---
title: "Phishing in the age of AI: sponsored links on Google"
date: 'Mon, 05 Oct 2026 13:02:29 -0400'
author: jmcouillard
image: https://jmcouillard.com/sites/default/files/styles/fixed_width_1200/public/articles/108/fleurs.jpg.webp?itok=XBGNSdDs
published: true
type: blog
url: https://jmcouillard.com/en/blog/phishing-age-ai-sponsored-links-google
language: en
id: 108
---

A client's project required greater visibility into events, errors, and logs. The chosen platform (a popular website builder) didn't allow log retention and offered a connection to Google Cloud Monitoring to address this need.

Like most people (I assume), to access the Google Cloud platform, I simply typed "google cloud" into my browser's address bar.

That's where an unlikely phishing scenario began, and the was pretty convincing. Again, I was at the final stage when I thought : why wasn't 1Password behaving as expected?

## Real-life case timeline

### 1. Need to use a Google Cloud service

To support a client in debugging their web transaction solution, logs and errors visibility is essential. I connected to the client's platform (Wix), and the recommendation for persistent logs was to connect it to Google Cloud Monitoring. I followed the steps to connect it and completed the process without any issues.

### 2. Using the address and search bar
 
Once the platform is connected, I want to access the Google Cloud Console to view the logs. So I type "google cloud" into the address bar of my browser (Brave), which performs the related search on Google.

![Search](https://jmcouillard.s3.amazonaws.com/public/jmcouillard/phishing2-search.jpg)

### 3. Accessing the Google Cloud public website

I click on the first link that appears, since I expect such a search should inevitably lead me to the right place.

It's a sponsored link, which leads to a subdomain of `google.com`.

![Sponsored link](https://jmcouillard.s3.amazonaws.com/public/jmcouillard/phishing2-sites-google.jpg)

### 4. Connecting to the platform

As expected, I arrive at the public website for Google's cloud services. But strangely, I'm no longer logged in. I click the "Sign in" button and am redirected to the Google login interface.

I don't see any options for my usual saved accounts.

![Login - Step 1](https://jmcouillard.s3.amazonaws.com/public/jmcouillard/phishing2-login-step1.jpg)

![Login - Step 2](https://jmcouillard.s3.amazonaws.com/public/jmcouillard/phishing2-login-step2.jpg)

### 5. Doubt and taking a step back

I realize that 1Password doesn't offer to authenticate me with my access key. The site forces to login with a password, and again, 1Password offers no option.

So I confirm the address in the address bar, since that's what 1Password bases its suggestions on.

That seems fine... google... .com...

Then suddenly, the difference becomes clear... Googlé ? .us.com ?

![URL](https://jmcouillard.s3.amazonaws.com/public/jmcouillard/phishing2-url-shadow.png)

## What's happening in the background

### 1. Sponsored Link on Google Sites

The subterfuge begins with the sponsored link. The link goes unnoticed because it uses an official Google domain... but it's actually a well-executed clone hosted on the Google Sites platform (`sites.google.com`).

### 2. Redirection

When clicking **Login**, the victim is redirected to another site (`googlé.us.com`) which, again, tries to remain undetected. The URL attempts to look like the official domain as closely as possible. And the website is a rather faithful copy of Google's platforms, especially for someone usually using them in English.

### 3. Entering your Google account ID

You then enter your Google ID to begin the verification process.

To add credibility, the fake website even appears to redirect the login attempt to the real Google service. This way, they can fake account verification, ensuring that an account actually exists before proceeding.

![Account verification](https://jmcouillard.s3.amazonaws.com/public/jmcouillard/phishing2-login-validate.jpg)

This undoubtedly helps to build trust in the malicious website.

### 4. Filling the credential field

We are forced to enter our password (other login options, such as access keys, are not accepted). If we enter it, the impact begins:

- If there is no 2FA, the hacker has full access to the email account. They can then use it to access a multitude of services, since email accounts are often used as a 2FA/MFA method.

- The entered email and password combination can be added to a list that can be exploited on other services. Imagine if you used the same username and password combination on another service: this combination is known to hackers and could potentially be sold to "everyone."

## Who's to blame?

I believe Google played a major role in making this attack possible. First, the purchase of sponsored links doesn't seem to be adequately monitored. A keyword as important as "Google Cloud" should be subject to much more rigorous checks. And, in the age of AI, it seems to me that it would be possible to detect website clones on its own platforms: a copy of a public Google site on a Google website platform seems perfectly detectable.

### googlé.us.com

How can a domain so close to Google's be exploited? First, domains with accented characters are a more recent addition. They are heavily exploited by hackers since large companies cannot reserve all the available variations of their domains. Similarly, the TLD (us.com) is also recent and exploitable due to its proximity to .com.

> The .US.COM is a sub-domain of .COM and is presented as an unofficial alternative for United States. Registering your domain name under this extension can be done for defensive purposes.

## Who to thank?

This time, we can certainly thank 1Password, because it was its predictable and rational behavior that raised my suspicions. Password managers are essential for maintaining proper digital hygiene. They saved me from a lot of trouble once again!
