Consumer Rights · Scam Alert · September 23, 2026
The offer is for access to about $200 worth of Anthropic’s Claude Max service.
Executive Briefing · Key Facts.
- cnet.com issued a new alert: New Phishing Attack Promises Claude Max, but Steals Your Google Credentials Instead.
- Delivery channel shown in the reconstruction below: Gmail.
- Pressure tactics matched: Unsolicited contact from someone you don’t know.
The Story So Far
But the real price could be giving scammers access to everything in your Google accounts. A new phishing scam reported by the cybersecurity service Malwarebytes works like this: The scam claims that Anthropic is celebrating attracting 100 million users by giving 10,000 people a free month of Claude Max with x20 limits.[1]
The offer, which includes “extended thinking” and “priority access to Opus and Sonnet, no caps,” is actually all cap. It’s a fake offer that leads to a Google login page meant to steal login and password information, which could in turn open up access to Gmail, Google Docs and other non-Google accounts that use your Google information.[1]
The fake giveaway, Malwarebytes said in its report, is different from many other phishing attempts because of how convincing it looks. “The presentation is careful, down to the real logo and colors, invented five-star reviews, and a long footer whose links lead almost entirely to genuine Anthropic pages,” wrote Stefan Dasic, senior malware research engineer at Malwarebytes.[1]
The page also includes a running counter showing how many of those fake 10,000 accounts have been given away.[1]
What This Looks Like
Every tactic above beats a specific human default. None of them beat a phone number you looked up yourself.
How to Protect Yourself
- Verify any unexpected contact through a phone number or website you already know is real — never one the message itself provides.
If You Already Clicked or Replied
Responding to one of these is not the end of the story, and the first hour matters more than the mistake does. Work down this list in order:
- Stop communicating with the sender. Do not send a final message explaining that you know it is a scam — that only confirms the number or address is live.
- If you shared a password, change it everywhere you reused it, starting with email and banking. Reused passwords are how one disclosure becomes several.
- If you shared card or bank details, call the number printed on your card and ask for the account to be flagged and reissued.
- If you sent money by gift card, call the card issuer immediately — some balances can be frozen if the cards have not been drained yet.
- Turn on two-factor authentication where it is offered, so a stolen password alone is not enough to get in.
- Report it (see below). Reports are what let investigators connect one message to a wider campaign.
Where to Report It
- Federal Trade Commission — reportfraud.ftc.gov is the FTC’s own intake for fraud reports.[2]
- FBI Internet Crime Complaint Center — ic3.gov handles internet-enabled crime, including losses already incurred.[3]
- The impersonated organization — most banks and large platforms run their own abuse address; reporting there is what gets a fraudulent number or domain taken down.
What’s Disputed or Unconfirmed
This post reports what cnet.com published and what a fixed detector matched in that text. It does not independently confirm the scale of the campaign, attribute it to anyone, or verify any figure the source reports. The example below the fold is a reconstruction built from the same reporting, not a captured message — so treat its wording as illustrative of the pattern, not as evidence of a specific message anyone received.
How to Verify This Yourself
Read the original alert directly at cnet.com[1] — that page is the primary source for everything above. For the recovery steps, the FTC publishes its own guidance on what to do after a scam.[4]
Kemetic Minds Analysis
Scam reporting tends to arrive as a list of things not to do, which puts the burden entirely on the person being targeted. The more useful read is structural: every tactic in the table above exists because it reliably beats a specific human default — trusting a familiar logo, acting fast under a deadline, believing a stranger who already seems to know something about you.
None of those defaults are failures of intelligence. They are the same instincts that make ordinary transactions possible. That is why “just be careful” does not work as advice, and why the one habit worth building is mechanical rather than judgmental: when a message asks for money, credentials, or speed, verify it through a channel you chose yourself. That single rule defeats every tactic listed above, without requiring you to spot which one you are looking at.
References
- cnet.com. New Phishing Attack Promises Claude Max, but Steals Your Google Credentials Instead. — primary source for this alert. ↩
- Federal Trade Commission. Report Fraud. — primary (U.S. government agency). ↩
- FBI Internet Crime Complaint Center (IC3). — primary (U.S. government agency). ↩
- Federal Trade Commission. What To Do if You Were Scammed. — primary (U.S. government agency). ↩
Related Reading
- More Consumer Rights coverage — the running Scam & Cybersecurity Watch archive.
- FTC: What To Do if You Were Scammed — the full official recovery guide.
Investigative methodology: this update was produced by scripts/scam_monitor.py from a real cnet.com alert — not a language model. The quoted text above is verbatim from the source; the mockup, where shown, is a reconstructed illustration built from the same text (see its own caption), not a captured real message. Protection tips, red-flag explanations, and recovery steps are matched from fixed curated tables, not generated per story. The “Kemetic Minds Analysis” section is standing editorial commentary about how these tactics work in general — it is identical on every Scam Watch post and is not reporting about this particular alert.

