The reported abuse of Google Ads for GoDaddy ManageWP phishing is a reminder that phishing has moved far beyond suspicious emails. Attackers are now abusing search ads and trusted brand names to place fake login pages directly in front of users who are actively looking for legitimate services.
As per public reporting, the campaign targeted ManageWP credentials through sponsored Google search results. The phishing page used an adversary-in-the-middle approach, capturing credentials and 2FA codes in real time, allowing attackers to access ManageWP accounts that may control multiple WordPress websites.
This is especially concerning because platforms like ManageWP are used to administer many websites from a single console. A single compromised account can potentially expose several customer websites, turning one phished login into a much larger operational and reputational issue.
The key lesson is simple: users may trust the search result, but attackers are increasingly buying their way above the real one. Because apparently even “sponsored” now needs a security inspection.
A phishing campaign delivered through Google sponsored search results is targeting credentials for ManageWP, GoDaddy's platform for managing fleets of WordPress websites. [...]
Source: Hackers abuse Google ads for GoDaddy ManageWP login phishing via Bleeping Computer — published 06 May 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.