RKG Logo 434-978-4300

Heads up!

Several of our clients have reported receiving this phishing email today:

From: Google Adwords-noreply [mailto:adwords-noreply@google.com]
Sent: Saturday, March 22, 2008 9:40 AM
To: XXXXXXXXXXXX
Subject: [Released by Allow List] Please Update Your Billing Information
————————
Dear Google AdWords Customer!

In order to update your billing information, please sign in to your AdWords account at https://adwords.google.com , and update your billing information. Your account will be reactivated as soon as you have entered your payment details. Your ads will show immediately if you decide to pay for clicks via credit or debit card. If you decide to pay by direct debit, we may need to receive your signed debit authorization before your ads start running, depending on our location. If you choose bank transfer, your ads will show as soon as we receive your first payment. (Payment options vary by location.)

Thank you for choosing AdWords. We look forward to providing you with the most effective advertising available.

Sincerely,

The Google AdWords Team
————————
This message was sent from a notification-only email address that does not accept incoming email. Please do not reply to this message. If you have any questions after following the steps above, please visit the Google AdWords Help Center at https://adwords.google.com/support/bin/topic.py?topic=8336>
————————

The actual destination login URL hidden under the display URL: http://adwords.google.com.fr4ck.cn/select/Login

Clearly, this isn’t from Google.

It is phishing attack designed to steal your billing information. Beware!

Here’s Google’s response to our team asking about this:

From: XXXXX [mailto:XXXXXXXXX@google.com]
Sent: Monday, March 24, 2008 3:16 PM
To: XXXXXXXXXXXXX
Subject: Re: [#255928689] [Released by Allow List] Please Update Your Billing Information

Hi XXXXXXXX,

This appears to be a ’spoofing’ email sent to some AdWords advertisers recently. ‘Spoofing’ refers to the act of fraudulently altering certain properties of an email to make it appear as though it originated from a legitimate source. The email can then lead to a deceptive website which collects sensitive personal information. In this case, the email may have appeared to be from Google AdWords, asking for your account login information. Please do not respond to these emails.

Google is not responsible for nor are we able to monitor the actions of other parties. However, we are very committed to ensuring the safety and security of our users and our advertisers, and we take issues of fraud seriously. Moreover, we’ve dedicated a number of resources towards preventative measures, such as the Google Safe Browsing extension for Firefox. You can find more information about this feature at http://www.google.com/tools/firefox/safebrowsing/.

Here are some steps you can take to ensure the security of your account:

* Be wary of unsolicited messages. Google will never send unsolicited messages asking for your password or other sensitive information. If you need to change your account information, such as your billing details or your password, always sign into your AdWords account from https://adwords.google.com and make the changes directly within your account.

* Check the message headers. The ‘From:’ address and the ‘Return-path’ should reference the same source.

* Make sure the URL is legitimate. The AdWords homepage URL will always be https://adwords.google.com.

* Change your Google Account password frequently. To learn how, visit https://adwords.google.com/support/bin/answer.py?answer=24828.

* Report suspicious messages to adwords-charge@google.com.

* Keep your computer’s antivirus and spyware protections up to date and regularly run system scans.

If you believe your Google AdWords account may have been compromised, please let us know so that we can initiate an investigation.

Best,

XXXXXXXXXX

——————
XXXXXX
Account Associate
National Agency Team

phishing

If you like this post, consider subscribing to our RSS feed. You can also have new posts sent to you via email.


Related Posts

Comments

  1. Karman, March 25, 2008:

    I guess google should take some actions not only to warn the adwords users but also to stop the fishing site. Even though it is in China, there should be some means to stop this

  2. Rob, March 25, 2008:

    I’ve been getting this phishing email up to 3 times a day for the last week or so and I’m not even a Google Adwords customer. I don’t have a commercial website so they (whoever they are) are casting their net wider.

  3. Alex, March 29, 2008:

    We received this email internally two days ago. We have http://www.opendns.com installed on our network which had already identified the fr4ck . cn as a phishing website. If you don’t have this in place now, look into it!

Your Comment

Tags

RKG Tags: ,

Technorati Tags: ,

Trackback

http://www.rimmkaufman.com/rkgblog/2008/03/24/beware-adwords-phishing-email/trackback/

Email Updates

Categories

Recent Comments

  • Nancy Kast: I am writing about your billing and online services. I have been receiving calls saying my bill is not paid. My husband pays all our...
  • Marc Adelman: George, Thanks for sharing this data. From an online buzz perspective, Bing is making a big splash. Everyone is talking about it....
  • George Michie: Hi Dennis, I’m not a lawyer, so take anything I say on this with a grain of salt (and please don’t sue us if we’re...
  • survey online: unfortunatelly i have to say that Google tools are the easiest survey web
  • Dennis Yu: Alan, We’ve had several C&D’s sent to us for seemingly innocuous issues. One of our casual dining clients bid on a...
  • George Michie: Hi Vivek, Haven’t had time to put together a full update, but I did take a look at the numbers. No material gains in market...
  • Karridy: You should checkout ClickPath’s call to KW tracking.
  • Vivek: George, really enjoying reading about the analysis you guys do. Was wondering if you have an update on this given a couple more weeks have...
  • Vicki Swaim: Dear Mr.Ullman, I hope you can help me with my problem. I ordered a TV stand the end of April that was advertised as a close out item....
  • Luke: It’s a shame we live in such a litigious society. Why should we have to set up an association? Surely we can prevent senseless...
  • George Michie: Josh, we have had shots fired over our bow and our client’s in the past. Usually responsible companies are reasonable about...
  • Ryan: Ok, George, I’m sufficiently scared… Thanks… :-) Incidentally, are there any trademark resources (other than Google...
  • Josh: We have run into trademark issues for several clients, although it has so far been a matter of trying to make “fair use” of a...
  • Mike: THANK YOU! I love you man!! :)
  • Matthew: Francis, We’ve likewise seen the “A-List” phenomenon in the past. Perhaps with Bing.com, there won’t be anymore of...

Blog Stats

  • Posts: 871
  • Words: 392,916
  • Comments: 2,079

Administration