:

HACKERS USE GOOGLE ADS TO PHISH MANAGEWP LOGINS

SECURITY DESK2 MIN READ
WED, MAY 6, 2026

■ AI-SUMMARIZED FROM 4 SOURCES ▸ TIMELINE

A phishing campaign leveraging Google sponsored search results is targeting ManageWP credentials, the GoDaddy platform used to manage multiple WordPress sites. Attackers are exploiting Google's ad system to reach users searching for the service.

Threat actors have launched a phishing attack using Google Ads to distribute fake ManageWP login pages. The malicious ads appear in sponsored search results when users look for the legitimate ManageWP platform, creating a convincing entry point for credential theft. ManageWP, owned by GoDaddy, allows WordPress administrators to manage multiple sites from a centralized dashboard. Compromised credentials would give attackers broad access to client websites, enabling them to inject malware, steal data, or modify site content. The Attack Method The campaign works by bidding on search terms related to ManageWP. When users click the ads, they land on fraudulent pages mimicking the official login interface. Users entering their credentials unknowingly hand them directly to attackers. This technique exploits the trust users place in Google's ad system. Many people assume sponsored results are legitimate, making them less likely to scrutinize URLs or warning signs. Scope and Risk The attack specifically targets users managing WordPress sites through ManageWP, a popular choice for agencies and freelancers handling multiple client sites. A single compromised account could expose dozens of websites. GoDaddy has not publicly confirmed the scale of the campaign or whether customer accounts have been compromised. The company typically relies on users to report suspicious activity. Recommended Actions ManageWP users should verify they're on the legitimate site by checking the URL directly rather than clicking ads. Bookmarking the official login page eliminates reliance on search results. If you've recently entered credentials on an unfamiliar page, change your ManageWP password immediately and enable two-factor authentication. Review account activity for unauthorized access or changes. This attack underscores the vulnerability of ad-based phishing. Google Ads' accessibility means attackers can reach high-value targets with minimal barriers. While Google removes malicious ads when detected, the lag between discovery and removal creates opportunity for attackers.

■ SOURCES

Bleeping ComputerBleeping ComputerBleeping ComputerHacker News

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Cybercriminals have transformed DDoS attacks into a polished, commercialized service complete with pricing tiers, customer support, and reseller programs. The DDoS-as-a-Service market has evolved from basic tools into sophisticated attack platforms.

YESTERDAYIndustry Desk

Microsoft faced backlash after threatening a security researcher with criminal investigation, reigniting debate over software vulnerability disclosure practices and corporate responsibility.

YESTERDAYSecurity Desk

Google is deploying Device Bound Session Credentials (DBSC) to all Chrome users, a security feature designed to prevent account takeovers by protecting session cookies from theft.

YESTERDAYIndustry Desk

Dutch authorities have dismantled a major botnet comprising 17 million infected devices and seized over 200 servers hosting the operation at a local provider.

YESTERDAYSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.