Check your adcenter accounts

clockwork84

New member
Jul 6, 2008
364
14
0
Castle Grayskull
I got a strange e-mail today from adcenter confirming a pre-existing billing agreement on an account that I haven't used since April. I log-in to adcenter to make sure nothing fishy was happening, and I noticed that a paused campaign was live and getting traffic. At any rate, someone created a bunch of new adgroups for some utorrent software download site. I whois'd the destination URL, and it's some photographer in Oregon (I'm assuming his site was hacked).

So, just a heads up, if you have any seldom used adcenter accounts, you might want to check up on them. I'm not entirely sure how someone got access.
 


You got phished.

I don't think it was phishing related. The e-mail was legit (headers and account numbers), and I didn't click on any of the links to begin with. The adgroups were all created 4 days prior to me receiving the e-mail this morning. I also don't typically click on any e-mail links, I haven't received an e-mail from adcenter in a while, and this username/password combo is isolated to this account. The only interaction I've had with adcenter/yahoo recently is receiving a snail-mail refund check. So, unless that was a forged check with some psychic neural transmitter probe, I don't see how someone could have phished this particular account.
 
I think that Jose was implying that you had been phished previously which is how somebody got into your account and changed settings that triggered the notification message.
 
I just logged into my adcenter account which I haven't used in probably 6 months+.

Someone had created an adgroup in an old campaign targeting a ton of phentermine-related keywords pointing to PharmacyDot.info and blew through about $500 in the last couple days.

Good thing i randomly decided to log into my acct as it'd already billed my amex a couple times without me noticing :P

Just put in a support request and calling them tomorrow so hopefully they'll make good. I spent a decent amt with them in the past so I don't see why they wouldn't.

Anyone able to dig up some info on pharmacydot.info? I'm thinking of forking over some cash and getting their whoisguard lifted, but it was probably purchased with a stolen cc and fake info anyway.
 
picard-facepalm.jpg