WARNING – Google AdWords PHISING SCAM – Please Update Your Billing Information
Here is a copy of the email, with the hyperlink de-activated:
From: Google Adwords-noreply [mailto:adwords-noreply@google.com] Sent: Saturday, March 22, 2008 9:28 AMTo: info@fireman247.comSubject: [PHISH] [SPAM] - Please Update Your Billing Information
------------------------Dear Google AdWords Customer!In order to update your billing information, please sign into your AdWords account at https://adwords.google.com, and update yourbilling information. Your account will be reactivated as soon as you haveentered your payment details. Your ads will show immediately if youdecide to pay for clicks via credit or debit card. If you decide to payby direct debit, we may need to receive your signed debit authorizationbefore your ads start running, depending on your location. If youchoose bank transfer, your ads will show as soon as we receive yourfirst payment. (Payment options vary by location.)Thank you for choosing AdWords. We look forward to providing you withthe most effective advertising available.Sincerely,The Google AdWords Team------------------------This message was sent from a notification-only email address that doesnot accept incoming email. Please do not reply to this message. If youhave any questions after following the steps above, please visit theGoogle AdWords Help Center athttps://adwords.google.com/support/bin/topic.py?topic=8336&hl=en_US tofind answers to frequently asked questions and a 'contact us' link nearthe bottom of the page.
Now, I have de-activated the hyperlink in this email because I do not want any unsuspecting people to accidentally click it, however if you were to have held your mouse over the hyperlink that said http://adwords.google.com, and looked at the actual destination URL.
In this case, the destination URL from the hyperlink pointed towards: http://adwords.google.com.fr4xx.cn/select/Login/
Notice the very last part of the URL. Fr4xx.cn. That is the actual destination URL, not the sub domain prefix. So, while this URL does contain the adwords.google.com that we are all familiar with, the actual domain is the last part fr4xx.cn. This is obviously not Google and therefore a PHISING scam.
It’s always important to remember to check the sending email address. This is not necessarily the visible email address that is shown, but the actual email address. If it is not from Google, then it is not an official Google email. The display email address is often not the actual sending address, just like you might see your friends name in the reply to field instead of their email address. You can check the actual sending email address by looking at the header. Go to View/Options, and you will see the header information in a box called “internet headers:”
The bottom line here is that if there was a billing problem with your Google AdWords account, you could always login to your AdWords account and see the notice. This would be my advice, to always check your Google account directly and not rely on the wording of an email.
If you received this email today, or one similar to it, delete it. It’s a fake.
Google has been notified and the violating site has already been shut down. I’m sure new sites will arise and abuse this same scam, so be careful and remember to always check your Google account directly for account notices.
Having an experienced account manager can prevent abuse like this from happening to your account. Contact me today to find out how I can dramatically increase the ROI from your Google AdWords account.
