When you search Google for a program to download or a website to log into, the first thing you see is usually an ad. It sits at the top, marked "Sponsored," and most people click it without a second thought, because the top result is normally what you wanted.
Scammers count on that. They buy ads in the names of trusted companies and popular software, so their fake site appears right at the top, above the real one, and you click it thinking it's the official page. It looks real!
The trick is called malvertising, short for malicious advertising. A scammer buys a search ad for a term people trust, like the name of your bank, a Microsoft login, or a common program such as a PDF reader or a video player. The ad looks normal, with the real brand name and a web address that looks right (for example, if you are looking for Chase bank's website, you Google it - instead of chase.com, which is the correct link, a malvertising link might send you to chasebank.com, which is not the official Chase website).
When someone clicks it, they land on a page built to look exactly like the real one. Sometimes that page asks you to log in and hands your username and password straight to the scammer. Other times it offers the software you were after, and the download installs malware instead of the real program.
These ads are convincing. They sit above the real result, so they're the first thing you see. They use the real company's name and a web address that looks right. And they show up on a search you started yourself, so they don't feel as suspicious as a random email or text would.
Attackers have also gotten good at hiding from the checks meant to stop them. They show a clean, harmless page to the ad reviewers and the real, malicious page to everyone else, so the ad can pass review and still do damage.
Very. In its 2025 Ads Safety Report, Google said it blocked or removed more than 8.3 billion ads that broke its rules, suspended 24.9 million advertiser accounts, and took down 602 million ads tied to scams. Google also noted that criminals are now using AI to make fake ads faster.
Security researchers have found scam search ads pretending to be well-known programs like VLC, 7-Zip, and CCleaner, and even Google's own apps, with downloads that installed password-stealing malware. These show up on the everyday searches your team runs.
For a business, the risk comes up in two everyday situations: downloading software, and logging in.
When someone downloads software, they search for a tool, click the top ad, and install something that steals the passwords and logins saved in their browser.
When someone logs in, they search for "Microsoft 365 login" or their bank, click the ad rather than the official link, and type their username and password straight into a fake page.
In both cases, the problem is info-stealing malware. Once it's on a machine, it can steal saved passwords, browser cookies, and session tokens, which can get an attacker into accounts even when multi-factor authentication is switched on.
Scroll past the sponsored results. The ads sit at the top, marked "Sponsored" or "Ad." The real website is usually just below, in the normal results.
Article used with permission from The Technology Press.