Malware & deception
Phishing
- Ad Manager API value
- PHISHING
What Google's rule says
The Ad Manager API defines PHISHING as phishing found in the creative or the landing page — one value covering both locations, unlike malware, which is split into two.
What actually causes it
- A landing page collecting credentials behind a login form that imitates another brand.
- A creative dressed as a bank, delivery, tax or account notification.
- A compromised destination serving a credential harvesting page to some visitors.
- A lead-generation form asking for account details it has no reason to need.
How to fix it
Treat it as a security incident on the destination first. If the page is legitimate, the usual trigger is a form asking for credentials that resemble another service's, and the fix is to stop collecting them rather than to reword the creative.
The part that is not obvious
The asymmetry with malware is the tell. Google splits malware into creative and landing page values but keeps phishing as one, which fits how the deception works: a phishing attempt is a single act spread across the ad and the page it leads to, and the ad on its own is rarely the offence. So unlike malware, the enum value will not tell you which end to look at — and unlike most reasons on this list, being the innocent party is common, because a hacked destination implicates every advertiser pointing at it.
Related reasons
Reason name and API value verified against Ad Manager API — CreativePolicyViolation (v202602) on 30 July 2026 (Ad Manager SOAP API v202602). The causes and fix above are practitioner guidance, not Google policy text.