<\/li>\n<\/ul>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"1024\" height=\"559\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" class=\"wp-image-419712 lazyload\" loading=\"lazy\" alt=\"Authentic capture of the fake Call of Duty two-factor authentication code page\" title=\"\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/cod-code.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/cod-code.png 1024w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/cod-code-300x164.png 300w\"><\/figure>\n<div id=\"mwtad3755325689\" class=\"gas_fallback-ad_309747-ad_309685-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why a Real Code Can Appear in a Fake Flow<\/h2>\n<p>A genuine security code is not a verdict on the website that asked you to enter it. It is a response to a login attempt. If a criminal sends your email and password to the real service, the service may issue a code exactly as it would for you.<\/p>\n<p>The fake form in the screenshot uses familiar language: complete sign-in, enter the authentication code, and act before the countdown expires. That urgency matters because one-time codes are short-lived. The attacker needs the victim to relay the code quickly enough to finish the genuine login.<\/p>\n<div id=\"mwtad1541852020\" class=\"mwtadp5 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"8560433799\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>The page also presents a support widget and policy-style links. Those ornaments do not connect it to Activision. A support button on a phishing page is still controlled by the page&#8217;s operator. A real login code from Activision should be entered only into a login screen you intentionally opened through the official app or website.<\/p>\n<p>If you see a code arrive after using such a giveaway page, stop. Do not keep trying alternate codes or wait for the promised points. Go directly to the real account service and change your password.<\/p>\n<p>If a code was already supplied to the fake page, assume the attacker may have crossed the second factor as well.<\/p>\n<div id=\"mwtad2266411465\" class=\"gas_fallback-ad_309748-ad_309685-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the Fake Call of Duty Points Scam Works<\/h2>\n<h3>Step 1: A huge bonus attracts players<\/h3>\n<div id=\"mwtad495779517\" class=\"mwtadp6 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"4034304343\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>The lure is a points windfall large enough to feel worth a minute of effort. The researched page offered 10,800 CP. It copied game presentation and included a &#8220;Get Free Point&#8221; style call to action.<\/p>\n<p>The awkward wording is a clue, but the main warning is that an unrelated site asks for account credentials to deliver a reward.<\/p>\n<p>Malwarebytes documented the page itself, not one exclusive distribution channel. It might be encountered through a message, search, or social post, but those routes should not be claimed as confirmed for every visitor. The dangerous part starts when a player leaves the official game ecosystem for the copied page.<\/p>\n<h3>Step 2: The site asks for an email and password<\/h3>\n<p>Instead of a redemption code, the page asks for a full Activision sign-in. That is a disproportionate request for a prize. A legitimate promotion may ask a player to use an official account flow, but an unfamiliar domain should never become a place to type the password.<\/p>\n<p>The site claims the reward will be confirmed later. That is convenient for the attacker: no immediate points need to appear while the player is still on the page. If the operator obtains a working password, it can start its own login attempt immediately.<\/p>\n<h3>Step 3: The real service sends a real code<\/h3>\n<p>The phishing process can submit the credentials to Activision as the victim types them. If the account has two-factor protection, the real service may challenge that login. The player then sees a genuine email or authenticator code, perhaps seconds after pressing the fake claim button.<\/p>\n<p>That timing can make the scam feel legitimate. In reality, the code is being generated because someone is trying to access the account. The code message may even say not to share it. Treat that warning literally, regardless of what the giveaway page says.<\/p>\n<h3>Step 4: The fake page asks you to relay the code<\/h3>\n<p>The second screen asks for the one-time code and uses a countdown. A player focused on the bonus may think this is routine verification. The attacker needs exactly that reaction. Once the code is entered, the operator can complete the real sign-in while it is still valid.<\/p>\n<p>Do not assume the attacker needs your phone or access to your email inbox. In this flow, you act as the courier for the code. That is why a security feature can be bypassed without being technically broken.<\/p>\n<h3>Step 5: The account can be taken over or abused<\/h3>\n<p>With a working password and one-time code, an attacker may enter the Activision account, change recovery details, link other accounts, or inspect purchases and payment methods. The exact available actions depend on account settings and platform links. It is safer to audit the account than to guess which action occurred.<\/p>\n<p>If the player waits four to eight hours for points, the attacker may already have had time to work. A missing reward is not the only sign. Unexpected emails, changed profile details, new linked accounts, or purchases you did not make all need prompt attention.<\/p>\n<div id=\"mwtad2033050860\" class=\"gas_fallback-ad_318930-ad_309685-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Company, Address, and Fulfillment Checks<\/h2>\n<h3>The giveaway page is not Activision<\/h3>\n<p>Call of Duty: Mobile and its currency are real. The phishing page that researchers captured had no affiliation with Activision. It borrowed the game&#8217;s name to obtain a login. Check who owns the exact website address before entering credentials; game logos and artwork can be copied.<\/p>\n<h3>A web address is not a business address<\/h3>\n<p>The evidence identifies a counterfeit sign-in flow, not a verified legal company or physical office behind it. An address in a footer, if one appears, would need independent verification. Do not infer that a similarly named legitimate business or hosting provider runs the scam.<\/p>\n<h3>Fake support can keep the victim engaged<\/h3>\n<p>The captured offer displayed a chat-style support bubble. Its presence makes the page look attended, but it does not establish authorized game support. If the &#8220;agent&#8221; asks for more codes, recovery information, or payment to release points, leave. Use Activision&#8217;s own support site instead.<\/p>\n<h3>No points are being fulfilled<\/h3>\n<p>The promised reward is the bait. The traceable flow is credential entry followed by a code request. There is no verified mechanism in the research showing this page can credit a Call of Duty account with legitimate points. A success message would not change that.<\/p>\n<div id=\"mwtad982097947\" class=\"gas_fallback-ad_381388-ad_309685-placement_406705\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3191649120\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How to Tell a Real Promotion From This Trap<\/h2>\n<p>Real game rewards do exist, which is why blanket advice that &#8220;all free points are fake&#8221; is not useful. The useful question is where the offer lives and what it demands. Open the official Call of Duty: Mobile app or <a href=\"https:\/\/www.callofduty.com\/mobile\" target=\"_blank\" rel=\"noopener\">official game site<\/a> independently, then look for the promotion there.<\/p>\n<p>Do not follow a shortened link just because it came from a player community. A screenshot of an offer can be copied, and social engagement is not proof of a partnership. If you cannot find the event through official channels, do not give it your password to test whether it works.<\/p>\n<p>Pay attention to code messages. A two-factor code is for a sign-in you initiated, not a raffle entry. If you are not actively signing into your own account at the official address, do not enter the code anywhere. The same rule protects bank, email, and shopping accounts.<\/p>\n<p>MalwareTips has covered other <a href=\"https:\/\/malwaretips.com\/blogs\/fortlobby-com-scam-fake-fortnite-locker-checker\/\">game-account phishing traps<\/a>. This particular case is distinguished by the real-time relay from a Call of Duty Points page to a fake two-factor screen.<\/p>\n<div id=\"mwtad606953847\" class=\"gas_fallback-ad_381392-ad_309685-placement_406664\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li><strong>Change the Activision password.<\/strong> Go directly to Activision, not back through the giveaway link. Use a unique password. If you reused the old one on email or other gaming accounts, change those too.<\/li>\n<li><strong>Assume access if you supplied a code.<\/strong> Review recent sign-ins, linked accounts, recovery addresses, and any settings that changed. Sign out of sessions you do not recognize. If you are locked out, use <a href=\"https:\/\/support.activision.com\/account-recovery\" target=\"_blank\" rel=\"noopener\">Activision&#8217;s hacked-account recovery<\/a> process.<\/li>\n<li><strong>Protect purchases and payment methods.<\/strong> Check game and platform purchase histories. Contact your card issuer or platform support about transactions you did not authorize. Do not give the fake site&#8217;s support chat a card number to &#8220;verify&#8221; the reward.<\/li>\n<li><strong>Save evidence.<\/strong> Record the website address, message or ad that led there, screenshots of the two forms, the time of the code, and any account-change emails. Do not post your code, password, or full payment details in a public report.<\/li>\n<li><strong>Check for downloads separately.<\/strong> The documented campaign is credential phishing; entering a password does not prove malware was installed. If a page also made you run an app or file, scan the device with Malwarebytes. AdGuard can help block known malicious ads and phishing pages in future browsing, but it cannot invalidate a code already handed over.<\/li>\n<li><strong>Warn teammates and friends.<\/strong> If the link came from a gaming group or a friend&#8217;s account, tell them the offer is fake. Do not accuse the friend of running it; their account or post may have been abused.<\/li>\n<li><strong>Ignore paid recovery promises.<\/strong> A stranger who offers to restore points or reclaim the account for an advance payment can be another scammer. Use the platform&#8217;s official support route.<\/li>\n<\/ol>\n<div id=\"mwtad657332757\" class=\"gas_fallback-ad_381392-ad_309685-placement_406665\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Frequently Asked Questions<\/h2>\n<h3>Are Call of Duty Points real?<\/h3>\n<p>Yes. CP is real in-game currency. That does not make a third-party page offering 10,800 points in exchange for a password legitimate.<\/p>\n<h3>Why did Activision send me a code after using the page?<\/h3>\n<p>The phishing site may have relayed your credentials to the real login. The genuine code is a response to that sign-in attempt, not proof that the giveaway is approved.<\/p>\n<h3>What if I entered my password but not the code?<\/h3>\n<p>Change the password immediately and review the account. The attacker may still hold the password and try it elsewhere, especially if you reused it.<\/p>\n<h3>What if I entered the one-time code too?<\/h3>\n<p>Assume the attacker may have accessed the account. Check linked platforms, account details, sessions, and purchases, then use Activision&#8217;s recovery process if needed.<\/p>\n<h3>Does a support chat bubble make the offer official?<\/h3>\n<p>No. The operator of a fake website can add a chat widget. It does not verify ownership, a game partnership, or the ability to award points.<\/p>\n<h3>Can a real event ask me to sign in?<\/h3>\n<p>Possibly, but sign in only after reaching the event through the official app or website. Never type credentials into an unfamiliar page reached from a giveaway link.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>The fake Call of Duty Points scam promises a large bonus, then collects the password and live code needed to enter a real account. The code can be genuine even while the page requesting it is fraudulent.<\/p>\n<p>If you used the offer, secure the account now. If you have not, find promotions through the official game and keep sign-in codes out of third-party giveaway forms.<\/p>\n<div id=\"mwtad655050020\" class=\"gas_fallback-ad_176819-ad_309685-placement_406666\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A page promises 10,800 free Call of Duty Points. It looks like a game promotion, right down to the familiar dark colors and a helpful-looking support bubble. The offer asks for your game login first. &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Fake Call of Duty Points Giveaway Steals Accounts\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/fake-call-of-duty-points-giveaway-accounts\/#more-419710\" aria-label=\"Read more about Fake Call of Duty Points Giveaway Steals Accounts\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":419711,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-419710","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/419710","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=419710"}],"version-history":[{"count":2,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/419710\/revisions"}],"predecessor-version":[{"id":419719,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/419710\/revisions\/419719"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/419711"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=419710"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=419710"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=419710"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}