Random Bytes

All Things Internet™ since 1999

By

Adwords Phish

This one almost got me.

I received a note from Google letting me know that they’d suspended some of my ad campaigns and that I should login to rectify. Clicking through, my suspicion was raised when I wasn’t automatically logged in like I normally am. Google *always* logs me in automatically, and usually into the wrong account.

It drives me crazy.

This gave me a cause to pause and I did a deeper inspection of the page and the email I’d received.

Turns out, the email was a complete fake. A scam intended to con me into giving my Google credentials to a nefarious third party. In this case, the email sends me to google-ows.com, a name that was only registered this morning. The page includes a script that collects your adwords username and password, which can also be used to sign into my other Google services – like GMail, etc. From there, who knows what the scam is, but it sets up the bad guys some pretty good access to your life if you fall for it.

Sneaky bastards.

The contents of the email…

Screen Shot 2011-10-12 at 11.18.24 AM.png

The page I was sent to…

Screen Shot 2011-10-12 at 11.55.12 AM.png