Claude Max Giveaway Fakes a Google Window to Steal Logins

Daniel Zimmermann
5 Min Read
A gift ribbon suspends a fake sign-in window inside a browser frame, illustrating the Claude Max phishing lure.
The promised Claude Max gift leads to a counterfeit sign-in window.

A fake Claude Max giveaway offers a free month of AI access, but the login window is part of the trap. In research published on September 23, Malwarebytes describes a page that imitates Google sign-in inside the scam site’s own tab. The familiar address and padlock belong to the drawing, not to a connection with Google.[1]

The gift removes the wrong suspicion

The page promises 10,000 subscriptions and displays a dwindling quota. Researchers found that the counter resets on reload. Its reassuring claim that no card is needed conceals a different demand: a Google login. Apple sign-in reports an error, while the email option also funnels visitors toward Google. Authentic Anthropic links in the footer lend the page borrowed credibility.

Those details work together. Scarcity discourages a pause, the absence of a payment form removes an obvious alarm, and the alternative login buttons create the appearance of choice. Following a footer link to a real company does not establish who controls the form you return to.

The address bar inside the address bar

The researchers identify a browser-in-the-browser technique: a movable imitation window rendered by the webpage. It starts with a human-verification screen. Their screenshot shows the crucial boundary—the supposed Google address sits inside the content area, below the real browser toolbar. The report describes credential harvesting, but does not quantify successful account takeovers.

Imitation Google verification window inside a fake Claude Max giveaway page; the real browser toolbar remains above it.
The inner address bar is part of the webpage. The actual browser toolbar sits above it. Source: Malwarebytes; site address redacted in the original.

A website can draw a convincing window, just as it can draw a bank logo. That picture does not gain the browser’s authority to tell you which server you are visiting. On desktop, a supposed popup that remains confined to the page is a warning sign. A window that moves freely is not, by itself, proof of safety: independently verify the actual destination before entering anything.

This also differs from a fake AI seller using a genuine Google consent screen. In that earlier case, the seller obtained limited profile information through real authorization. Here, the reported login interface itself is counterfeit. Similar branding can conceal different failures, so the response should follow what you actually supplied.

Start a legitimate login yourself

Anthropic’s current instructions list Google sign-in and an emailed login link as ways to access Claude. They also say a dedicated Claude password cannot currently be created. Begin at the service’s own site or installed app, rather than treating a promotion’s imitation window as an identity check.[2]

Nor does “free” alone prove fraud. Anthropic says it occasionally offers limited promotions through official channels, while its Max help page lists regular web subscriptions at $100 or $200 per month. The check is whether the specific offer can be verified independently, not whether it has a polished logo or a generous prize.[3]

If you entered your Google credentials

Open your Google Account independently. Google’s recovery guidance calls for reviewing recent security events and signed-in devices, changing a compromised password, and checking account settings and third-party access. If you cannot sign in, use Google’s account recovery process. Enable two-step verification; review Gmail forwarding or filters if someone may have entered the mailbox.[4]

If the exposed password was reused, change it on those accounts too. Where Google provides access to Claude, inspect Claude activity and billing as a separate check; stolen Claude access can also consume paid usage. Entering credentials warrants action, while merely seeing this page does not establish an account takeover.

The useful distinction is simple: a login-looking picture is still controlled by the page that drew it. A free subscription should never be the reason to stop checking that boundary.

References

  1. Stefan Dasic. “Fake Claude Max giveaway hides a Google account phishing trap.” Malwarebytes, September 23, 2026. Research report.
  2. Anthropic. “Log in to your Claude account.” Claude Help Center, accessed September 23, 2026. Login instructions.
  3. Anthropic. “What is the Max plan?” Claude Help Center, updated September 22, 2026; accessed September 23, 2026. Plans and promotions.
  4. Google. “Secure a hacked or compromised Google Account.” Google Account Help, accessed September 23, 2026. Account recovery guidance.
Share This Article
With a strong background in consumer safety and fraud prevention, Daniel specializes in providing actionable tips and advice to users. His focus is on helping individuals understand the risks of interacting with fraudulent sites and services
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?