{"id":1198,"date":"2010-04-27T17:31:16","date_gmt":"2010-04-27T16:31:16","guid":{"rendered":"http:\/\/www.colinmcnulty.com\/blog\/?p=1198"},"modified":"2010-04-27T17:31:16","modified_gmt":"2010-04-27T16:31:16","slug":"beware-this-new-phishing-email","status":"publish","type":"post","link":"https:\/\/www.colinmcnulty.com\/blog\/2010\/04\/27\/beware-this-new-phishing-email\/","title":{"rendered":"Beware This New Phishing Email"},"content":{"rendered":"<p>I received 4 copies of this phishing email today:<\/p>\n<table border=\"1\" cellpadding=\"0\" width=\"450\">\n<tbody>\n<tr>\n<td>Hello,<\/p>\n<p>Your Google Adwords Account has stopped   running this morning.<\/p>\n<table border=\"0\" cellspacing=\"0\" cellpadding=\"0\" width=\"400\">\n<tbody>\n<tr style=\"text-align: center;\">\n<td width=\"22\"><strong> <\/strong><\/td>\n<td width=\"851\"><strong>Some of the ads have stopped     running today (Tuesday, 27 April 2010).<\/strong><\/p>\n<p><strong>If you want to get your ad back up     and running you need to optimize the campaign to improve the CTR. The link     below has some helpful tips, but, in a nutshell, you need to look at your     keywords and your ad text. Make sure your keywords are jighly relevant and     then make sure that each keyword in the ad group makes sense in terms of     the ad text associated with this ad group (usually this means you need to     create more ad groups with a smaller number of keywords). Having a tight     connection between keywords and ad text helps improve CTR, which should fix     your problem.<\/strong><\/td>\n<td width=\"10\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong><span style=\"color: #0000ff;\"><span style=\"text-decoration: underline;\">Click here to get your ads back up.<\/span><\/span><\/strong><\/p>\n<p><strong>Please   note: <\/strong>if you do not <strong><span style=\"color: #0000ff;\"><span style=\"text-decoration: underline;\">verify<\/span><\/span><\/strong> the   status of your account and notify us if your ads do not appear online, we   cannot help you.<\/p>\n<p>\u00a9 2010 Google   Inc. 1600 Amphitheatre Parkway, Mountain View, CA 94043<\/p>\n<p>Email   Preferences:\u00a0We sent you this email because you have indicated that you   are willing to receive AdWords account performance suggestions. If you do not   wish to receive emails of this nature in the future, please visit your   account&#8217;s\u00a0<a href=\"https:\/\/adwords.google.com\/select\/editcommunicationspreferences\" target=\"_blank\">Communications Preferences<\/a> page (AdWords login   required). Click on the word &#8216;Yes&#8217; beside &#8216;Customized help and performance   suggestions,&#8217; and change to &#8216;No&#8217;.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>If you don&#8217;t know, a &#8220;phishing&#8221; (pronounced &#8220;fishing&#8221;) website, is a fake website that tries to pass itself off as a real website in order to get you to enter your login credentials, which <strong>they then steal your login<\/strong> and use on the legitimate website.  So this phishing email, is trying to get me to go to the phishing website and enter my Google AdWords account details.  Typically scammers try it with bank accounts, but this is the first time I&#8217;ve seen it for Google AdWords.<\/p>\n<p>Why AdWords?  Because if they get your adwords account (if you have one) they can put their own ads up and <strong>spend your advertising budget for their own websites!<\/strong>  Now it&#8217;s no surprise that having been to the website (note I&#8217;ve disabled the phishing links to it in the email copy above, except for the real link at the bottom), it looks completely legitimate, just like the normal Google login page.<\/p>\n<p><strong>How do I know it&#8217;s a phishing email \/ website then?<\/strong> There are several give aways, but the main one is the url; it&#8217;s not the regular google.com one.  Also, you can tell the url without even clicking the link, just by hovering your mouse over the link in your email program, you get a popup that shows you the url:<\/p>\n<a href=\"http:\/\/www.colinmcnulty.com\/blog\/wp-content\/uploads\/2010\/04\/phishing.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/www.colinmcnulty.com\/blog\/wp-content\/uploads\/2010\/04\/phishing.png\" alt=\"\" title=\"phishing\" width=\"455\" height=\"332\" class=\"aligncenter size-full wp-image-1200\" srcset=\"https:\/\/www.colinmcnulty.com\/blog\/wp-content\/uploads\/2010\/04\/phishing.png 455w, https:\/\/www.colinmcnulty.com\/blog\/wp-content\/uploads\/2010\/04\/phishing-300x218.png 300w\" sizes=\"auto, (max-width: 455px) 100vw, 455px\" \/><\/a>\n<p>You see that &#8220;google-sn.com&#8221; is not google.com.  That extra <strong>&#8220;-sn&#8221;<\/strong> shouldn&#8217;t be there.  This is subtle I know, but if you want to protect yourself online, you need to do one simple thing: <strong>pay attention to the urls<\/strong>, that is the actual domains \/ website names that you visit when you have an account that has anything to do with money.  This alone tells me this if a phishing attack.  But there are several other tells, to use a poker term, that you can look for to <strong>see if you&#8217;ve got a phishing email<\/strong>.  They were:<\/p>\n<p>&#8211; I received 4 copies of the same email, I would expect a legitimate email from Google to have sent only one.<\/p>\n<p>&#8211; There was no email address in the <strong>&#8220;To:&#8221;<\/strong> field of the email, I would have expected to see not only my own personal email address here, but also specifically the email address I use for my Google AdWords account (I have several hundred email addresses!).<\/p>\n<p>&#8211; There was a broken image in the email, meaning that it had a blank square with a red X in.  It probably was meant to be the Google logo.  I wouldn&#8217;t have expected a real email to be properly constructed.<\/p>\n<p>&#8211; The email started &#8220;Hello,&#8221; and didn&#8217;t address me by name.  Google know my name and use it in their emails.  Further, there were no personally identifying bits of information in the email, it was completely generic.<\/p>\n<p>&#8211; Finally, whilst I have an AdWords account, I&#8217;m not currently running any ads, so there are none to disable!<\/p>\n<p>Anyway, I hope that helps someone avoid getting ripped off!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I received 4 copies of this phishing email today: Hello, Your Google Adwords Account has stopped running this morning. Some of the ads have stopped running today (Tuesday, 27 April 2010). If you want to get your ad back up and running you need to optimize the campaign to improve the CTR. The link below [&hellip;]<\/p>\n","protected":false},"author":161,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[210,209,211],"class_list":{"0":"post-1198","1":"post","2":"type-post","3":"status-publish","4":"format-standard","6":"category-uncategorized","7":"tag-adwords","8":"tag-google","9":"tag-phishing"},"_links":{"self":[{"href":"https:\/\/www.colinmcnulty.com\/blog\/wp-json\/wp\/v2\/posts\/1198","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.colinmcnulty.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.colinmcnulty.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.colinmcnulty.com\/blog\/wp-json\/wp\/v2\/users\/161"}],"replies":[{"embeddable":true,"href":"https:\/\/www.colinmcnulty.com\/blog\/wp-json\/wp\/v2\/comments?post=1198"}],"version-history":[{"count":0,"href":"https:\/\/www.colinmcnulty.com\/blog\/wp-json\/wp\/v2\/posts\/1198\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.colinmcnulty.com\/blog\/wp-json\/wp\/v2\/media?parent=1198"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.colinmcnulty.com\/blog\/wp-json\/wp\/v2\/categories?post=1198"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.colinmcnulty.com\/blog\/wp-json\/wp\/v2\/tags?post=1198"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}