Share
FORENSICS / GAMING ACCOUNT THEFT

The free COD Points page that captures your 2FA code while you wait

A link promises 10,800 free Call of Duty Points. The page looks close enough. You type your Activision email and password, press the button, and a few seconds later a genuine two-factor code from Activision lands in your inbox. That arrival is the moment most people relax, because a real code means a real login, and a real login means a real site. It means neither. It means the page you are looking at just used your password on the actual Activision login server, on your behalf, and is now waiting for you to hand over the one thing standing between a stranger and your account.

SafeBrowz Threat Research

The code that arrives is real. The page asking for it is not.

There is no 10,800 free COD Points giveaway. Malwarebytes Threat Intelligence documented the page on July 24, 2026: it asks for your Activision email address and password rather than a redemption code, promises the reward will be confirmed in four to eight hours, runs a decorative live-chat widget, and its submit button reads GET FREE POINT instead of GET FREE POINTS. What separates it from an ordinary fake login is timing. The site relays your credentials to the genuine Activision login server the instant you submit them, which makes Activision send a real two-factor code to your own inbox, and a second phishing screen then collects that code before it expires. This is why the usual reassurance fails. Players are taught that a code arriving on their own device proves the login is legitimate, and here the code genuinely is legitimate. It was simply requested by someone else using your password. The honest scope of any defense follows from that: once you type the code into the attacker's screen, the session is theirs and no scanner can pull it back. The block has to happen at the link, before the form ever loads.

Not sure about a link? SafeBrowz checks it before the page can load. Add to Chrome, free Get the free Android app or scan a URL now →

Where the page comes from

Nobody searches for this page. It arrives. Malwarebytes does not document how this particular campaign was distributed, but pages in this family reach players the same handful of ways: a comment under a gameplay clip, a reply in a Discord server, a short video whose entire pitch is a URL on screen. The delivery is disposable by design, because a page like this only has to survive one brief visit.

Malwarebytes published its analysis on July 24, 2026, and its central advice is the whole defense in one sentence: reach websites yourself by typing the address or opening the official app, rather than following a link from a message, a social post or an ad. One note before we walk the page. Malwarebytes did not publish the campaign's domains, so we are not naming any. The red examples below are illustrative patterns showing the shape these sites take, not addresses we attribute to this campaign.

Screen one: the offer, and the word that gives it away

The first page is a passable imitation of official Call of Duty Mobile promotional art: logos in the right places, the right dark palette, a headline offering 10,800 CP. That figure is not random. Points are bought in bundles, and a grant that size represents a serious amount of real money, which is exactly the arithmetic the lure depends on. A small giveaway invites scrutiny because it is not worth the trouble. A large one invites hurry.

Around the offer sits a familiar furniture set:

  • A countdown timer. The number falls while you read. It relates to nothing, and exists to shorten the window in which you might think.
  • A live-chat widget. Malwarebytes describes it as existing solely to make the site look more legitimate. A trust prop, not a support channel.
  • A promise of delay. The reward will be confirmed in four to eight hours. That line buys a window in which you will not be suspicious about the points not arriving, and by the time you are, the account has already moved.
  • A submit button reading GET FREE POINT. Singular. In an official promotion that button goes through brand review, localisation and QA. Here nobody checked, because nobody had to.

Malwarebytes also notes awkward phrasing across the page. That tell survives even when the visual design is good, and it generalises well beyond Call of Duty: attackers can clone artwork perfectly, because artwork can be copied. They cannot clone a copywriting and QA process. The same principle runs through our guide on how to tell if a website is a scam.

Illustrative of the shape these hosts take, without attribution to this campaign: codm-freecp-rewards[.]top, cod-points-claim[.]xyz, codmobile-giveaway[.]online. Cheap top-level domains, the brand or its abbreviation stitched to a reward word, registered days before use and abandoned days after. The genuine properties are callofduty.com and activision.com, with account support at support.activision.com and the real sign-in flow at profile.activision.com.

The field that should have ended it: a password for a giveaway

Here is the structural giveaway, and it is bigger than any typo. The form asks for an email address and a password. Not a redemption code. Not a player ID. A password.

Think about what a legitimate reward actually requires. To grant you in-game currency, a publisher needs to know which account to credit, and that is all. That is why real promotions run on redemption codes you enter inside the game, on an in-app event, or on a signed-in session on the publisher's own site. In none of those flows does a third-party page need your password, because your password is not an identifier. It is an authenticator. There is exactly one reason a promo page wants it, and it is not to give you anything.

This is the same architectural lie underneath every free-currency scam in gaming, whatever the brand on top. It runs the fake Robux generators we broke down in the Roblox account hijack guide, it runs the gift-link bait in the Discord Nitro free scam, and it runs the inventory-theft pitches in the Steam trade hijack scam. Different currencies, different logos, one identical demand: prove you own the account by handing over the thing that proves you own the account.

The two seconds after you press the button

Most phishing pages are dumb collectors. They write your credentials to a file, show a spinner, and redirect you somewhere harmless. The attacker reads the file later, by which time you may have changed the password, or the code they need has expired.

This page does not wait. Malwarebytes describes the second stage plainly: the phishing site immediately submits the credentials to the real Activision login page. Not later, not in a batch. Now, while you are still watching the spinner.

So there are two logins happening. Yours, into a page that is not Activision, and the attacker's, into the page that genuinely is, using the password you typed a moment ago. Activision's server sees an ordinary login attempt with correct credentials and issues a two-factor challenge. That challenge goes to you, because the account is yours. A real code arrives from the real system, for a login you did in fact start. Every element is authentic except the person who will use it.

The technique has a name: adversary in the middle. The phishing page sits between you and the real service, passing traffic both ways so every response the victim sees is genuine, just relayed. Our explainer on the AiTM attack and how it steals a 2FA code covers the internals. What matters here is the consequence: two-factor authentication was built to defeat an attacker who has your password and nothing else, and relay defeats it not by breaking the code but by making you the one who fetches it.

Screen two: the code, and the code-expiry clock

The second page appears the instant the relay triggers the challenge. It asks for the verification code sent to your device, and Malwarebytes is specific about its purpose: it is designed to capture that one-time code before it expires.

Expiry is why the whole thing has to run live. A one-time code is valid for only a few minutes, so harvesting it into a text file to read tomorrow is worthless. The attacker instead compresses the operation into the natural rhythm of a login you already believe you are performing. You type the code because you were expecting a code. A page like this typically accepts the code, shows some confirmation, repeats the four-to-eight-hour promise, and lets you leave feeling like nothing went wrong.

Notice how different this is from an attack players have been warned about. In MFA fatigue, you are bombarded with approval prompts you did not ask for, and the right response is obvious: deny them all. Here there is one prompt, at the exact moment you expected one, in response to something you did. There is no anomaly to notice. The anomaly is the page itself, and it was visible before any of this started.

By the end of that screen the attacker has your email address, your password and a completed authenticated session. Malwarebytes puts it bluntly: the victim ends up handing over everything needed to access their real account, the password and the one-time code that was supposed to keep attackers out.

Catch the fake CP page before the login form loads

Add the browser extension, or the SafeBrowz Android app, and every link you open gets checked automatically before the page can render its form. A throwaway domain wearing a game publisher's branding and asking for an account password is the pattern our engine is built to flag, and it flags it at the moment you arrive, which on this attack is the only moment that helps. Free forever, with an optional Premium AI deep scan at $14.99 per year.

Chrome Add to Chrome Firefox Add to Firefox Edge Add to Edge Google Play Get it on Google Play

See pricing and Premium features

What the four-to-eight-hour promise is actually buying

The delay promise has the most under-appreciated job on the page. A stolen gaming account is worth something only until the owner notices. Promising a wait explains in advance why nothing will happen after you submit, so you do not go looking, and it resets your expectation of normal to several hours. That is a generous head start.

Malwarebytes does not detail what the operators do with the accounts afterwards, and we are not going to invent specifics. What is well established across gaming account theft generally is the shape of the first few minutes: change the recovery email so the real owner cannot reset, change the password, then pivot to whatever else the account touches. That last part is why this matters more than a game. A publisher account can carry a payment method, a purchase history, linked platform identities and a friends list that trusts a message from you.

For scale, the FBI's Internet Crime Complaint Center recorded 859,532 complaints in its 2024 Internet Crime Report, with phishing and spoofing the most-reported crime type at 193,407 complaints. Gaming audiences get targeted because free-currency lures are the easiest pitch anyone has ever had to write.

The 30-second check before you type into any rewards page

Not a checklist to memorise. Four questions, in order, and the first failure ends it.

One: how did I get here? If the answer is a comment, a DM, a short video or an ad, you are already in the risk category, because publishers do not run giveaways through strangers' links. Close the tab and go to the game or to callofduty.com yourself. If the promotion is real it will be there.

Two: what is it asking me for? A code to enter in-game is normal. A signed-in session on the publisher's own domain is normal. An email and password typed into a promotional page is not, ever, under any framing. This one question kills the entire free-currency scam family.

Three: what does the address bar actually say? Read it right to left, from the last dot before the first slash. That is the real owner of the page. Brand words to the left of it are just text an attacker chose, and codm-freecp-rewards[.]top belongs to whoever registered the .top, not to Activision.

Four: is something rushing me? A countdown on a giveaway is not scarcity, it is a technique. Real promotions have end dates, not ticking clocks that reset when you reload.

Fail any one of the four and there is nothing further to weigh up, because the rest of the page was built to make you weigh it up.

If you already entered your login and the code

Assume the account is compromised right now and work in this order. Speed is everything, because the attacker's first move is to lock you out of your own recovery.

Change your Activision password immediately, from a device you trust, by typing activision.com or profile.activision.com into the address bar. Do not follow any link, including one in an email claiming to be about this. If the password has already been changed, go straight to support.activision.com and start account recovery.

Sign out of all active sessions if the option exists. People skip this step, and against a relay attack it is the one that matters most, because what the attacker took was a live session. A new password does not necessarily evict a session that is already open.

Check and reset two-factor authentication. Activision supports an authenticator app and SMS, and the authenticator option issues ten backup codes, per Activision's own two-factor authentication support article. Confirm the registered number and authenticator are still yours and nothing was quietly added.

Check the recovery email and linked accounts. Verify the email on the account is still yours, then review the platform identities and payment methods attached to it and remove anything you do not recognise.

Change the password anywhere else you reused it, starting with your email account, which is the master key to everything else.

If money moved, our walkthrough on what to do after getting scammed covers the reporting order for cards, banks and platform disputes. In the US, report to the FTC at reportfraud.ftc.gov and the FBI at ic3.gov.

How SafeBrowz reads a relay page before you type

SafeBrowz runs a 3-layer detection architecture: Local + APIs + AI. A real-time credential-relay page shows why the layers are arranged the way they are, because this attack gives you no useful signal after the first click.

  • Layer 1 - Local detection: 60+ URL pattern signatures and a 550+ brand database with homograph and Punycode checks, running inside the extension before the page renders. What this layer catches on a page like this is the shape of the address itself: a reward word on a throwaway top-level domain, scored with no network round trip. It is deliberately narrow, and it fires on the brands it actually tracks, so a game publisher outside that list is left to the layers below rather than guessed at.
  • Layer 2 - API checks: aggregates Google Safe Browsing, PhishTank, URLhaus and ScamAdviser feeds plus 30+ scam-TLD lists alongside our own blocklist. Giveaway-phishing domains get reported quickly once a campaign has volume, so an already-known host is settled on reputation before you interact.
  • Layer 3 - AI deep scan (Premium): the layer covering the domain registered this morning that no feed has seen. Our infrastructure analyses what the page presents, in 100+ languages: publisher branding and an in-game currency offer paired with a password field, a countdown and a chat widget, on a host with no relationship to the brand it is wearing. That reads as impersonation on content rather than reputation, which is what catches a same-day domain.

Honest scope, and it is unusually stark here. Everything above happens at the link. Once you type the code into the attacker's screen the session exists, it is theirs, and no extension or blocklist can reach into Activision's servers and revoke it. On a relay page there is no safe later moment, because the one signal people rely on, the genuine code arriving on their own phone, is manufactured by the attack itself.

Detection signatures are derived from threat-intelligence research and our internal brand database, not from user browsing data. SafeBrowz does not store per-user browsing history.

🛡 LIVE CHECK

Sent a free points or rewards link? Check it here first

Paste any giveaway, rewards or login link before you type anything into it. Our 3-layer engine (Local + APIs + AI) returns a verdict in about 3 seconds. Free, no signup.

Full scan with deep AI analysis → · No URL is logged to your identity.

Frequently asked questions

Is the 10,800 free COD Points offer real?

No. Malwarebytes Threat Intelligence documented it on July 24, 2026 as a phishing page built to steal Activision accounts. It asks for your email and password instead of a redemption code, the submit button reads GET FREE POINT rather than GET FREE POINTS, the phrasing is awkward, and it runs a decorative live-chat widget and a promise of confirmation in four to eight hours. Real Call of Duty promotions never need your password on a third-party page.

How did a scam site make a real 2FA code arrive for me?

Because it logged in as you, in real time. The moment you submit your email and password, the phishing site passes them to the genuine Activision login server. Activision sees a valid login attempt and sends a two-factor code to the address registered on the account. The code is real, it was just requested by an attacker using your password, and a second phishing screen then asks you to type it in so it can be used before it expires. Our AiTM 2FA bypass explainer covers the mechanism.

I entered my Activision email, password and 2FA code. What should I do right now?

Treat the account as compromised immediately. From a device you trust, type activision.com or profile.activision.com into the address bar and change your password. Sign out of all active sessions if the option exists, because the attacker holds a live session a password change alone may not end. Confirm your two-factor settings, registered phone number and recovery email are still yours, review linked accounts and payment methods, and change that password anywhere else you reused it. If you are locked out, start recovery at support.activision.com.

How do real Call of Duty rewards actually work?

Through the game or Activision's own properties. Real rewards come as redemption codes you enter inside Call of Duty Mobile, as in-game events and battle pass progression, or as offers surfaced when you are already signed in on an official Activision site. None need a password typed into a promotional page, because a password is not how a publisher identifies which account to credit. Verify any promotion by opening the game or going to callofduty.com yourself.

Can a URL scanner stop a real-time credential relay page?

At the link, yes, and that is the only place it can. A browser-layer scanner like SafeBrowz checks the page when you arrive, before the form renders, and a throwaway domain wearing a publisher's branding while asking for an account password is a brand-impersonation pattern our 3-layer engine flags on structure and content rather than reputation alone, which is what catches a same-day domain. What it cannot do is help afterwards: once the code is typed in, an authenticated session exists on Activision's side and no extension can revoke it.

Related reading

Bottom line: this campaign works by turning your best security habit against you. You were taught that a code arriving on your own device means the login is genuine, so the attacker arranges a genuine login and lets Activision send you a genuine code. Everything after the first click is authentic except the person on the other end, which leaves nothing to spot once you are on the page. Two reflexes cover it: no promotional page ever needs your password, and reach Call of Duty by opening the game or typing callofduty.com yourself. Keep SafeBrowz in your browser or on your phone so a relay page is flagged before the form loads, and paste anything you are unsure about into the free scam checker first.