1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

A Cautionary Tale...

Discussion in 'Google AdWords' started by CustardMite, Aug 8, 2008.

  1. #1
    Hi all,

    Something happened to one of the accounts that we manage yesterday, that you should probably be aware of.

    The account was created by our client, who had only used a 6 character password, and the account was hacked.

    Somebody accessed the account, set up a new campaign, and spent £600 of their cash sending people to a free mobile phone download website in America and Canada.

    After a few hours, they turned off the campaign and deleted their website (hence covering their tracks quite well).

    Google cancelled the account as soon as they noticed it.

    We have resolved the problems, got the money back and reactivated the account (it's great having an Adwords rep, isn't it!), but you should probably be aware that your passwords are hackable, particularly if they are short or obvious.
     
    CustardMite, Aug 8, 2008 IP
    scubita likes this.
  2. T_Media

    T_Media Peon

    Messages:
    691
    Likes Received:
    13
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Thanks for the heads up CustardMite
     
    T_Media, Aug 8, 2008 IP
  3. info

    info Well-Known Member

    Messages:
    898
    Likes Received:
    12
    Best Answers:
    0
    Trophy Points:
    120
    #3
    Thanks. need to change password more often.
     
    info, Aug 9, 2008 IP
  4. robertpriolo

    robertpriolo Peon

    Messages:
    1,859
    Likes Received:
    30
    Best Answers:
    0
    Trophy Points:
    0
    #4
    interesting...

    care to share the password that was hacked?

    I just wonder how obvious it was
     
    robertpriolo, Aug 9, 2008 IP
  5. Michael T.

    Michael T. Active Member

    Messages:
    816
    Likes Received:
    19
    Best Answers:
    0
    Trophy Points:
    60
    #5
    Really interesting.But why only a 6 characters password for adwords?All my paswords all at least 10 characters.
     
    Michael T., Aug 9, 2008 IP
  6. PPC-Coach

    PPC-Coach Active Member

    Messages:
    1,450
    Likes Received:
    23
    Best Answers:
    0
    Trophy Points:
    90
    #6
    I had an old account with a 6 character, real word password hacked 2 weeks ago too.

    I didn't even know until my rep emailed me and said it happened and they stopped it and credited me the money.

    If your password is a real word, these hackers use brute force scripts that literally run through the dictionary applying each word to the login until they have success. I didn't think adwords accounts could have those brute force hacks, but I guess they can. The solution is go with random letters, numbers and symbols and use a passwords manager to remember them. My new passwords are all 10 to 20 characters in length and all random.

    :)
     
    PPC-Coach, Aug 9, 2008 IP
  7. scubita

    scubita Peon

    Messages:
    5,550
    Likes Received:
    318
    Best Answers:
    0
    Trophy Points:
    0
    #7
    I change my passwords (all of them) quite often. Thanks for heads up buddy :)
     
    scubita, Aug 9, 2008 IP
  8. CustardMite

    CustardMite Peon

    Messages:
    1,138
    Likes Received:
    33
    Best Answers:
    0
    Trophy Points:
    0
    #8
    Just a quick follow-up on this. It's happened to a second account (set up by one of our clients, but now being managed by us). It was a seven character password including letters and numbers.

    Strongly advise everyone to make their passwords 10 characters plus, and pass this on to their clients, if they have logins to their accounts...
     
    CustardMite, Aug 26, 2008 IP
  9. GuyFromChicago

    GuyFromChicago Permanent Peon

    Messages:
    6,728
    Likes Received:
    528
    Best Answers:
    0
    Trophy Points:
    0
    #9
    Were these two accounts both from the same client?
     
    GuyFromChicago, Aug 26, 2008 IP
  10. Dollar

    Dollar Active Member

    Messages:
    2,598
    Likes Received:
    82
    Best Answers:
    0
    Trophy Points:
    90
    #10
    I would think telling Adwords to put a bruce force protection in there login would be beneficial.
    Even Vbulletin has it, you get 5 trys then you have to wait 15 minutes.
     
    Dollar, Aug 26, 2008 IP
  11. GuyFromChicago

    GuyFromChicago Permanent Peon

    Messages:
    6,728
    Likes Received:
    528
    Best Answers:
    0
    Trophy Points:
    0
    #11
    If you try and login to AdWords (any G' service I think) a few times and fail it throws the captcha into the mix.

    I wonder if the compromised accounts were both from the same client. If so, maybe a password document got leaked or they were using a similiar (and easy) password combo.

    Anyway, strong passwords are a must and things like this are a great reminder.
     
    GuyFromChicago, Aug 26, 2008 IP
  12. CustardMite

    CustardMite Peon

    Messages:
    1,138
    Likes Received:
    33
    Best Answers:
    0
    Trophy Points:
    0
    #12
    Different clients.

    The password on the second one should have been fairly secure - he'd not used it in a year (which should rule out any kind of spyware) and he swore he hadn't e-mailed the password to anyone (which should rule out e-mail fraud).

    As you say, Google should be secure, so I don't know how it can have happened, only that it did...
     
    CustardMite, Aug 27, 2008 IP
  13. monfis

    monfis Well-Known Member

    Messages:
    1,476
    Likes Received:
    31
    Best Answers:
    0
    Trophy Points:
    160
    #13
    Happened to me two years ago (more than $ 3000)
    Had no problems with Google, they recognized, closed the compromized account and offered a new one, but I noted then - it's possible to live without Adwords (at least for the moment) :)
     
    monfis, Aug 27, 2008 IP
  14. pondlife

    pondlife Peon

    Messages:
    898
    Likes Received:
    18
    Best Answers:
    0
    Trophy Points:
    0
    #14
    Captured by a phishing attack maybe? AdWords is only an email plus password which may have been the same login for many different applications.

    Thanks for making us aware and bringing this issue back into our consciousness.

    :)
     
    pondlife, Aug 27, 2008 IP
  15. CustardMite

    CustardMite Peon

    Messages:
    1,138
    Likes Received:
    33
    Best Answers:
    0
    Trophy Points:
    0
    #15
    Disused login. Nobody had used it in over a year, or given the password to anyone else (via e-mail or anywhere else).

    Most perplexing...
     
    CustardMite, Aug 27, 2008 IP
  16. narsticle

    narsticle Peon

    Messages:
    1,679
    Likes Received:
    12
    Best Answers:
    0
    Trophy Points:
    0
    #16
    wow thats a really sucky situation. I use really obscure passwords.
     
    narsticle, Aug 27, 2008 IP
  17. GuyFromChicago

    GuyFromChicago Permanent Peon

    Messages:
    6,728
    Likes Received:
    528
    Best Answers:
    0
    Trophy Points:
    0
    #17
    I posted about this over the weekend...one of my personal AdWords accounts was hacked on September 18th. I had not changed the password in a long time but it was strong. I was lucky...no charges were incurred but the account is still completely inactive.

    Change your passwords!
     
    GuyFromChicago, Sep 22, 2008 IP