Forum Moderators: buckworks & skibum

Message Too Old, No Replies

Adwords Account Hacked

seems to be a bit of it about

         

ytswy

11:05 am on Aug 14, 2008 (gmt 0)

10+ Year Member



More a heads up than anything; we've just had someone compromise our adwords account - they added a new campaign with an insane budget promoting some dodgy "anti" virus site. Been doing a bit of searching around and have seen other recent reports of hacks with a similar mo.

Cheeky person paused our campaigns as well.. Caught it within 24 hours and I understand Google will refund charges for fraudulent activity, so no real harm done.

Best tip I've found is that if you go Campaign Management > Tools > My Change History you can see all the changes made to the account. This saved me a lot of time checking each ad in our legitimate campaigns to check the destination url hadn't been changed. Also revealed that he'd turned off all email notification.

Not sure how they got our details, although I'm as sure as I can be that it's not due to malware on a local machine. Don't think it was phished either although I can't be 100% positive. Maybe brute forced, or it got exposed some other way.

Really weird thing was that the destination domain in the fraudulent ads doesn't exist.. can't figure that out for the life of me..

Anyone got any tips for what to do in this situation?

[edited by: engine at 4:02 pm (utc) on Aug. 15, 2008]

irish_john

6:22 pm on Aug 25, 2008 (gmt 0)

10+ Year Member



I noticed the following behaviour, after my main MCC was hacked, one of my accounts received a phishing email.

iJeep

7:56 pm on Aug 25, 2008 (gmt 0)

10+ Year Member



We just had ours hacked over the weekend. They spend over $8000 in just a few days. I got the standard answer from Google on this one.

What I can't figure out is how they got in. I'm the only person who knows the password and I never click links in e-mail messages, I always open a new tab and type it in direct.

I saw somebody mentioned iPhone. I use my iPhone to check things on my Google account.

Is it a possibility that the iPhone connection was hacked or that Google itself was hacked and got everybodies account info from there?

RhinoFish

1:24 pm on Aug 26, 2008 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



one of my clients got the phishing mail again, he knows the deal, but he saw the domain and thought it "looked" real...

adstechselect . com

he still didn't click it, i've beaten it into him to not do that.

AWA - does G want us to forward these phishing attempts to a certain inbox there?

jskrewson

3:48 am on Aug 30, 2008 (gmt 0)

10+ Year Member



I just discovered that my client center account was hacked, and all 4 of the accounts I manage. It was the same anti-virus, cheap airfare, etc ads. They racked up $34,395 dollars in 12 hours!

Unbelievable. I seem to have caught it before very many, if any charges went through to my credit cards. I reported my credit card and my backup credit card as stolen. I couldn't risk having that much of a charge on my accounts, even for a couple of days...

I too wish I knew how they got my password. I don't click on e-mail links ever. I do use my iPhone with my google account.

Really bad time of the year, I make most of my money from back-to-school. This could really, really hurt me financially if my adwords accounts are down for any period of time.

027viaa

9:37 am on Aug 30, 2008 (gmt 0)

10+ Year Member



It has been a week for me now. No response from Google so far, apart from the 'we are investigating' one.

I also took care Google no longer is allowed to withdraw money from my bankaccoun.

jskrewson

2:20 pm on Sep 1, 2008 (gmt 0)

10+ Year Member



Adwords is closed for Labor Day. How can a company that generates millions in revenue, 24-7, possibly have phone support that is only available during regular business hours?

My ads have been down for three days and I haven't even received acknowledgment of the problem.

mortgagemax

2:41 pm on Sep 1, 2008 (gmt 0)

10+ Year Member



The lack of support hours is completely astonishing ... isn't it?!

... and you say "millions in revenue"? Try over $3 BILLION in PROFIT last quarter alone!

027viaa

5:58 pm on Sep 1, 2008 (gmt 0)

10+ Year Member



Got an update again....received an email from google:
Subject: "Outstanding Balance for Google AdWords" :-(

Ofcourse I've asked my bank to block my bankingaccount.

Can't believe it takes this long for Google to do the investigation :(

Green_Grass

12:04 pm on Sep 3, 2008 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



New phishing mail on its way.

I was almost convinced.

It goes .... disapproved ads... gives a reason..very sophisticated.

Watch out..

027viaa

1:25 pm on Sep 4, 2008 (gmt 0)

10+ Year Member



Just got an answer from Google. They investigated my complaint and confirmed my account has been compromissed and I am not responsible for the > 10.000 euro's spend.

Big relief! I still wonder though how the hell the got in...I'm not the kind of guy fooled by phising tricks :(

RhinoFish

1:59 pm on Sep 4, 2008 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I'm sure this was no fun for you at all, think the same must be true for Google and their aggregate funds lost must be substantial. I wonder what future security protocols G might add to protect their advertisers, their own finances and their time (I'm sure this is time consuming for G)... maybe give anyone who would be willing to layer in extra security a small discount... I'd give G my fingerprints and buy a biometric scanner if it would help, I just trust G that way.

Anyhow, very glad to hear that things were resolved for you!

And I hope G pursues the perp's data trail and helps law enforcement catch them and that they get locked up hard.

This 41 message thread spans 2 pages: 41