Adwords Account Hacked

Discussion in 'Google AdWords' started by ecompeak, Nov 23, 2007.

  1. #1
    Every morning I check my Adwords account, and it's a good thing I do.

    Somehow, someone hacked into my adwords account, setup a new campaign, set the max bid at $5 and the daily max at $5000! They ending up racking up over $350 yesterday and $45 today before I caught it.

    I have reported this to Google, and changed my adwords account password.

    Has anyone ever had this happen to them?

    Will Google try to stick me with these charges?

    Is changing my password enough to protect myself?

    Why are these such scum bags in the world?

    A word of caution - check your adwords account at least daily.

    Mike
     
    ecompeak, Nov 23, 2007 IP
  2. joebloggs

    joebloggs Peon

    Messages:
    265
    Likes Received:
    15
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Thanks

    I'm sorry to hear about that.

    I do check every day!
     
    joebloggs, Nov 23, 2007 IP
  3. Red_Virus

    Red_Virus Well-Known Member

    Messages:
    3,756
    Likes Received:
    249
    Best Answers:
    0
    Trophy Points:
    135
    #3
    Really sorry to hear about that, So did Google refund the money & did u contact the guy whose site was being promoted with your account. ?
     
    Red_Virus, Nov 23, 2007 IP
  4. Minterest

    Minterest Well-Known Member

    Messages:
    2,694
    Likes Received:
    39
    Best Answers:
    0
    Trophy Points:
    180
    #4
    Did u get the money back from adwords???
     
    Minterest, Nov 23, 2007 IP
  5. ecompeak

    ecompeak Peon

    Messages:
    12
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #5
    I'm waiting to hear back from Adwords.

    Will they go after the person for fraud, or will it be up to me? The person's website is a blog, with no contact info. I did a whois on the domain and the contact information is private.

    I'll keep you posted.

    Thanks,
    Mike
     
    ecompeak, Nov 23, 2007 IP
  6. gsv13

    gsv13 Well-Known Member

    Messages:
    2,773
    Likes Received:
    114
    Best Answers:
    0
    Trophy Points:
    130
    #6
    I hope they will do something to that site!! ;)
     
    gsv13, Nov 23, 2007 IP
  7. motex

    motex Peon

    Messages:
    234
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #7
    Make sure you gather all this information and pile it into a zip or folder. Contact that websites host and if google sends out any email on the matter forward it to them. I think you need a subpeona...however you spell that but If you keep at it bro, you will get it done and nab the guy....Hopefully, depends how good he is at being covert.

    Make sure you do a full virus scan on your computer, and update you browser if need be.....check security sites for any new browser exploits....Track back to any emails you have received, anything odd that maybe happened to your computer.

    It could even be as simple as, you used a public computer and someone either had control over it...Who knows, lots of possibilities.

    Starting to wonder if you running on wiFi...thats so easy to sniff traffic from. Hence your google sign in details....

    Hope google helps you out man.
     
    motex, Nov 23, 2007 IP
  8. amirt5

    amirt5 Peon

    Messages:
    218
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #8
    Really sorry to hear about that
    try to use 2 language password
     
    amirt5, Nov 23, 2007 IP
  9. ecompeak

    ecompeak Peon

    Messages:
    12
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #9
    I finally received an response from Google.

    Thank you for your email. I apologize for the delayed response. I
    understand your Google AdWords account may have been compromised by
    malicious software, or 'malware.' Your account has been suspended
    temporarily while we investigate this matter. Please read this email
    carefully for information on how to check your computer for malware, as
    well as instructions on providing details for our investigation.

    CHECK YOUR COMPUTER FOR MALWARE

    (Gave a list of Malware killing programs to try.)

    HELP US INVESTIGATE YOUR ACCOUNT

    Please respond to this email with the following information for our
    investigation:

    1. When do you suspect the account was compromised?
    2. What were the last changes you made or your last successful login?
    3. What was changed within your account? Please specify the campaigns, ad
    groups, and keywords affected.
    4. What is your IP address? Please visit http://www.whatismyip.com and
    reply with the number that appears in the green bar at the top of the
    page.
    5. Did you sign into your account from different locations recently?

    Once we've received this information, we'll investigate your account's
    activity. This process may take several days.


    TEMPORARY SOLUTIONS

    If you still have access to your current AdWords account, please change
    your password after you've checked your system for malware.

    If you'd like to continue advertising while we're conducting our
    investigation, create a new account after you've checked your computer for
    malware. Be sure to use a different password for the new account. You can
    then reply to this email with your new Customer ID, and we will waive the
    activation fee for your new account.

    Please reply directly to this email with any additional questions or
    concerns you may have. Thank you for your cooperation.

    ----------------------------------------------

    I have done some investigation of my own, and have found some strange things. The domain the Adwords ad is directed to is a .net domain (that was registered the same day as my account was hacked). The .net domain redirects to a .com of the same name. The weird thing is, this is a blog and I don't see any monetization on the blog. The only links on the blog go to major finance sites and I see no affiliate links.

    Why would someone steal $425 worth of clicks and not try to make money on it? Could it be someone is trying to screw me personally for some reason, instead of trying to steal clicks to make money?

    I still don't know if Adwords is going to charge me - they neglected to answer that question.

    Mike
     
    ecompeak, Nov 26, 2007 IP
  10. semantic7

    semantic7 Member

    Messages:
    92
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    48
    #10
    If I were you I would do a complete check on the computer and change the login name and password for the computer and password for your adwords account. The extent of sophistication malwares have now I would be satisfied only after a complete wipe and reinstall but thats just me. My guess you either have a wireless internet connection, a weak password or a keylogger in your computer.
     
    semantic7, Nov 26, 2007 IP
  11. sirKello

    sirKello Active Member

    Messages:
    174
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    51
    #11
    That's bad news dude.
    Fingers crossed that Google waves the fee.

    Keep us up to date.
     
    sirKello, Nov 26, 2007 IP
  12. allswl

    allswl Well-Known Member

    Messages:
    451
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    128
    #12
    hope you get back your money..maybe you should change your login info regularly
     
    allswl, Nov 26, 2007 IP
  13. ecompeak

    ecompeak Peon

    Messages:
    12
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #13
    Here is an update on my Adwords account getting hacked into.

    Google did an investigation and were good enough to not charge me for the fraudulent campaign. However, they mentioned nothing about going after the hackers.

    They suggested I run a spyware removal program, and create a new Adwords account.

    My McAfee anit-virus software was up to date, and the two spyware programs I ran showed nothing, other than some cookies.

    I will be much more careful with my passwords in the future, and make them totally impossible to guess.

    Don't get complacent and think they won't get you. Be careful!

    Mike
     
    ecompeak, Nov 30, 2007 IP
  14. Cadelaf

    Cadelaf Peon

    Messages:
    184
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #14
    Prolly you got your account phished?
    You sure you typed the correct address?

    Download a firewall to see all your traffic

    I recommend comodo firewall it is free and it is the best
    personalfirewall.comodo.com
     
    Cadelaf, Nov 30, 2007 IP
  15. ferrari61

    ferrari61 Peon

    Messages:
    71
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #15
    incredible! I persoanlly wouldn't expect Google to take it further - they might allow for 'small quantity' fraud (and it might not be worth their while?) - agree that passwords need to be more complicated (must change mine!) - you didn't say if you have wireless (what encryption) or logged in on a machine other than your normal machine

    Good Luck - it'll be good to hear if Google does decide to persue the offender (of course they NOT LET YOU KNOW ABOUT IT?)
     
    ferrari61, Nov 30, 2007 IP