Search/activision
Vendor

activision

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
call of duty 2
Connections
9 relationships
Call of Duty Mobile scam uses fake free points giveaway to hijack players’ accounts
Call of Duty Mobile scam uses fake free points giveaway to hijack players’ accounts Call of Duty Mobile players should watch out for a phishing campaign disguised as a free Call of Duty Points giveaway, Malwarebytes researchers have warned. Victims are asked to log in with their email address and password to claim free Call of Duty Points (CP), the game’s premium currency, before being redirected to a second page requesting their 2FA code. “The site has no connection to Activision. Its only purpose is to steal the login details needed to take over accounts,” the researchers said. Call of Duty Mobile has been downloaded an estimated 489 million times and generated around $1.8 billion in lifetime in-app purchases, according to Malwarebytes. An Activision account is often worth more than the in-game points it holds. Players frequently link the account to Xbox, PlayStation, or Battle.net profiles, so a takeover can expose stored payment methods, purchase history, and other connected accounts. How the scam works Disguised as the official Call of Duty Mobile site, the first phishing page offers 10,800 free Call of Duty Points in exchange for an email address and password rather than a legitimate redemption code. A message on the page tells visitors their reward will be “confirmed” within four to eight hours, buying time for the scammers. A fake Call of Duty Mobile site (Source: Malwarebytes) “There are warning signs, though,” the researchers noted. The page reads “GET FREE POINT” instead of “GET FREE POINTS,” the instructions are worded awkwardly, and it includes a live chat widget that appears to exist only to make the site look more legitimate. The redirect that follows relies on a technique known as a real-time credential relay. Rather than storing stolen usernames and passwords to use later, the phishing site forwards them directly to Activision’s real login page the moment they’re entered. That can trigger a genuine 2FA code, and it’s this code the second page is designed to capture before it expires. “The victim ends up handing over everything needed to access their real account: their password and the one-time code that’s supposed to keep attackers out,” the researchers added. What to do if you entered your details Security researchers recommend the following steps for anyone who submitted credentials on the fake page: Change the Activision password immediately. If a 2FA code was entered, treat the account as compromised, review recent account activity, and sign out of all active sessions. Check linked payment methods for unauthorized charges. The safest way to claim any in-game promotion is to go directly to the source by opening the official app or typing the publisher’s website address into a browser, rather than following links in messages, social media posts, or ads.
helpnetsecurity.comJul 28, 2026extracted
Call of Duty Mobile scam uses fake free points to steal player accounts
Call of Duty Mobile players should watch out for a phishing campaign disguised as a free Call of Duty Points giveaway. Victims are asked to log in with their email address and password to claim free Call of Duty Points (CP), the game’s premium currency. They’re then redirected to a second page asking for their two-factor authentication (2FA) code. The site has no connection to Activision. Its only purpose is to steal the login details needed to take over accounts. Why Call of Duty Mobile accounts are worth stealing Call of Duty Mobile has been downloaded an estimated 489 million times worldwide and has generated around $1.8 billion in lifetime in-app purchases. An Activision account can be valuable for more than just the in-game currency it contains. Many players link their Activision account to Xbox, PlayStation, or Battle.net, meaning a stolen login could expose: Stored payment methods Purchase history Other linked gaming accounts How the scam works The first page mimics the official Call of Duty Mobile site and offers 10,800 free points in exchange for an email address and password—not a redemption code, but a full account login. It also claims the reward will be “confirmed” within four to eight hours, buying time before anyone notices nothing has arrived. There are warning signs, though. The page says “GET FREE POINT” instead of “GET FREE POINTS,” contains awkwardly worded instructions, and includes a live chat widget that appears to exist solely to make the site look more legitimate. The redirect follows a common phishing technique known as a real-time credential relay. Instead of storing stolen usernames and passwords for later, the phishing site immediately submits them to the real Activision login page. That can trigger a genuine two-factor authentication (2FA) code, which the second page is designed to capture before it expires. The victim ends up handing over everything needed to access their real account: their password and the one-time code that’s supposed to keep attackers out. How to avoid this scam Check the address bar. Legitimate promotions don’t ask you to sign in through an unfamiliar website. Don’t let countdown timers rush you. They’re designed to make you act before you think. If you’re unsure whether a promotion is genuine, open the official Call of Duty Mobile app or visit Activision’s website yourself instead of following a link. Use tools that spot scams for you. Malwarebytes Scam Guard can help you check suspicious links, while Malwarebytes Browser Guard blocks many phishing sites before they load. If you play on your phone, Malwarebytes Mobile Security adds another layer of protection by helping block phishing sites and other mobile threats. If you already entered your details Change your Activision password immediately. If you entered a 2FA code, assume someone may have accessed your account. Check your account activity and sign out of all devices. Review any linked payment methods for unauthorized purchases. The simplest way to avoid phishing attacks like this is to reach websites yourself by typing the address into your browser or using the official app, rather than following links from messages, social media posts, or ads. Scammers know more about you than you think. Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in.
malwarebytes.comJul 24, 2026extracted