I received an email this morning purporting I was the main actor in an embarrassing video online. The email — obvious spam to anyone tech savvy — insisted I take a look.
The sender was Bale Garnock. I don’t know a Bale, but from his (her?) email address, I could tell he was legit: myoshida AT ws.ipc.fit.ac.jp. (Please, if this is anyone’s email address, let me know!) I mean, c’mon: Who takes the time to alert others of embarrassing videos they star in? This guy must be my friend.
His email only contained one line of text, which got my attention. It said “Take a look at yourself :)”, all of which was linked to this address:
http://www.google.com/pagead/iclk?sa=l&ai=YJsnJu
&num=85998&adurl=http://scramignon.com/video.exe
Being as cavalier as I am, I decided to click it. What came up (unsurprisingly, of course) was a “video” I was asked to download. No website. No ads. Just a video.
Before actually looking at it — Hey, it’s a video of me right? — I noticed the link pointed to http://www.google.com/… Wow. I was pretty surprised.
From what I can tell, it seems a spammer was able to peddle their “video” through Google’s servers by simply editing a Google ad’s query string. (Look. I can do it too: Reader, take a look at yourself!)
This is interesting, if not concerning. On one hand, I’m sure this is something that Google doesn’t want to support, as they have a campaign against promoting unsafe internet material. On the other hand, if the recipient is not careful, they could assume the email — or the link, at least — is a legitimate one.
* * *
Googlers! By no means am I making a judgment of your services by writing this post. Although spam going through Google’s services is likely a concern, I’m more poking fun at how spammers expect people to fall for these type of emails (though, unfortunately, people do). If there is someone I can contact to alert them of this email, I would be very happy to do so.
UPDATE, 4/23:
Since I made this post, I’ve received three spam emails containing links pointing to Google servers.
UPDATE, 4/21:
I finally found Google’s contact information for security issues (found via Google, no less), and I sent them an email alerting them of the problem. Although they did respond, it seems I was given a default form response, pasted below, implying nothing more will likely happen with it.
Oh well…
Hello Tim,
Thank you for bringing this issue to our attention.
The email you have received is not owned by Google. Instead, it was likely
designed by an unauthorized party operating under false pretenses while
using the Google brand. This practice is commonly called ‘phishing.’
‘Phishing’ occurs when an unauthorized party claims to be a representative
of a legitimate organization in an attempt to trick the recipient into
disclosing important personal information like passwords or bank account
numbers.
Remember, Google will never send unsolicited mass messages asking for your
password or personal information, or messages containing executable
attachments. If you ever receive one of these messages, we strongly advise
you not to view it, and to delete it immediately.
Keeping our users safe from phishing is something we take very seriously.
To help us stop phishing attacks, we ask that you report any suspicious
messages or websites to Google at phishing@google.com
We appreciate your assistance in keeping Google users safe.
Sincerely,
Andrew B.
The Google AdWords Team