Hackers Target US Coin Master Players in New Phishing Scam
A New Threat to Mobile Gamers
A new wave of cyberattacks is hitting American mobile gamers hard. Security researchers are sounding the alarm, warning that players of the wildly popular mobile title Coin Master are being singled out in a sophisticated new phishing campaign. The bait is simple: unlimited free spins.
As developer Moon Active prepares to launch its highly anticipated October 2026 in-game festivals, players are desperate for resources. Spins are the lifeblood of the game. They let you build virtual villages, raid rivals, and win virtual cash. But getting them usually costs real money or requires patience. That is where scammers step in.
How the Scam Works
Cyber intelligence firm CyberGuard Security released a detailed report this week exposing the operation. They tracked a massive network of fraudulent websites designed to deceive unsuspecting players. These pages look identical to official Coin Master reward hubs, complete with matching fonts, colors, and art styles.
Gamers typically find these links on social media platforms like TikTok, X, and YouTube. Sometimes they even spread through compromised Facebook groups where players share game tips. Once a user clicks, the trap springs.
The site asks for the player’s Facebook login credentials under the guise of linking their account to send the reward. Why Facebook? Because Coin Master players routinely link their social media accounts to save progress and play with friends.
“This is not just about losing game progress,” says Marcus Vance, a lead threat analyst at CyberGuard. “By stealing Facebook logins, hackers gain access to personal messages, contact lists, and linked payment methods. It is a goldmine for identity thieves.”

The Scale of the Attack
Coin Master is not a niche game. With over 100 million downloads worldwide, it consistently ranks among the top-grossing mobile games in the United States. Its user base spans all demographics, making it an incredibly lucrative target for opportunistic hackers. CyberGuard reports that the current campaign has already directed tens of thousands of US players to malicious domains over the last two weeks alone.
Many of these phishing domains use clever typosquatting techniques. They register names like “coinmaster-free-spinz.com” or “moonactive-rewards-claim.net” to appear legitimate at a quick glance. To make matters worse, some of these sites use secure HTTPS connections, which displays a padlock icon in browser address bars. This gives players a false sense of security.
The Danger of “Human Verification”
Some of the fake sites go a step further. They require a “human verification” process before releasing the promised millions of spins. This usually involves downloading a third-party app or completing a survey.
In reality, these apps are packed with adware or info-stealing malware. Some victims reported unauthorized charges on their credit cards within hours of trying to claim the fake rewards. Others had their mobile devices slowed down by malicious background scripts.
Why the Timing Matters
Timing is everything in cybersecurity. October is historically one of the busiest months for mobile gaming events. Moon Active has teased massive prize pools and limited-time events for late October 2026. Players want to stock up on spins early, and cybercriminals are exploiting this urgency.
How to Protect Your Account
Security experts urge players to be incredibly cautious. To keep your account safe, keep these rules in mind:
- Moon Active never asks for your password to award spins.
- Official promotions only happen through verified social channels or directly inside the app.
- Never download third-party files or apps to claim game rewards.
If you think you fell for the scam, change your Facebook password immediately. Revoke access to any suspicious third-party apps in your settings and monitor your bank statements for unusual activity.