This is the story of Russell, whose AdWords campaigns fell prey to a phishing scam.
Seemingly out of the blue, Russell one day noticed how a lot of odd, likely spammy campaigns had been set up in his account though.
“While the email may look official at first glance to those who don’t know about the concept of phishing – Russell didn’t – those who do know about it will have a symphony of alarm bells ringing by now. In this email, it is not important what the mail claims to be; it claims that it’s an “official notification from Google AdWords that the service(s) listed below will be deactivated†unless the person renews them “immediately.†The email also claims to be sent from the address customersolutions–ysm@google.com. But these things can be faked; what is more important is the URL that shows when you hover over the link in question that will take you to the login form. In this case, Russell tells me the URL reads:
yms-words.com/adwords/select/Login.htm”