Fake Google Ads “Sync” Alert Steals Credentials

Cofense · Medium sophistication
Last updated July 30, 2026

Cofense observed a real phishing campaign impersonating Google Ads Sync Accounts (MMC) with a fake “maintenance/system upgrade” notice. The email pressures recipients to click “Complete Sync Account,” sending them through lookalike sites and a fake Google sign-in pop-up that captures credentials. The attack relies on brand trust (Google logos) and urgency (threats of service interruption) to drive clicks.

How the attack worked

Cofense documented a phishing campaign that impersonates Google Ads MMC Sync accounts using a fake system upgrade or maintenance notice. The email pressures recipients to click a Complete Sync Account button, warning that failing to act within a set time frame will cause service interruptions or account limitations. Clicking the button starts a multi-step redirect: first to a Blogspot page displaying Google branding and a loading indicator, then to a newly registered lookalike domain, mcc-sync-ads[.]com. That final page presents a Google sign-in button that opens a JavaScript form built to imitate the real Google login and harvest whatever credentials are entered.

Why it succeeded

The campaign leans on two familiar social engineering levers: brand trust and urgency. The email prominently uses Google branding to appear legitimate, even though the sending domain, enavalenceart[.]com, has no connection to Google Ads. The urgent framing around account sync and threatened service disruption is designed to push recipients past normal scrutiny and toward the call to action before they check the sender address or the destination URLs.

What to watch for

  • Sender display names claiming to be Google Ads MMC Sync while the actual domain is unrelated to Google
  • Urgent language threatening service interruption or account limitations for not syncing in time
  • A Complete Sync Account button that triggers a chain of redirects across unrelated domains, including a Blogspot page and a newly created lookalike domain
  • A Google sign-in prompt that appears mid-redirect rather than on a page the user navigated to directly

Building resistance

Defenders can reduce the impact of this style of attack with a few habits:

  • Teach employees to check the real sender email domain, since logos and display names are not proof of legitimacy
  • Encourage a pause when messages threaten service impacts or account limitations for inaction, since urgency is a common manipulation tactic
  • Treat unexpected account sync or upgrade prompts, and any multi-step redirect chain, as high risk, and verify URLs before entering credentials
  • Remind users that sign-in pop-ups can be fake JavaScript forms embedded in a phishing page; when in doubt, navigate to the service directly instead of authenticating through an embedded prompt

This campaign is a reminder that credential theft attempts increasingly combine convincing brand impersonation with layered infrastructure, making sender verification and URL checks essential habits for teams managing advertising or other SaaS platform accounts.

Key findings

  • Cofense observed a phishing campaign targeting Google Ads Sync Accounts (MMC) with fake system upgrade/maintenance notifications.
  • The sender display name suggests Google Ads MMC Sync, but the sending domain is not Google (enavalenceart[.]com).
  • The email uses urgency, warning of service interruptions/account limitations if the recipient does not comply in time.
  • The lure is a button labeled “Complete Sync Account,” which initiates a multi-step redirect chain.
  • Victims are redirected first to a Blogspot URL showing Google branding/loading indicators, then to a newly registered lookalike domain (mcc-sync-ads[.]com).
  • The final page presents a Google sign-in button that opens a JavaScript form mimicking a legitimate Google login to harvest credentials.

Who’s being targeted

  • Commonly targeted roles: Marketing, Digital Advertising/SEM, Growth teams, Employees with access to Google Ads / Google MMC accounts, General workforce (brand-impersonation phishing).
  • Affected industries: Advertising/Marketing, Organizations using Google Ads / major SaaS platforms.
  • Attack channels: email, website.
  • Impersonated: Google Ads MMC Sync (Google), Google Ads / Google sign-in.

Red flags to watch for

  • Sender domain is not a Google-owned domain (enavalenceart[.]com).
  • Urgent threat of service interruption/account limitation for not syncing within the time frame.
  • Redirects to non-Google/lookalike URLs (Blogspot page and newly created domain).
  • Lookalike domain: mcc-sync-ads[.]com appears legitimate at first glance but is not owned by Google.
  • Newly created domain used for login flow.
  • Google sign-in is a JavaScript imitation rather than a real Google authentication page.
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the fake Google Ads sync attack work?

An email impersonating Google Ads MMC Sync warned recipients to manually sync their account or face service interruptions. Clicking the Complete Sync Account button led through a Blogspot page to a lookalike domain with a fake Google sign-in form that captured credentials.

What domains were used in this phishing campaign?

The sending email domain was enavalenceart[.]com rather than a Google domain, and the final phishing page used a newly registered lookalike domain, mcc-sync-ads[.]com, neither of which is owned by Google.

How can employees spot this type of phishing attempt?

Check the actual sender email domain rather than trusting the display name or logo, be wary of urgent account sync or upgrade demands, and avoid signing in through embedded pop-ups that appear mid-redirect.

Who is most at risk from this campaign?

Marketing, digital advertising, and growth teams that manage Google Ads MMC accounts are primary targets, though the brand impersonation could affect any general workforce recipient.

Read the video transcript

You get an email: "Complete Sync Account" or your Google Ads MMC might be limited. Looks official, Google logos and all. You click the button. First a Blogspot page flashes with a Google Ads logo and loading bar, then you land on mcc-sync-ads.com with a big Google sign-in button. Here’s the trick: that Google sign-in pop-up is just a JavaScript form on mcc-sync-ads.com, not a real Google page. Your email and password go straight to them. One move: if a Google Ads sync email feels urgent, don’t click it. Go to ads.google.com or your normal bookmark and check your account from there.

Similar attacks