Search Ad Impersonation & Malvertising Scams
Scammers buy sponsored search ads that sit above the genuine result for a bank, brand, or download, routing users to lookalike phishing pages, fake support numbers, or trojanised installers.
Last reviewed: 27 July 2026
What this scam is
Search ad impersonation, often called malvertising, exploits a gap most people never think about: the sponsored results at the top of a search page are paid placements, not vetted endorsements. A search engine ranks its organic results by relevance and reputation, but a sponsored slot simply goes to whoever paid and passed light automated screening. Scammers exploit this by buying ads that impersonate a bank, a well-known brand, a government service, or a popular software download, and engineering them to appear above — sometimes indistinguishable from — the genuine organisation's own result. Click the ad and you land somewhere the scammer controls: a pixel-perfect lookalike login page that harvests your credentials, a fake "customer support" phone number that connects you to a fraudster, or a download button that delivers a trojanised installer bundling malware. The victim did everything they were taught — searched for the real company by name rather than following an email link — which is exactly why this scam is so effective and why fraud agencies have warned about it since 2022.
How it works
The scammer registers with a search or social advertising platform, sometimes through a compromised or throwaway account, and buys ads targeting the exact terms people use to reach a real service: a bank's name, "download [software]", "[brand] customer support", "[airline] refund". The ad copy mimics the genuine brand, and the displayed link is often styled to look like the real domain while the actual click destination is a lookalike the scammer controls — a near-miss URL, a hyphenated variant, or a hosting subdomain. From there the con branches. Brand and bank impersonation ads lead to phishing pages that capture logins, card numbers, and one-time codes in real time. Poisoned software-download ads serve installers that look like the real app but carry infostealers or remote-access malware — a fast-growing branch, because people trust a "top result" for a download. Fake support-number ads display a phone number instead of a link; call it and a "technician" talks you into paying, sharing codes, or granting remote access. Malicious campaigns are frequently rotated and cloaked — showing reviewers a clean page while sending real users to the trap — so a policy-violating ad can run for hours before removal.
Why this scam works
It hijacks a good habit. Users have been trained never to trust links in unsolicited emails, so they open a browser and search for the company by name — and land on a scammer's ad believing they navigated there safely. The top position reads as endorsement, when it only means someone paid. The destination pages are pixel-perfect clones, so nothing feels wrong until credentials or money are already gone. The download variant is especially potent because installing software from a "top result" feels routine, and the app often does install and work, hiding the malware. Fake-support ads exploit a person already in distress — locked out, defrauded, or with a broken device — who is grateful to find a number quickly. The distinction that matters most: search results are two layers stacked together, paid and organic, and the fact that you typed the name yourself vouches for your intent, never for the ad you clicked.
Common red flags
- A sponsored/ad label above the result you were about to click
- A URL that is a near-miss of the real domain — extra words, hyphens, or an unusual ending
- A login or one-time-passcode prompt appearing right after you clicked an ad
- A download button reached through an ad rather than the vendor's own site
- A 'customer support' phone number shown directly in an ad
- Being told to grant remote access, install a tool, or read out a code to fix a problem
- Pressure to act immediately before your account is 'suspended' or 'compromised'
Sanitized example messages
Illustrative, sanitized examples. Personal details are replaced with placeholders such as [phone number] and [fake link].
Official [Your Bank] Login — Secure Access. Verify your account now to avoid suspension. (sponsored) yourbank-secure-login.com
Download [Popular App] — Free Official Installer 2026. Fast, safe, verified. (sponsored) getapp-download-official.net
[Brand] Customer Support — 24/7 Help Line. Call now: +1-800-000-0000 to resolve login issues. (sponsored)
Your download is ready. To complete setup, allow the installer to make changes and enter the code our technician gives you.
How to verify before you act
Treat the ad block as untrusted no matter how official it looks. Scroll past the sponsored results to the genuine organic result, or better, type the official domain directly into the address bar yourself — for a bank or government service, use a bookmark or the number and web address printed on your card, statement, or official correspondence. Before clicking any result, read the actual URL carefully: impersonators rely on near-miss domains, extra words, hyphens, and unusual endings. Download software only from the vendor's official site reached the same way, or from an official platform app store, never from a search ad's download button. Never phone a "support" number found in an ad; get support contacts from the official website, your card, or the product packaging. If a page asks for a login or a one-time passcode moments after you clicked an ad, stop — a genuine site you reached yourself will not depend on you having come through an advertisement.
Payment methods used
- Bank transfer
- Credit card
- Payment apps
- Gift cards
- Cryptocurrency
Who is usually targeted
- Online banking customers
- People searching for tech or customer support
- Software and app downloaders
- Shoppers searching for a brand
What to do immediately
- If you entered banking or card details, call your bank using the number on your card and freeze the account or cards immediately
- If you gave a one-time passcode or password, change that password now and revoke access from other devices and active sessions
- If you installed something or granted remote access, disconnect from the internet and run a full security scan, or seek professional help to check for malware
- Report the malicious ad to the search or ad platform and report the impersonation to the real company
- Report the fraud to your national fraud or cybercrime service and, if money moved, ask your bank about recovery
- Watch statements and accounts closely for unauthorised charges, new logins, or password-reset attempts
How to prevent it
- Ignore the sponsored ad block entirely; scroll to the organic result or type the official domain into the address bar yourself
- Reach banks and government services through bookmarks or the address printed on your card, statement, or official letters
- Download software only from the vendor's official site or an official app store, never from a search ad's download button
- Read the full URL before clicking — impersonators use near-miss domains, hyphens, and extra words
- Never call a 'customer support' number found in a search ad; get support details from the official site or product packaging
- Use a reputable ad blocker and keep browser and security software updated to reduce malicious-ad exposure
Evidence to preserve
- Screenshots of the ad, its sponsored label, and the exact search term used
- The full destination URL and any lookalike login or download page
- The phone number, email, or account details the scammer used
- Payment records, downloaded file names, and any remote-access tool you were asked to install
Where to report it
- Action Fraud (UK) — UK national fraud & cybercrime reporting centre
- FTC ReportFraud (US) — US Federal Trade Commission fraud reports
- FBI IC3 (US) — US Internet Crime Complaint Center
- Scamwatch (Australia) — Australian competition & consumer reporting
- Your bank's fraud line — Use the number on the back of your card or in your banking app — never a number the caller gives you
Always verify reporting routes and emergency contacts on the official government or agency website for your country.
Frequently asked questions
Aren't the ads at the top of search results checked by the search engine?
Only lightly, and not for legitimacy in the way people assume. A sponsored slot goes to whoever pays and passes automated screening, not to the most trustworthy organisation. Scammers slip through with cloaked pages that show reviewers a clean site while sending real users to the trap, so a policy-violating ad can run before removal. The top position signals that someone paid for it — nothing more. Treat the ad block as unverified and rely on the organic result or the official domain instead.
I only searched for my bank's name and clicked the first result. How could that be a scam?
Because the first result was likely an ad, not your bank. This scam specifically targets people doing the right thing — searching by name rather than following an email link. The sponsored result sat above the genuine one and looked identical, but the click went to a lookalike page the scammer controlled. Searching for the real name protects you from phishing emails, but it does not protect you from paid impersonation. Scroll past the ads or type the official web address yourself.
Is it really dangerous to download software from a search ad?
Yes, and it is one of the fastest-growing forms of this scam. A poisoned download ad serves an installer that often looks and even works like the real app, while quietly bundling malware such as an infostealer or remote-access tool. Because the file came from a 'top result', people trust it and click through the security warnings. Always download from the vendor's official website, reached by typing the address yourself, or from an official app store — never from a search ad's download button.