Sign in

Tags

Calendar

<<  September 2010  >>
MoTuWeThFrSaSu
303112345
6789101112
13141516171819
20212223242526
27282930123
45678910

Blogroll


    Anti-phishing Tips from the Google SafeBrowsing Team

    Posted on June 30, 2008 15:14 by Tom Funk    Bookmark and Share

    As a followup to our occasional posts on the Google AdWords phishing scam emails we all keep seeing, here's what you can expect to receive from Google when you forward a bogus email to their phishing@google.com address:

    The email and website you have discovered is not owned by Google. Instead, it was likely designed by an unauthorized party operating under false pretenses while using the Google brand. This practice is commonly called 'phishing.'

    'Phishing' occurs when an unauthorized party claims to be a representative of a legitimate organization in an attempt to trick the recipient into disclosing important personal information like passwords, bank account numbers or other sensitive information.

    If you receive a suspicious email like this, do not visit any of the URLs provided; they may install malware (harmful software) on your computer.

    Keep these tips in mind to help you spot phishing attempts:

    • Be wary of unsolicited messages. Google's AdWords team will never send you an email asking you to reply with your password or other sensitive information. If you need to change your account information, such as your billing details or your password, always sign in to your AdWords account from https://adwords.google.com and make the changes directly within your account.
    • Check the message headers. The From: address and the Return-path should reference the same source.
    • Make sure the URL is legitimate. The AdWords homepage URL will always be https://adwords.google.com.
    • Change your Google Account password frequently.
    • Keep your computer's antivirus and spyware protections up to date and regularly run system scans. Antivirus software (such as Norton Security Scan and Spyware Doctor) and instructions for use are available for free as part of the Google Pack (not available in all languages).


    Keeping our users safe from phishing is something we take very seriously. To help us stop phishing attacks, we ask that you report any suspicious messages or websites to Google at phishing@google.com


    This morning our spam filters and those of some of our clients were clogged with a number of bogus emails purporting to be from Google AdWords. Bearing the subject line "Please Re-activate your account," they resemble some actual billing-info alerts from Google, but they are pure phishing scams -- sent to random email addresses and meant to get receivers to cough up their credit card info.

    The sender email address and the links are spoofed to make them appear to be Google addresses. When you "view source" you'll see the links actually point to a "Adwords.Google.com" subdomain on the Chinese domain hki045.cn, or other non-Google domain. If you receive similar messages, IGNORE AND DELETE THEM! DO NOT CLICK THROUGH.

    The copy of one of the emails we received is as follows:

    ---------------------------------------------------------------------------------
    Dear Google Adwords Customer,

    Your ads have stopped running because we were unable to process your billing information.
    To activate your account and start running your ads, enter your billing information.

    In order to activate your account and start running your ads, enter your billing information.
    Pease sign into your account at http://adwords.google.com/select/login, and update
    your billing information.

    Once your account is reactivated and your billing information has been processed,
    any your ads and campaigns can begin running immediately on Google.

    ----------------------------------------------------------------------------------
    This message was sent from a notification-only email address that does
    not accept incoming email. Please do not reply to this message.

    ----------------------------------------------------------------------------------

    Google Adwords Team