AdWords
1.9K members online now
1.9K members online now
Understand Google's advertising policies, including ad approval status and account suspension
Guide Me
star_border
Reply

Hacked account - Another phishing Ad for AdWords logins

Collaborator ✭ ✭ ✭
# 1
Collaborator ✭ ✭ ✭

Hello,

 

Please look at the ad below found by typing "adwords en forum" (my favourite phrase to find the forum URL) from location Bucharest, Romania. This is the click ID string which I know you need to catch and stop these hackers :

 

http://www.google.ro/aclk?sa=l&ai=CzJNk37ZYVaKzJ8Lm7QaenoDICcLy4akGitSgx5UC7JqoCAgAEAEoAmCDpeGF6BugA...

 

The Ad destination URL from the string is adurl=http://brasilsrser.ddns.net/adwords&cad=rja , which does not match to the Display URL so I wonder how the hell did it get approved ? Do they have someone inside Google ?

 

another-hacked-advertiser.png

 

Notice the Display URL www.google.com.br and the message

 

1) "Comece ganhando novos clientes hoje Inscreva-se no Adwords" (which translates into "Start winning new clients by signing-up to AdWords" ) and then

2) the second Ad line "Compare preços e produtos · Economize até 40%" ( which translates into "buy at discount price - save 40%)  and some sitelinks about TV sets.

 

This ad text is absurd and the real destination URL is this one

 

http://brasilsrser.ddns.net/adwords/?gclid=CKiN3O6PycUCFYrKtAodWFQArg

 

The page is a phising page for AdWords logins , here is how it looks , asking me to login into AdWords :

 

adwords-phishing-ad.png

 

 

I think the sitelinks are original to the advertiser because when I click on them, they lead me to this domain, which I believe is the hacked advertiser account .

 

http://www.buscape.com.br

 

The sitelinks URLs are :

 

http://www.buscape.com.br/proc_unico?id=2852&xrc114=201658&xro=107,114,109&xrc107=1593&xrc109=1595&o...

 

http://www.buscape.com.br/tv.html?obn=1&gclid=COiG77iRycUCFWuWtAodSQoA8w

 

http://www.buscape.com.br/proc_unico?id=2852&xro=107&xrc107=1268&obn=1&kw=tv+3d+cinema&gclid=CKrrkrm...

 

1 Expert replyverified_user
1 ACCEPTED SOLUTION

Accepted Solutions
Marked as Best Answer.
Solution
Accepted by topic author Adrian B
September 2015

Re: Hacked account - Another phishing Ad for AdWords logins

[ Edited ]
Top Contributor
# 4
Top Contributor

Well... This seems to be a worldwide (not that sophisticated, though...) since I also  get to see the  this ad.
I escalated the case to the enforcement team at Google, asking to investigate how this could have happened.

 

Moshe, AdWords Top Contributor , Twitter | Linkedin | Community Profile | Ad-Globe
Did you find any helpful responses or answers to your query? If yes, please mark it as the ‘Best Answer’

View solution in original post

Re: Hacked account - Another phishing Ad for AdWords logins

Participant ✭ ☆ ☆
# 2
Participant ✭ ☆ ☆
Hi Adrain,

I have also seen this yesterday, while I am looking for Adwords forum. I thought it is an ad by Google . But, as you said it is redirecting to the URL you mentioned above.

Re: Hacked account - Another phishing Ad for AdWords logins

[ Edited ]
Collaborator ✭ ✭ ✭
# 3
Collaborator ✭ ✭ ✭

Thank you, I am glad I am not the only one seeing this issue.

 

The strange think is how did they manage to save the Ad with that display URL which does not match the destination/final URL . Having different domains in the two URL fields should stop from saving the ad in the first place. They must have found a software bug somehow.

Marked as Best Answer.
Solution
Accepted by topic author Adrian B
September 2015

Re: Hacked account - Another phishing Ad for AdWords logins

[ Edited ]
Top Contributor
# 4
Top Contributor

Well... This seems to be a worldwide (not that sophisticated, though...) since I also  get to see the  this ad.
I escalated the case to the enforcement team at Google, asking to investigate how this could have happened.

 

Moshe, AdWords Top Contributor , Twitter | Linkedin | Community Profile | Ad-Globe
Did you find any helpful responses or answers to your query? If yes, please mark it as the ‘Best Answer’

Re: Hacked account - Another phishing Ad for AdWords logins

Collaborator ✭ ✭ ✭
# 5
Collaborator ✭ ✭ ✭
The Ad text is not in Romanian language but in Brasilian language (portughese) like the TLD in the Display URL .com.br . It is made to fool a Portughese speaking audience which is around 200 milion people only in Brasil.

Re: Hacked account - Another phishing Ad for AdWords logins

Top Contributor
# 6
Top Contributor

OOhh.. Ok. Corrected. The case is still open with Google.

Moshe, AdWords Top Contributor , Twitter | Linkedin | Community Profile | Ad-Globe
Did you find any helpful responses or answers to your query? If yes, please mark it as the ‘Best Answer’

Re: Hacked account - Another phishing Ad for AdWords logins

Collaborator ✭ ✭ ✭
# 7
Collaborator ✭ ✭ ✭

I think Google managed to stop this Ad, I cannot see it anymore. Thank you Moshe.

Re: Hacked account - Another phishing Ad for AdWords logins

[ Edited ]
Top Contributor
# 8
Top Contributor

Great! Thanks for reporting the case @Adrian B

Moshe, AdWords Top Contributor , Twitter | Linkedin | Community Profile | Ad-Globe
Did you find any helpful responses or answers to your query? If yes, please mark it as the ‘Best Answer’

Re: Hacked account - Another phishing Ad for AdWords logins

Visitor ✭ ✭ ✭
# 9
Visitor ✭ ✭ ✭
My client is a victim of a hacked account and found several ads like this in his account. Plus two manual payments were added that he didn't make (presumably to cover their activity) and the daily spend went up. The ads were removed but account was then suspended and we have not been able to get it reinstated despite Adwords specialists in Dublin and India saying it's obvious the account has been hacked. Many appeals and forms filled in but they have now said the decision is final and we must not create another account or that will be suspended too. I'm considering legal advice now. Has anyone any comment / suggestions please.