VYPR
researchPublished Jul 24, 2026· 1 source

Call of Duty Mobile Players Targeted by Phishing Scam for Account Hijacking

A sophisticated phishing campaign is targeting Call of Duty Mobile players, luring them with promises of free in-game currency to steal their Activision account credentials and two-factor authentication codes.

Cybercriminals are actively targeting the massive player base of Call of Duty Mobile with a deceptive phishing campaign designed to hijack player accounts. The scam, detailed by Malwarebytes Labs, preys on players' desire for in-game advantages by offering a fake giveaway of 10,800 free Call of Duty Points (CP), the game's premium currency. This lure is used to trick unsuspecting users into divulging their Activision account login credentials.

The attack unfolds in two stages. Initially, victims are directed to a fake website that closely mimics the official Call of Duty Mobile interface. Here, they are prompted to enter their email address and password to claim the promised free CP. This initial step is crucial, as it harvests the primary login details. The scammers employ subtle but telling signs of a fraudulent site, such as grammatical errors like "GET FREE POINT" instead of the correct "GET FREE POINTS," and an awkwardly worded set of instructions.

Following the credential harvesting, victims are then redirected to a second page. This page is specifically designed to capture their two-factor authentication (2FA) code. This technique, known as a real-time credential relay, is particularly insidious. Instead of simply storing the stolen username and password, the phishing site immediately attempts to log into the legitimate Activision portal. This action triggers a genuine 2FA code request, which the second page then prompts the user to enter before it expires. By obtaining both the password and the 2FA code, attackers gain complete control over the player's account.

The value of a compromised Call of Duty Mobile account extends beyond just in-game currency. With an estimated 489 million downloads worldwide and over $1.8 billion in lifetime in-app purchases, the game's ecosystem is lucrative. Many players link their Activision accounts to other gaming platforms like Xbox, PlayStation, or Battle.net. A successful account takeover could therefore expose sensitive information such as stored payment methods, purchase history, and access to other linked gaming profiles, leading to further financial loss or identity theft.

To protect themselves, players are advised to exercise extreme caution. Always verify the URL in the address bar before entering credentials; legitimate promotions do not require sign-ins through unfamiliar websites. Be wary of countdown timers that create a false sense of urgency. If a promotion seems too good to be true, it likely is. Instead of clicking on suspicious links, players should navigate directly to the official Call of Duty Mobile app or Activision's website.

Users who believe they may have fallen victim to this scam should immediately change their Activision password. If a 2FA code was entered, it's critical to assume the account has been compromised. Reviewing account activity, signing out of all devices, and checking linked payment methods for unauthorized transactions are essential steps. Employing security tools like Malwarebytes Scam Guard or Browser Guard can also help block phishing sites before they load, adding an extra layer of defense against such threats.

This incident highlights a persistent trend in cybercrime: the exploitation of popular online services and gaming platforms to conduct phishing and account takeover schemes. As virtual economies grow and player engagement deepens, the personal and financial data associated with these accounts become increasingly attractive targets for threat actors. Vigilance and adherence to security best practices remain the most effective defenses for gamers worldwide.

Synthesized by Vypr AI