RKG Logo 434-978-4300

Heads up!

Several of our clients have reported receiving this phishing email today:

From: Google Adwords-noreply [mailto:adwords-noreply@google.com]
Sent: Saturday, March 22, 2008 9:40 AM
To: XXXXXXXXXXXX
Subject: [Released by Allow List] Please Update Your Billing Information
————————
Dear Google AdWords Customer!

In order to update your billing information, please sign in to your AdWords account at https://adwords.google.com , and update your billing information. Your account will be reactivated as soon as you have entered your payment details. Your ads will show immediately if you decide to pay for clicks via credit or debit card. If you decide to pay by direct debit, we may need to receive your signed debit authorization before your ads start running, depending on our location. If you choose bank transfer, your ads will show as soon as we receive your first payment. (Payment options vary by location.)

Thank you for choosing AdWords. We look forward to providing you with the most effective advertising available.

Sincerely,

The Google AdWords Team
————————
This message was sent from a notification-only email address that does not accept incoming email. Please do not reply to this message. If you have any questions after following the steps above, please visit the Google AdWords Help Center at https://adwords.google.com/support/bin/topic.py?topic=8336>
————————

The actual destination login URL hidden under the display URL: http://adwords.google.com.fr4ck.cn/select/Login

Clearly, this isn’t from Google.

It is phishing attack designed to steal your billing information. Beware!

Here’s Google’s response to our team asking about this:

From: XXXXX [mailto:XXXXXXXXX@google.com]
Sent: Monday, March 24, 2008 3:16 PM
To: XXXXXXXXXXXXX
Subject: Re: [#255928689] [Released by Allow List] Please Update Your Billing Information

Hi XXXXXXXX,

This appears to be a ’spoofing’ email sent to some AdWords advertisers recently. ‘Spoofing’ refers to the act of fraudulently altering certain properties of an email to make it appear as though it originated from a legitimate source. The email can then lead to a deceptive website which collects sensitive personal information. In this case, the email may have appeared to be from Google AdWords, asking for your account login information. Please do not respond to these emails.

Google is not responsible for nor are we able to monitor the actions of other parties. However, we are very committed to ensuring the safety and security of our users and our advertisers, and we take issues of fraud seriously. Moreover, we’ve dedicated a number of resources towards preventative measures, such as the Google Safe Browsing extension for Firefox. You can find more information about this feature at http://www.google.com/tools/firefox/safebrowsing/.

Here are some steps you can take to ensure the security of your account:

* Be wary of unsolicited messages. Google will never send unsolicited messages asking for your password or other sensitive information. If you need to change your account information, such as your billing details or your password, always sign into your AdWords account from https://adwords.google.com and make the changes directly within your account.

* Check the message headers. The ‘From:’ address and the ‘Return-path’ should reference the same source.

* Make sure the URL is legitimate. The AdWords homepage URL will always be https://adwords.google.com.

* Change your Google Account password frequently. To learn how, visit https://adwords.google.com/support/bin/answer.py?answer=24828.

* Report suspicious messages to adwords-charge@google.com.

* Keep your computer’s antivirus and spyware protections up to date and regularly run system scans.

If you believe your Google AdWords account may have been compromised, please let us know so that we can initiate an investigation.

Best,

XXXXXXXXXX

——————
XXXXXX
Account Associate
National Agency Team

phishing

Technorati Tags: ,

If you like this post, consider subscribing to our RSS feed. You can also have new posts sent to you via email.


Related Posts

Comments

  1. Karman, March 25, 2008:

    I guess google should take some actions not only to warn the adwords users but also to stop the fishing site. Even though it is in China, there should be some means to stop this

  2. Rob, March 25, 2008:

    I’ve been getting this phishing email up to 3 times a day for the last week or so and I’m not even a Google Adwords customer. I don’t have a commercial website so they (whoever they are) are casting their net wider.

  3. Alex, March 29, 2008:

    We received this email internally two days ago. We have http://www.opendns.com installed on our network which had already identified the fr4ck . cn as a phishing website. If you don’t have this in place now, look into it!

Your Comment

Tags

RKG Tags: ,

Technorati Tags: ,

Trackback

http://www.rimmkaufman.com/rkgblog/2008/03/24/beware-adwords-phishing-email/trackback/

Email Updates

Categories

Recent Comments

  • Mark Ballard: Cory, I don’t see this as an SEO v. PPC issue. The core of my argument is that CTRs are lower primarily due to misleading...
  • Cory Grassell: What are your thoughts on stats that suggest consumers are more apt to click on organic search results than PPC results? As a...
  • George Michie: Kevin, Marc, thanks for your comments. Help is coming, but not the solution. There are a number of instances when the CTR on the...
  • Marc Adelman: George, You have been an advocate of “the advanced control option” for years now. Depressing right YEARS! Eh…listen...
  • Kevin Hill: Is what they really need is a fourth match type. Here’s google’s help documentation on broad match: This is the default...
  • Kevin Micalizzi, Dimdim Web Conferencing: Jim (& George)- We still offer a free version of Dimdim. Just click Sign Up Now at the top of the...
  • Tomas: indeed, i can’t talk about it either… :)
  • Philip Price: Thank you for the RegHack, it worked for me, tho at first when i made the reg file with the information i copied from above i also...
  • George Michie: Sorry Jim, this post was written in 2007. Apparently some of those products are gone.
  • Jim: Hey, I checked two products like dimdim and cutepdf but none is free. What are you talking about free and open source?
  • George Michie: If they keep hearing the same message, and seeing evidence in the data to back it up, something will have to give. There is hope on...
  • Tomas: I’ve been having the same argument with Google for months now and in the end there does seem to be a feature in the algorithm that...
  • George Michie: Doesn’t have to be, it can be intra-adgroup as well.
  • Josh: George – I take it you’re referencing a scenario where your exact-match keywords are not listed as negative exact match keywords...
  • George Michie: Melissa, you’re right, it’s always happened to varying degrees, particularly since the advent of extended broad match....

Blog Stats

  • Posts: 948
  • Words: 451,089
  • Comments: 2,877

Administration