When someone on your team searches Google for a program to install, or a login page for a supplier, the first thing they usually see is an ad — marked “Sponsored,” sitting right at the top. Most people click it without thinking twice, because the top result is normally the one they were after.
Scammers are counting on exactly that. They buy search ads using the names of trusted companies and popular software, so their fake page shows up above the real one — and your team clicks it assuming it’s official.
It’s called malvertising, short for malicious advertising. A scammer buys a search ad for a term people already trust — your bank’s name, a Microsoft login, a common program like a PDF reader. The ad looks completely ordinary, carrying the real brand name and a web address that reads correctly at a glance.
Click it, and you land on a page built to be a near-perfect copy of the real one. Sometimes it prompts a login and hands your username and password directly to the scammer. Other times it offers the download you came for, and what actually installs is malware instead of the real program.
They sit above the genuine result, so they’re the first thing anyone sees. They carry the real company’s name and a URL that looks right on a quick glance. And because they show up on a search your own employee started, they don’t register as suspicious the way a random email or text message would.
Attackers have also gotten skilled at slipping past the review process built to catch them — showing a clean, harmless version of the page to reviewers while sending everyone else to the real, malicious one, so the ad passes review and keeps running.
Very. In its 2025 Ads Safety Report, Google said it blocked or removed more than 8.3 billion policy-violating ads, suspended nearly 25 million advertiser accounts, and took down over 600 million ads tied directly to scams. Google also noted that criminals are now using AI to churn out fake ads faster than ever.
Security researchers have documented scam search ads impersonating well-known software like VLC, 7-Zip, and CCleaner — even Google’s own apps — with downloads that installed password-stealing malware. This isn’t some obscure corner of the internet. It shows up on the everyday searches your New York team runs constantly.
The risk shows up in two everyday moments: downloading software, and logging in. Someone searches for a tool, clicks the top ad, and installs something that quietly harvests whatever passwords are saved in the browser. Or someone searches “Microsoft 365 login” or their bank, clicks the ad instead of the real result, and types credentials straight into a fake page.
Either way, the underlying problem is info-stealing malware. Once it’s on a device, it can lift saved passwords, browser cookies, and active session tokens — which can get an attacker straight into an account even with MFA turned on, since a stolen session token can bypass the login step altogether.
Scroll past sponsored results — ads sit at the top, marked “Sponsored” or “Ad,” with the genuine site usually just below in the normal listings. Never download software from an ad; type the maker’s address in directly, or use the regular, non-ad result. Bookmark the sites people log into most — banking, Microsoft 365 — so there’s no need to search each time. Keep devices and browsers current, and make sure everyone actually knows this pattern exists. Once people know the top result can be a trap, they tend to stop clicking it.
If your team already runs multi-factor authentication and firewall protection, that’s a solid second layer once a mistake happens — but skipping sponsored results by habit is what stops the click before it starts. It’s exactly the kind of scenario worth building into ongoing security awareness training, since scammers lean on it more every quarter.
Aren’t ads at the top of Google reviewed and safe?
Google reviews ads and removes billions that break the rules, but scammers still slip through by showing reviewers a clean page while sending everyone else to the malicious one. A “Sponsored” label doesn’t guarantee the destination is safe.
What exactly is malvertising?
Short for malicious advertising — scammers buying online ads, often on trusted brand names, to route people to fake sites that steal logins or install malware.
How do I download software safely?
Go to the maker’s official site by typing the address in yourself, or use the regular (non-ad) search result. Never download from a sponsored ad, and don’t trust anything that arrived through one.
What should someone do if they clicked a scam ad?
If they only viewed the page, close it without entering anything. If they typed a password, change it and turn on MFA right away. If they downloaded and ran a file, disconnect the device from the network and have your IT provider check it for info-stealing malware.
Does an ad blocker help?
It can — a reputable one hides many sponsored results before anyone gets the chance to click. It’s not a complete fix by itself, so keep the habits above in place too.
Prepared by the EB Solution team — cybersecurity and managed IT services for businesses across the New York area. Want your team trained on this before it costs you something? Reach out to EB Solution and we’ll build it into your security awareness program.