The #malvertising campaigns via Google Ads are not just about software downloads and scams. They also include phishing for popular password managers such as 1Password.

The differences are so subtle, most people will fall for it.

Real URL:
https://my[.]1password.com/signin
Phishing URL:
https://my1pasword[.]com/signin

@malwareinfosec the issue starts with url bar = search bar. If i type apple.com i want to load apple.com not search google for appke.com to then stumble on fakeapple.com etc
@afink @malwareinfosec Then take Google out of your search engine list, and deselect the preference to complete or correct URLs.
@thespoonless @afink @malwareinfosec that’s great and all but try telling that to EVERYONE USING GOOGLE!