Right here’s how you can keep away from being hit by fraudulent web sites that scammers can catapult on to the highest of your search outcomes
10 Apr 2025
•
,
4 min. learn

When was the final time you looked for one thing utilizing Google Search, Bing or one other gateway to the countless expanse of the web? What a foolish query, proper? It might have been simply moments in the past and maybe it’s even the way you landed on this blogpost.
Others looking out on-line, nonetheless, could encounter much less favorable outcomes. How so? Our behavior of blindly trusting and clicking on high search outcomes has grow to be so predictable that it may be subverted and turned in opposition to us.
Rigging the sport
Cautionary examples aren’t exhausting to come back by, and I recall one that’s too quirky to not point out: some Australians who not too long ago looked for one thing as innocuous because the legality of Bengal cats within the nation didn’t obtain simple info on pet laws; as a substitute, they unwittingly ran the chance of having their information stolen following a series of occasions that began with a click on on a high search engine consequence.
However even when you’re not a cat fancier, you must know that even a easy search question could breed bother. Some cybercriminals have for years been utilizing strategies that may push malicious web sites dressed as much as look legit into the highest of individuals’s search outcomes, usually leveraging both website positioning poisoning (also called black hat website positioning) or, much more generally, malicious search advertisements.
One refined instance of ‘website positioning fraud as a service’ was uncovered by ESET researchers in 2021 after they discovered a beforehand undocumented server-side trojan that manipulated search engine outcomes by hijacking the status of the web sites it compromises. Comparable campaigns have been noticed once more simply weeks in the past.
In one other instance, ESET researchers recognized a marketing campaign that deployed advertisements in Google search outcomes main victims to phony web sites that seemed equivalent to these of standard software program, similar to Firefox, WhatsApp, or Telegram. The tip purpose was to realize full management of the compromised gadgets.

The dangers aren’t misplaced on Google, in fact. In accordance with its newest Advertisements Security Report, in 2023 the corporate “blocked or eliminated over 5.5 billion advertisements, barely up from the prior 12 months, and suspended 12.7 million advertiser accounts, almost double from the earlier 12 months.”
Some threats nonetheless slip by way of, nonetheless. Which is why it pays to know concerning the dangers concerned in each natural and paid search outcomes, and how you can separate the wheat from the chaff.
Hidden in plain sight
The latest meteoric rise of AI instruments, for one, has created new looking grounds for scammers, sparking schemes the place fraudsters purchased advertisements for counterfeit ChatGPT websites that redirected folks to web sites harvesting bank card particulars. The positioning beneath displayed logos of precise OpenAI companions, presumably duping even many tech-savvy victims. A lot the identical factor occurred with different AI instruments, together with most not too long ago when DeepSeek burst onto the scene.

ESET researchers in Latin America not too long ago noticed a classy marketing campaign that impersonated the La Veloz del Norte bus firm campaigns and focused Argentinians who seek for long-distance bus tickets. Vacationers who entered their info on the imposter web site unwittingly handed over each login credentials and banking particulars to cybercriminals.

Monetary companies symbolize significantly high-value targets. In 2022, ESET researchers in Latin America alerted folks to scams impersonating Mastercard by way of advertisements.

Staying secure
Most of all, do not forget that prominence in search outcomes doesn’t routinely equate to legitimacy. Additionally, chances are high excessive that many individuals don’t at all times distinguish between natural outcomes and advertisements, and criminals reap the benefits of this particularly by way of malvertising campaigns geared toward individuals who, for instance, seek for software program.
In some circumstances, fraudsters could register a typosquatting or similar-looking top-level area to that of the software program writer with the intention to dupe the sufferer, as was the case right here with telegraem[.]org. Which is why you must keep away from blindly clicking on no matter seems on the high of your search web page. As a substitute, look at the URLs meticulously and look out for any indicators that one thing is amiss. Apply the identical stage of scrutiny when you’re utilizing Google’s AI search options, as scammers are continuously evolving their strategies and discover new methods of selling web sites that push scams and malware.
Defend your digital accounts with sturdy and distinctive passwords or passphrases, in addition to with two-factor authentication. Use respected safety software program that may determine and block connections to malicious domains, thus offering an extra layer of safety in opposition to misleading search outcomes.
Additionally, Google itself presents instruments to examine the outcomes, similar to accessing particulars by clicking the three dots adjoining to sponsored listings, which may expose discrepancies between claims and the true identification. For those who suspect that you have encountered a dodgy web site, you possibly can report it to Google.
Conclusion
We’ve all carried out it 1,000,000 instances: typed a question, scanned outcomes, clicked on considered one of them, ‘obtained our fill’, and moved on. And though basic engines like google more and more compete with the likes of ChatGPT and AI-generated search summaries, the basic search-and-click routine is unlikely to go anyplace any time quickly. Previous habits die exhausting, and the dangers aren’t going anyplace, both. Search fastidiously.