Skip to main content

Click to Sync: From Google Ads Maintenance Notice to Credential Theft

July 21, 2026

By: Elaine Irinco, Cofense Phishing Defense Center

Threat actors continue to exploit trusted brands to lure users into phishing attacks. Using social engineering techniques that create scenarios that mimic parts of a user’s daily routine, they leverage a sense of urgency and familiarity to manipulate people’s behavior. The Cofense Phishing Defense Center (PDC) has observed a new phishing campaign targeting Google Ads Sync Accounts (MMC), in which attackers send fake system upgrade notifications that urge recipients to synchronize their accounts immediately. Brand impersonation remains one of the most common tactics used to establish trust with victims. 
 

In the case of this attack, attackers sent malicious emails disguised as a maintenance notification from Google Ads Sync that requires account synchronization as a prerequisite for credential harvesting. In organizations where platforms like Google, Microsoft, Amazon, and other well-known services are a major part of the business process, these platforms are often used by cybercriminals as an easy way to capture users’ attention and serve as a starting point for their malicious activities. 

Figure1 (19)

Figure 1: Spoofed Google Ads MMC Sync Maintenance Notification
 

 Threat actors commonly spoof legitimate organizations to increase the credibility of phishing emails. In this case, the fraudulent email claims to be from Google Ads MMC Sync, which can be seen under the sender's name. However, a closer look at the sender’s email address reveals that the domain is enavalenceart[.]com, which is not associated with the Google Ads domain. This notification, disguised as a system upgrade notice, urges users to manually sync their MMC accounts and threatens anyone who fails to comply within the specified time frame with service interruptions or account limitations. Threat actors often use a sense of urgency to manipulate recipients, as seen in the wording in Figure 1, which urges the user to click the “Complete Sync Account” button. 

The phishing email prominently displays Google's branding to reinforce legitimacy. Users are more likely to trust familiar logos and branding, making brand impersonation an effective social engineering technique. This is why it is important to train users to be aware of the security risks associated with commonly used or familiar websites and applications.

Figure2 (20)

Figure 2: Spoofed Google Ads Redirection Page
 

Upon clicking the "Complete Sync Account" button, the user is redirected to hxxps://syncmcchub[.]blogspot[.]com/2026/06/syncmcchub[.]html. During the redirection process, a Google Ads logo and a loading indicator briefly appear alongside a continue button. This makes the page appear more legitimate and helps to avoid any hint of malicious activity on the backend. Attackers use spoofed lookalike domains like the one shown in Figure 2 to deceive users into interacting with the malicious page.

Figure3 (17)

Figure 3: Google Ads Account Sync Phishing Page

After a quick redirect, users are taken to the main phishing page. In this case, they land on another malicious URL (hxxps://mcc-sync-ads[.]com/) which at first glance appears to be a legitimate Google Ads URL. Further investigation of the domain shows that it is newly created and not associated with or owned by Google. By combining newly registered lookalike domains with mimicked legitimate login pages, attackers attempt to lure users into interacting with the malicious email.

Figure4 (14)

Figure 4: Google login embedded within Google Ads Account Sync Phishing Page

The phishing page shown in Figure 4 includes a Google sign-in button which, after clicking, displays a .js form made to imitate the legitimate Google sign-in page. This method is a multi-stage phishing attack in which each step is designed to build trust before prompting the victim to input their credentials on what appears to be a legitimate login page. The user is likely unaware that the resulting Google pop-up is a .js form designed to accept and store the user’s credentials.

Ultimately, threat actors continue to evolve their phishing techniques by abusing trusted platforms and impersonating legitimate services to deceive users into disclosing sensitive information. These attacks rely on creating a false sense of legitimacy and urgency, increasing the likelihood that users will interact with malicious content. Organizations can reduce their risk by fostering a strong security culture through user awareness training, encouraging employees to verify any unexpected requests via official channels, and promoting the habit of thinking before clicking links or responding to unsolicited messages. A proactive approach to cybersecurity remains one of the most effective defenses against credential theft and phishing attacks.

Today's phishing attacks rely on trusted brands, adaptive infrastructure, and convincing social engineering to evade traditional defenses. Organizations need a phishing defense strategy that can identify, investigate, and remediate these advanced threats. Cofense delivers AI-powered phishing detection backed by human intelligence to help security teams stay ahead of evolving attacks. Schedule a demo to see the platform in action.