Fake Claude Max Giveaway Scam: Protect Your Google Account
A website claiming Anthropic just hit 100 million users and wants to celebrate by giving away 10,000 free months of Claude Max is not a celebration. It is a Google credential trap, according to Malwarebytes, which uncovered the fake Claude Max giveaway scam this week. The page never asks for money. It asks for something more valuable: the password to your Google account.
The bait works because it borrows a real financial incentive. Claude's paid plans start at $20 a month and get considerably more expensive at higher usage tiers, while free accounts run into stricter limits fairly quickly, Malwarebytes reports. A free month of the top-tier plan is a genuinely appealing offer, which is exactly why it makes effective bait. Phishing has always followed what people want, and right now that includes AI subscriptions nobody wants to pay for, per Malwarebytes.
This isn't an isolated stunt. Microsoft Threat Intelligence documented a growing wave of phishing, malicious advertising, and search-driven attacks impersonating ChatGPT, Copilot, DeepSeek, and Claude earlier this year, including an Anthropic-branded phishing campaign that reached more than 2,000 organizations. This guide walks through how the fake giveaway operates, the specific tells that expose it, why the real prize is a Google account rather than an AI subscription, and what to do if you already typed in your password.
How the fake Claude Max giveaway scam works
Video of the Day

The page opens with an announcement: Anthropic supposedly crossed 100 million users and is thanking everyone with 10,000 free one-month subscriptions to Claude Max, the company's highest-usage tier, according to Malwarebytes. A live counter sits below the pitch, showing fewer than 750 of those 10,000 slots supposedly remaining and ticking down every few seconds.
Nothing is actually being counted. The number is generated inside the visitor's own browser and resets the moment the page reloads, so every single person who lands on the site sees an identical, manufactured shortage, Malwarebytes found. It is theater, not inventory.
The page's FAQ section does something else worth noticing: it repeatedly insists that no payment details are required to claim the offer. That reassurance should raise suspicion rather than lower it. A scam that goes out of its way to promise it isn't after your credit card is usually telling you, indirectly, what it is actually after.
This is urgency and scarcity standing in for legitimacy, a pattern that shows up across other AI-brand lures too. Microsoft's June 2026 research described a ChatGPT-themed phishing campaign that sent roughly 4,500 emails, most of them to targets in South Africa, warning recipients their ChatGPT Plus subscription would be downgraded to the free plan within seven days unless they updated their payment method. Clicking through led victims across a chain of legitimate-looking redirects before landing on a page built to harvest credit card numbers and expiration dates, per Microsoft. Different bait, same engine: a deadline, a threat of loss, and a page designed to look official enough that nobody stops to check.
Video of the Day
The real target: a Google login phishing scam, not a Claude giveaway

Click the giveaway's "claim now" button and two sign-in options appear. Only one of them actually works. The Apple button throws a pre-written message saying that sign-in method is temporarily unavailable, and typing anything into the accompanying email field quietly discards it and redirects to the Google button instead, Malwarebytes reports. Every path on the page funnels to the same destination, and the prize waiting there is far bigger than a free month of software.
A Google account is not just an inbox. It typically connects to stored documents, backups, and the password-reset emails for a long list of other services, from banking apps to social media. Whoever controls the Google login effectively controls the recovery path into everything tied to it, which is why Malwarebytes describes it as far more valuable than the giveaway itself.
There's a second wrinkle for Claude users specifically. Anyone who signs into their actual Claude account using "Sign in with Google" could give attackers a route into that account too, once the underlying Google credentials are compromised, Malwarebytes notes. The fake giveaway and the real subscription share the same weak point.
Worth stating plainly: none of this means Claude, Google, or Anthropic got hacked. Microsoft's research on AI-brand impersonation is explicit that this kind of activity is brand abuse, not evidence that any of the referenced companies had their systems breached. The scam borrows a trusted name; it doesn't come from behind it.
How fake Google sign-in windows steal your login

The pop-up window that appears when you click "Sign in with Google" looks convincing because it's built to. Security researchers have tracked this technique, known as browser-in-the-browser phishing, since 2022, Malwarebytes notes. The address bar, the padlock icon, and everything else inside that "Google" window are simply drawn by the attacker's own page. None of it is a real browser window. It's an image doing an impression of one.
The engineering behind the illusion is more polished than a single scammer knocking something together in an evening. The fake window loads through one line of code pulled from an outside service that presents itself to other criminals as a reusable sign-in widget, complete with installation instructions, Malwarebytes found. Comments inside that code are written in Russian and refer to the target plainly as "the victim." One comment even explains a bug fix: dark-themed versions of the fake window used to flash white while loading, so the widget now fetches the correct color scheme in advance to avoid that tell. This is a maintained product, not a one-time hack.
The flow also opens with a human-verification step before anything resembling a password box appears, which may make the process feel more legitimate to a visitor while likely helping the page dodge automated security scanners, per Malwarebytes. It buys the fake site a little more time before it gets flagged and blocked.
This isn't confined to Claude-themed lures, either. Malwarebytes points to a separate campaign, tracked by Unit 42 in June 2026, that used the same kind of draggable fake browser window to target Microsoft 365 users. The wrapper changes with whatever brand is trending; the mechanics underneath stay consistent.
Microsoft's own research turned up a comparable setup in its Anthropic-branded phishing campaign that ran for three days in April 2026, hitting more than 2,000 organizations, most heavily in the United States, the United Kingdom, and India. That campaign used a fake "Claude Appeal Request" email with a PDF attachment, routing victims through several redirects before landing them on infrastructure consistent with adversary-in-the-middle tactics, designed to intercept login sessions in real time, according to Microsoft. Different delivery method, same goal: get past the login screen without the victim noticing anything unusual.
How to spot a fake Claude offer: a step-by-step check

Most people won't inspect page source or trace redirect chains before clicking a login button. They don't need to. A handful of quick, low-tech checks catch this scam reliably:
-
Drag the sign-in window toward the edge of your screen. A genuine Google popup is a separate browser window and moves freely anywhere on your display. A fake one is trapped inside the webpage that created it and stops dead at its border. It takes about two seconds and, per Malwarebytes, it's the single most reliable test a non-technical user has available.
-
Let your password manager make the call. It checks the actual site address behind the page, not whatever logo or branding is displayed on screen. If it stays silent in a spot where it would normally offer to autofill your Google credentials, trust that silence over what your eyes are telling you.
-
Treat countdowns and slot counters as decoration. A "fewer than 750 remaining" banner on a giveaway page isn't tracking anything real. Ignore it entirely rather than letting it push you toward a faster, less careful decision.
-
Get suspicious the moment only one login option works. A page that conveniently disables Apple sign-in, or silently discards whatever you type into an email field, is steering everyone toward one specific, pre-built path. That's a design choice, not a glitch.
-
Go to the source directly instead of clicking through. Type claude.ai or google.com into your address bar yourself rather than following a link from an ad, an email, or a social media post. It costs a few extra seconds and sidesteps the entire fake page.
Any one of these checks would have exposed the giveaway page in seconds. Together, they cover most of the phishing variants likely to show up next, whatever brand name they borrow.
What to do if you already entered your Google password
Closing the browser tab does not undo a completed login. If credentials were typed into the fake window, the fix starts with changing the real Google password immediately, through Google's actual website rather than any link from the phishing page, Malwarebytes advises.
After that, sign out of every other active session tied to the account and review the list of connected apps and devices for anything unfamiliar. Attackers who grab a working session can sometimes stay logged in even after a password change, so cutting off those other sessions matters as much as the password itself.
For longer-term protection, CISA strongly urges organizations to adopt phishing-resistant multifactor authentication, such as hardware security keys or passkeys, as the strongest available defense, and recommends number-matching MFA as an interim fallback where phishing-resistant options aren't yet in place (CISA). That guidance is aimed at organizations, but the underlying logic holds for a personal Google account too: a fake browser window can copy anything on screen, but it can't forge a physical security key or a passkey tied to the real device.
Browser-level scam blockers add another layer before any of this becomes necessary. Tools like Malwarebytes Browser Guard block known phishing and scam domains before the page even loads, which stops the fake giveaway from opening in the first place rather than relying on a user to spot it mid-scam.
Anthropic's own Threat Intelligence team has spent recent months investigating and disrupting misuse of Claude, publishing regular findings on how bad actors attempt to exploit the platform, according to its threat intelligence page. Its most recent report this month covered operations identified and shut down over the prior eight months. Phishing pages that misuse the Claude name sit outside Anthropic's own systems, but the company's ongoing tracking is part of the broader effort to make brand impersonation harder to pull off convincingly.
The fake Claude Max giveaway will get patched, taken down, or replaced with a new theme eventually. The checks that expose it won't age nearly as fast. A genuine offer, if one exists, can wait the extra ten seconds it takes to open a new tab and check Claude or Google directly rather than trusting whatever window just popped up.