When someone on your team searches Google for a program to download, or for the login page of a supplier, the first thing they usually see is an ad — marked “Sponsored,” sitting right at the top. Most people click it without a second thought, because the top result is normally the one you wanted.
Scammers count on exactly that habit. They buy search ads using the names of trusted companies and popular software, so their fake page lands right above the real one — and your team clicks it thinking it’s official.
It’s called malvertising — malicious advertising. A scammer buys a search ad for a term people already trust: your bank’s name, a Microsoft login, a common program like a PDF reader. The ad looks entirely normal, with the real brand name and a web address that reads correctly at a glance.
Click it, and you land on a page built to look exactly like the real one. Sometimes it asks you to log in and hands your username and password straight to the scammer. Other times it offers the download you were after, and what actually installs is malware instead of the real program.
They sit above the real result, so they’re the very first thing anyone sees. They carry the real company’s name and a web address that looks right at a glance. And because they show up on a search your own team started, they don’t feel as suspicious as a random text or email would.
Attackers have also gotten good at slipping past the checks meant to catch them — showing reviewers a clean, harmless page while everyone else gets sent to the real, malicious one, so the ad clears review and keeps running.
Very. In its 2025 Ads Safety Report, Google said it blocked or removed more than 8.3 billion policy-violating ads, suspended nearly 25 million advertiser accounts, and took down over 600 million ads tied to outright scams. Google also flagged that criminals are now using AI to produce fake ads faster than ever.
Security researchers have found scam search ads impersonating well-known tools like VLC, 7-Zip, and CCleaner — and even Google’s own apps — with downloads that installed password-stealing malware. These aren’t obscure corners of the internet. They show up on the everyday searches your Toronto team runs every week.
The risk shows up in two everyday moments: downloading software, and logging in. Someone searches for a tool, clicks the top ad, and installs something that quietly steals whatever passwords are saved in the browser. Or someone searches “Microsoft 365 login” or their bank’s name, clicks the ad instead of the official result, and types their credentials straight into a fake page.
Either way, the real problem is info-stealing malware. Once it’s on a device, it can lift saved passwords, browser cookies, and session tokens — which can get an attacker into accounts even when MFA is switched on, because a stolen session token can skip the login step entirely.
Scroll past the sponsored results — the ads sit at the top marked “Sponsored” or “Ad,” and the genuine site is usually just below in the regular listings. Don’t download software from an ad; type the maker’s address in yourself, or use the normal (non-ad) search result. Bookmark the sites your team logs into regularly — banking, Microsoft 365 — so there’s no need to search and click each time. Keep devices and browsers updated, and make sure everyone knows this is a real thing to watch for. Once people know the top result can be a trap, they generally stop falling for it.
If your team already has security awareness training in place, that’s a solid second layer once someone’s caught the mistake — but the habit of skipping sponsored results is what stops the click from happening at all. Businesses we support through our Vaughan-based IT support team often add this exact scenario to that training, since it’s one of the easiest habits to build.
Aren’t ads at the top of Google reviewed and safe?
Google does review ads and removes billions that break the rules, but scammers still get through by showing reviewers a clean page and everyone else the malicious one. A “Sponsored” label doesn’t mean the destination is safe.
What exactly is malvertising?
Short for malicious advertising — scammers buying online ads, often on trusted brand names, to send people to fake sites that steal logins or install malware.
How do I download software safely?
Go to the maker’s official site by typing the address yourself, or use the regular (non-ad) search result. Never download from a sponsored ad, and don’t trust a download that arrived by way of one.
What should I do if someone clicked a scam ad?
If they only viewed the page, close it and don’t type anything in. If they entered a password, change it and enable MFA immediately. If they downloaded and ran a file, disconnect the device from the network and have your IT provider check it for info-stealing malware.
Does an ad blocker actually help?
It can — a reputable one hides many sponsored results before anyone has a chance to click them. It isn’t a complete fix on its own, so keep the other habits above in place too.
Prepared by the EB Solution team — cybersecurity and managed IT services for businesses across the Greater Toronto Area. Want your team trained on this before it costs you something? Reach out to EB Solution and we’ll build it into your security awareness program.