
Right here’s tips on how to keep away from being hit by fraudulent web sites that scammers can catapult on to the highest of your search outcomes
10 Apr 2025
•
,
4 min. learn

When was the final time you looked for one thing utilizing Google Search, Bing or one other gateway to the countless expanse of the web? What a foolish query, proper? It could have been simply moments in the past and maybe it’s even the way you landed on this blogpost.
Others looking on-line, nevertheless, might encounter much less favorable outcomes. How so? Our behavior of blindly trusting and clicking on prime search outcomes has turn into so predictable that it may be subverted and turned in opposition to us.
Rigging the sport
Cautionary examples aren’t exhausting to return by, and I recall one that’s too quirky to not point out: some Australians who lately looked for one thing as innocuous because the legality of Bengal cats within the nation didn’t obtain easy data on pet rules; as an alternative, they unwittingly ran the chance of having their information stolen following a series of occasions that began with a click on on a prime search engine consequence.
However even should you’re not a cat fancier, it’s best to know that even a easy search question might breed hassle. Some cybercriminals have for years been utilizing methods that may push malicious web sites dressed as much as look legit into the highest of individuals’s search outcomes, sometimes leveraging both web optimization poisoning (also called black hat web optimization) or, much more generally, malicious search adverts.
One subtle instance of ‘web optimization fraud as a service’ was uncovered by ESET researchers in 2021 after they discovered a beforehand undocumented server-side trojan that manipulated search engine outcomes by hijacking the popularity of the web sites it compromises. Related campaigns have been noticed once more simply weeks in the past.
In one other instance, ESET researchers recognized a marketing campaign that deployed adverts in Google search outcomes main victims to phony web sites that regarded similar to these of standard software program, corresponding to Firefox, WhatsApp, or Telegram. The tip aim was to achieve full management of the compromised units.

The dangers aren’t misplaced on Google, in fact. Based on its newest Adverts Security Report, in 2023 the corporate “blocked or eliminated over 5.5 billion adverts, barely up from the prior yr, and suspended 12.7 million advertiser accounts, practically double from the earlier yr.”
Some threats nonetheless slip by, nevertheless. Which is why it pays to know concerning the dangers concerned in each natural and paid search outcomes, and tips on how to separate the wheat from the chaff.
Hidden in plain sight
The latest meteoric rise of AI instruments, for one, has created new searching grounds for scammers, sparking schemes the place fraudsters purchased adverts for counterfeit ChatGPT websites that redirected individuals to web sites harvesting bank card particulars. The location under displayed logos of precise OpenAI companions, probably duping even many tech-savvy victims. A lot the identical factor occurred with different AI instruments, together with most lately when DeepSeek burst onto the scene.

ESET researchers in Latin America lately noticed a classy marketing campaign that impersonated the La Veloz del Norte bus firm campaigns and focused Argentinians who seek for long-distance bus tickets. Vacationers who entered their data on the imposter web site unwittingly handed over each login credentials and banking particulars to cybercriminals.

Monetary companies signify significantly high-value targets. In 2022, ESET researchers in Latin America alerted individuals to scams impersonating Mastercard by adverts.

Staying protected
Most of all, keep in mind that prominence in search outcomes doesn’t robotically equate to legitimacy. Additionally, likelihood is excessive that many individuals don’t all the time distinguish between natural outcomes and adverts, and criminals make the most of this particularly by malvertising campaigns geared toward individuals who, for instance, seek for software program.
In some instances, fraudsters might register a typosquatting or similar-looking top-level area to that of the software program writer as a way to dupe the sufferer, as was the case right here with telegraem[.]org. Which is why it’s best to keep away from blindly clicking on no matter seems on the prime of your search web page. As a substitute, study the URLs meticulously and look out for any indicators that one thing is amiss. Apply the identical degree of scrutiny should you’re utilizing Google’s AI search options, as scammers are continually evolving their strategies and discover new methods of selling web sites that push scams and malware.
Shield your digital accounts with sturdy and distinctive passwords or passphrases, in addition to with two-factor authentication. Use respected safety software program that may determine and block connections to malicious domains, thus offering a further layer of safety in opposition to misleading search outcomes.
Additionally, Google itself presents instruments to examine the outcomes, corresponding to accessing particulars by clicking the three dots adjoining to sponsored listings, which might expose discrepancies between claims and the true id. For those who suspect that you have encountered a dodgy web site, you’ll be able to report it to Google.
Conclusion
We’ve all performed it 1,000,000 occasions: typed a question, scanned outcomes, clicked on one in every of them, ‘received our fill’, and moved on. And though traditional search engines like google and yahoo more and more compete with the likes of ChatGPT and AI-generated search summaries, the traditional search-and-click routine is unlikely to go wherever any time quickly. Outdated habits die exhausting, and the dangers aren’t going wherever, both. Search fastidiously.