NEWS /

Data Theft Scam Targets Google Ads

29 Apr, 2007, 1:00 pm IST | by AP |

Google Inc. yanked paid advertisements linked to some 20 search terms that online criminals had hijacked to steal banking and other personal information from Web surfers looking for the Better Business Bureau and other sites.

It was unclear how many people were affected before the breach was discovered this week, but computer security experts said Thursday the attack appears to be isolated and only targeting Windows XP users who had not properly updated their machines.

They said the attack was unlikely to undermine Google's core business of selling lucrative advertising links, which made up the bulk of the Mountain View-based company's $3.08 billion in profit in 2006 and $1 billion in the first quarter of 2007 alone.

Google said it dismantled the offending links and shut down the problem AdWords accounts Tuesday. The company is working with advertisers to identify any other malware-loaded sites that might be on the network, it said.

''We canceled the affected ads as soon as we were made aware of the problem,'' the company said in a statement. ''Overall, Google is committed to ensuring the safety and security of our users and our advertisers. We actively work to detect and remove sites that serve malware to our users both in our ad network and in our search results.''

However, the experts said the infiltration of the Web's largest marketing network raises questions for the entire search industry about how to screen advertisers for those with nefarious motives.

The attack targeted the top sponsored links tied to Google search results, installing a program on victims' computers to capture private information used to access online accounts for 100 different banks.

''This is serious—there's confidence in the links that are at the top, whether they're sponsored or not,'' said Nick Ianelli, an Internet security analyst with the federally funded CERT Coordination Center at Carnegie Mellon University. ''It's going to affect the whole industry, not just one provider.''

The scheme, discovered by security software firm Exploit Prevention Labs in New Kingston, Pa., involves a ruse by online criminals to fool Google searchers into clicking through a rogue site loaded with malicious code.

The criminals created their own Web site and outbid legitimate businesses in Google's AdWords program to secure prime placement of ads linked to popular search terms. Users who clicked on those ads were then routed to the booby-trapped site before being sent on to the legitimate destination.

Ken Dunham, director of the rapid response team at VeriSign Inc.'s iDefense Intelligence, said criminals targeted Google's AdWords service in a similar manner in a 2005 ''phishing'' attack.

In that case, the criminals created a site that mimicked a well known retailer, placed an ad on Google, then stole users' credit card and other information when they tried to order products, he said.

Dunham said Google likely implemented more stringent authentication policies for its premium advertising members after that incident. However, he said it would be too costly to impose the same verification procedures for all advertisers.

The current incident raises questions for search companies about how they screen members of its advertising network and drives home the message about keeping up with security updates, Dunham said.

''Attackers have been doing this for some time—the old dog is still doing old tricks and it's working,'' he said. ''We need to realize this is a known tactic, people should be aware of it and identify when this could be an issue.''

Roger Thompson, chief technology officer for Exploit Prevention Labs, said Thursday that no further attacks of this type had been discovered, ''but the exploit site is still live and serving, so if someone finds a way to hook to it, it'll fire.''

Tags: Google , data theft

RELATED STORIES

EU's Almunia offers Google chance to settle antitrust case, Google disagrees with opinion

EU's Almunia offers Google chance to settle antitrust case, Google disagrees with opinion

The European Union's antitrust chief on Monday offered Google a chance to settle an investigation into allegations of anti-competitive behaviour after ...

26/11 attacks planned using Google Earth, says U.S commander

Google to meet French regulator on privacy policy

Chrome 19 now available, features Tab syncing

Google Drive gets Research tool

Samsung confirms Galaxy Nexus will not officially launch in India

Google engineer behind Street View data breach identified

googles dark side - google conspiracy

20 Sep, 2007, 11:29 pm IST

googles dark side - google conspiracy

google office around the world

12 Mar, 2010, 10:37 am IST

google office around the world

HotForWords - GOOGLE SEXY OFFICIAL VIDEO

06 May, 2011, 09:31 am IST

HotForWords - GOOGLE SEXY OFFICIAL VIDEO

google Documentary - Discovery Channel

23 Jan, 2011, 04:05 pm IST

google Documentary - Discovery Channel

 

Leaked Images, Availability, Pricing,
Specs, Pre-order

Photos

High Court Order - Madras

High Court Order - Madras

17 May, 2012, 04:22 PM

2.3

Trials Evolution

Trials Evolution

12 May, 2012, 10:33 AM

Sniper Elite V2

Sniper Elite V2

09 May, 2012, 10:04 PM

3.6

MORE PHOTOS

OPINIONS

Padmini Harchandrai

The latest "should they-shouldn't they" event with Facebook is the lift of the minimu...

MORE OPINIONS

features

Portable Wi-Fi Drives for your smartphone

Portable Wi-Fi Drives for your smartphone

Fed up of the limited storage on your mobile device? Here are some devices

By Aaron Almeida

Top 5 potential Gmail alternatives

Top 5 potential Gmail alternatives

Google’s Gmail service is arguably the most advanced and feature-packed...

By Naina Khedekar

Five ways to beat the petrol hike

Five ways to beat the petrol hike

Petrol prices went up by a considerable amount post Wednesday, and this...

By Karan Shah

MORE FEATURES

On video: HTC One V

On video: HTC One V

18 May, 2012, 04:44 AM

4.5

On video: Cowon Z2 (16GB)

On video: Cowon Z2 (16GB)

15 May, 2012, 04:58 PM

2.3

On video: Samsung WB150F

On video: Samsung WB150F

08 May, 2012, 04:23 AM

5.0

MORE VIDEOS

776 views

1129 views

630 views

MORE WALLPAPERS