Click to Sync: From Google Ads Maintenance Notice to Credential Theft
ID: 90658d52-6368-533d-a504-9df1a2afe3bb
STIX ID: report--90658d52-6368-533d-a504-9df1a2afe3bb
Feed Name: Cofense Blog
Cofense PDC observed a phishing campaign impersonating Google Ads Sync (MMC) that sends fake maintenance notifications urging users to "Complete Sync Account"; clicking the email redirects victims through a Blogspot redirect to a newly registered lookalike domain (mcc-sync-ads.com) which hosts a staged Google sign-in (a .js form) to harvest credentials. The report highlights brand impersonation, urgency-based social engineering, the sender domain enavalenceart.com, the redirect URL (syncmcchub.blogspot.com/2026/06/syncmcchub.html) and recommends user training, verification via official channels, and phishing defense controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
