By: Tech Security Desk
Published: September 2026
Main Facts
Cybersecurity researchers have uncovered a highly convincing, technologically sophisticated phishing campaign that uses the allure of artificial intelligence to compromise user credentials. Discovered and analyzed by threat intelligence experts at Malwarebytes, the scam lures unsuspecting victims with the promise of a free, high-end upgrade to Anthropic’s "Claude Max" service—a bundle ostensibly valued at around $200.
However, security analysts warn that the actual price of admission is far higher, handing malicious actors full access to victims’ Google accounts and, by extension, a treasure trove of sensitive personal and professional data.
The fraudulent scheme capitalizes on the explosive mainstream popularity of generative AI tools. According to the lure, Anthropic is supposedly celebrating a major milestone of attracting 100 million active users. To mark the occasion, the scam claims the company is gifting 10,000 lucky individuals a free month of Claude Max featuring enhanced capabilities, including "extended thinking," 20x usage limits, and priority, uncapped access to Anthropic’s advanced Opus and Sonnet models.
In reality, the entire offer is "all cap." Victims who click through to claim their prize are funneled into a cleverly engineered credential-harvesting trap designed to intercept Google login credentials. Because many modern web services rely on single sign-on (SSO) ecosystems, compromising a primary Google account can give hackers unhindered entry into associated Gmail inboxes, Google Drive documents, cloud backups, and even third-party applications linked via Google authentication.
What elevates this campaign above routine phishing attempts is its extraordinary level of polish. Unlike clumsy, typo-ridden emails or obviously fake landing pages, this operation utilizes advanced browser-in-browser spoofing, authentic branding elements, and psychological pressure tactics to deceive even tech-savvy internet users.
Chronology of the Threat
The timeline of this specific campaign reflects the rapid agility with which modern cybercriminal syndicates deploy infrastructure to exploit trending technology topics.
- Early September 2026: Threat actors deploy the infrastructure for the fake Anthropic giveaway campaign. Initial web hosting configurations are established using rented servers to mask the operators’ true geographic locations and identities.
- Mid-September 2026: Social media advertisements, search engine optimization poisoning, or targeted messaging begin directing users to the professionally designed fraudulent landing page. The site features a dynamic, real-time counter displaying the dwindling number of remaining "free accounts," generating artificial urgency.
- Mid-September 2026: Security researchers at Malwarebytes detect anomalous traffic patterns and analyze the fraudulent domain. Stefan Dasic, senior malware research engineer at Malwarebytes, leads the technical investigation, unearthing the browser-in-browser phishing mechanism.
- Publication Date: Malwarebytes publishes its threat intelligence report, alerting the public, enterprise security teams, and industry peers to the scam. Investigations reveal that the site’s backend infrastructure is tied to a UK-registered company, though security researchers emphasize that this registration likely represents a stolen identity or a shell corporation used to obscure the perpetrators.
Supporting Data and Technical Mechanics
To understand why this phishing campaign is so dangerous, one must examine the meticulous engineering behind the fraudulent landing page. According to Malwarebytes’ analysis, the threat actors went to extraordinary lengths to mimic the official Anthropic user experience.
The Anatomy of the Illusion
When users navigate to the malicious URL, they are greeted by an interface that is virtually indistinguishable from a legitimate corporate portal.
- Visual Fidelity: The page utilizes authentic Anthropic logos, precise corporate color palettes, and polished typography.
- Social Proof: To build immediate trust, the site incorporates fabricated five-star user testimonials praising the purported Claude Max upgrade.
- Authentic Footers: In a departure from typical phishing pages—which often feature broken or missing footer links—the vast majority of hyperlinks in the footer of this fraudulent site redirect visitors to genuine, legitimate pages on Anthropic’s official website. This clever trick lulls visitors into a false sense of security, making them believe they are on an official subdomain or partner platform.
- The Urgency Counter: A prominent, active counter displays a running tally of the supposed 10,000 free accounts being claimed, weaponizing the psychological principle of scarcity to prompt rushed decision-making.
The Browser-in-Browser Trick
The centerpiece of the technical attack is a sophisticated user-interface spoofing technique known as a "browser-in-browser" (BiB) attack.
When a victim decides to claim the offer, they are prompted to upgrade their account. Standard authentication options, such as logging in via Apple ID, are intentionally disabled or greyed out. This leaves only one viable path: "Sign in with Google."
Upon clicking the Google sign-in button, the page does not redirect the user to a new tab or an external pop-up window managed by the operating system. Instead, the malicious script draws a convincing, self-contained browser window directly inside the existing browser tab.
Stefan Dasic described the precision of this illusion in his report: "The page draws a browser window inside the existing tab, complete with a padlock and a correctly spelled Google sign-in address. It can even be dragged around the page."
For individuals who do not closely inspect the finer details of their browser canvas—such as noticing that the window frame exists inside the web page rather than as an independent operating system application—the trap snaps shut. Once the victim inputs their email and password into the spoofed window, the credentials are immediately transmitted to the attackers.

Infrastructure and Attribution Challenges
As cybersecurity investigators trace the digital footprints left behind by the threat actors, tracking down the perpetrators has proven exceptionally difficult.
Initial forensic sweeps traced the hosting server to a UK-registered corporate entity. However, Malwarebytes experts caution that this finding offers limited insight into the real identity of the hackers. Renting servers with stolen credentials, prepaid credit cards, or cryptocurrency is a standard operational security measure for modern cybercrime organizations.
Furthermore, technical analysis of the website’s source code revealed developer comments written in the Russian language. While this might lead casual observers to jump to conclusions regarding the geographical origin of the threat actors, seasoned cybersecurity researchers treat such linguistic markers with extreme skepticism. Code comments can easily be fabricated, copied from open-source repositories, or deliberately planted by malicious actors to misdirect law enforcement and intelligence agencies. As Dasic noted, "Language in code is weak evidence on its own and has been planted before to misdirect."
Official Responses and Industry Context
As artificial intelligence platforms become deeply integrated into both personal workflows and corporate environments, they have increasingly become prime targets for social engineering campaigns.
The Unique Vulnerability of AI Ecosystems
The architecture of modern AI platforms compounds these risks. Because many popular AI assistants—including Claude—do not rely on standalone, traditional username-and-password combinations created from scratch by every user, they frequently tie access directly to third-party identity providers like Google or Microsoft. Alternatively, they use magic login links sent directly to a user’s email address.
This design choice creates a dangerous single point of failure. As Dasic explained in a statement to technology publication CNET: "The overlap matters because Claude has no password of its own: You get in either by continuing with Google or by a login link sent to your email. So if someone’s Claude account is tied to the Google account that was phished, the attacker reaches it either way."
By seizing control of a victim’s Google account, the threat actors automatically gain administrative control over any connected AI tools, third-party software integrations, and cloud storage repositories tied to that identity.
Industry Warnings
Security firms and technology journalists have amplified warnings regarding this campaign, categorizing it as part of a broader, troubling trend wherein cybercriminals leverage high-demand technological perks—such as free API credits, premium AI tiers, or exclusive software betas—to bypass human skepticism.
Anthropic, Google, and other major technology providers continuously work alongside third-party threat intelligence vendors to takedown fraudulent domains as soon as they are identified. However, the decentralized nature of domain registration and the speed at which threat actors can spin up new infrastructure mean that proactive user vigilance remains the primary line of defense.
Broader Implications for Digital Security
The emergence of the fake Claude Max phishing campaign highlights critical vulnerabilities in how everyday internet users interact with authentication prompts and promotional offers online. As generative AI continues to dominate the cultural and commercial landscape, scammers will undoubtedly continue to exploit brand names like Anthropic, OpenAI, Microsoft, and Google to perpetrate fraud.
The Ripple Effect of a Compromised Google Account
The fallout of falling victim to a Google account phishing scam extends far beyond losing access to an AI chatbot subscription. For the average consumer and professional, a primary Google account acts as the digital master key to their entire online existence.
Once inside a compromised Google ecosystem, malicious actors can:
- Exploit Recovery Options: Reset passwords for banking, shopping, and social media accounts by intercepting password-reset emails sent to the linked Gmail inbox.
- Exfiltrate Private Data: Access confidential documents, photographs, financial spreadsheets, and personal communications stored in Google Drive and Google Photos.
- Deploy Lateral Attacks: Use the victim’s compromised email address to send spear-phishing messages to colleagues, friends, and family members, expanding the reach of the criminal network.
- Monetize Cloud Resources: Leverage compromised enterprise or developer accounts to mine cryptocurrency, run unauthorized machine learning workloads, or execute secondary cyberattacks.
How to Protect Yourself Against Browser-in-Browser Scams
In light of this evolving threat, cybersecurity experts recommend adopting stringent defensive habits to avoid falling victim to sophisticated UI spoofing and phishing traps:
- Verify the Authentication Context: Be extremely suspicious of login prompts that appear inside a webpage canvas rather than as an independent operating system window or a trusted redirect to an official
accounts.google.comURL. If you can drag the login box outside of the active webpage boundaries or if it behaves unusually within the browser viewport, close the tab immediately. - Enable Hardware-Based Multi-Factor Authentication (MFA): Traditional SMS-based or app-based push notifications can sometimes be bypassed or manipulated. Utilizing FIDO2-compliant physical security keys (such as YubiKeys) for Google account logins provides robust protection because physical keys cannot be spoofed by browser-in-browser phishing pages.
- Inspect URLs Rigorously: Always check the address bar of your browser. While malicious pages can spoof internal elements, they cannot legally replicate the official domain structure of trusted identity providers unless you are actively visiting their site.
- Adopt a Healthy Skepticism of "Free" Upgrades: Remember the old digital adage: if an offer sounds too good to be true, it almost certainly is. Major technology companies rarely distribute hundreds of dollars worth of premium software tiers via unverified third-party promotional landing pages or unexpected social media advertisements.
- Monitor Account Activity Regularly: Routinely check the "Security" settings of your Google account to review active sessions, connected third-party applications, and recent login history. Revoke access for any unfamiliar devices or applications immediately.
As cybercriminals refine their tactics, marrying high-end web design with advanced psychological manipulation, user education and technical awareness remain the most effective shields against the modern threat landscape.
