Why You Should Scroll Past the First Result on Google

Free seo search engine optimization google illustration

Summary: Scammers buy ads on Google and other search engines using the names of trusted brands and software, so their fake site shows up at the very top, above the real one. Click it and you can land on a fake page that steals your login or installs malware. You can avoid nearly all of it by skipping the sponsored results and going to the real website yourself.

When you search Google for a program to download or a website to log into, the first thing you see is usually an ad. It sits at the top, marked “Sponsored,” and most people click it without a second thought, because the top result is normally what you wanted.

Scammers count on that. They buy ads on the names of trusted companies and popular software, so their fake site appears right at the top, above the real one, and you click it thinking it’s the official page.

How the scam works

The trick is called malvertising, short for malicious advertising. A scammer buys a search ad for a term people trust, like the name of your bank, a Microsoft login, or a common program such as a PDF reader or a video player. The ad looks normal, with the real brand name and a web address that looks right.

When someone clicks it, they land on a page built to look exactly like the real one. Sometimes that page asks you to log in and hands your username and password straight to the scammer. Other times it offers the software you were after, and the download installs malware instead of the real program.

Why these ads are so easy to fall for

These ads are convincing. They sit above the real result, so they’re the first thing you see. They use the real company’s name and a web address that looks right. And they show up on a search you started yourself, so they don’t feel as suspicious as a random email or text would.

Attackers have also gotten good at hiding from the checks meant to stop them. They show a clean, harmless page to the ad reviewers and the real, malicious page to everyone else, so the ad can pass review and still do damage.

How common is this?

Very. In its 2025 Ads Safety Report, Google said it blocked or removed more than 8.3 billion ads that broke its rules, suspended 24.9 million advertiser accounts, and took down 602 million ads tied to scams. Google also noted that criminals are now using AI to make fake ads faster.

Security researchers have found scam search ads pretending to be well-known programs like VLC, 7-Zip, and CCleaner, and even Google’s own apps, with downloads that installed password-stealing malware. These show up on the everyday searches your team runs.

What this means for your business

For a business, the risk comes up in two everyday situations: downloading software, and logging in.

When someone downloads software, they search for a tool, click the top ad, and install something that steals the passwords and logins saved in their browser.

When someone logs in, they search for “Microsoft 365 login” or their bank, click the ad rather than the official link, and type their username and password straight into a fake page.

In both cases, the problem is info-stealing malware. Once it’s on a machine, it can steal saved passwords, browser cookies, and session tokens, which can get an attacker into accounts even when multi-factor authentication is switched on.

How to protect your team

  • Scroll past the sponsored results. The ads sit at the top, marked “Sponsored” or “Ad.” The real website is usually just below, in the normal results.
  • Don’t download software from an ad. Type the maker’s web address yourself, or search and use the normal result, then download from the official site.
  • Bookmark the sites you log into. For your bank, Microsoft 365, and other important accounts, use a saved bookmark instead of searching each time.
  • Keep devices and browsers updated. Turn on automatic updates so a bad download is less likely to work.
  • Tell your team this is a thing. Most people have no idea the top result can be a trap, and once they know, they stop clicking it.

Frequently asked questions

Aren’t ads at the top of Google checked and safe?

Google reviews ads and removes billions that break its rules, but scammers still slip through by showing reviewers a clean page and everyone else the malicious one. A “Sponsored” label doesn’t mean the site is safe.

What is malvertising?

Malvertising is short for malicious advertising: scammers buy online ads, often on trusted brand names, to send people to fake sites that steal logins or install malware.

How do I download software safely?

Go to the maker’s official website by typing the address yourself, or search and use the normal (non-ad) result. Don’t download from a sponsored ad, and don’t trust a download that arrives through one.

What should I do if someone clicked a scam ad?

If they only visited the page, close it and don’t enter anything. If they typed a password, change it and turn on MFA. If they downloaded and ran a file, disconnect the device and have your IT provider check it for info-stealing malware.

Does an ad blocker help?

It can. A reputable ad blocker hides many sponsored results, which takes the fake links off the page before anyone can click them. It isn’t a complete fix, so keep the habits above too.

Sources and further reading

If you’d like to give your team a plain rundown of what a scam ad looks like, or tighten how software gets installed on your computers, your IT provider can help with both. And if you don’t have an IT provider, feel free to reach out to us and we’ll help you sort it.

Featured Image Credit

This Article has been Republished with Permission from The Technology Press.

How to Spot a Scam Email Now That They Look Real

Free scam phishing fraud illustration

Summary: Scammers now use AI to write their phishing emails, so the spelling and grammar mistakes that used to give them away are gone. The UK’s National Cyber Security Centre and the FBI both warn that AI makes these messages cleaner, more personal, and harder to spot. The way to catch them now is to look at what an email is asking you to do, because the writing no longer gives anything away.

For years, the advice for spotting a scam email was simple: look for bad spelling and clumsy grammar. A real bank or supplier writes properly, the thinking went, so a message full of mistakes was probably fake. It was easy to teach, and for a long time it worked.

It doesn’t anymore. Scammers now use AI to write their emails, and AI writes cleanly. The typos and awkward phrasing that used to give phishing away are gone, and the messages landing in your team’s inbox read as well as anything from a real company. Worse, they can be written to sound like they came from someone you already know.

Why the old advice stopped working

The spelling-and-grammar tell worked because a lot of scammers were writing in a language that wasn’t their own, and the mistakes showed. AI took that away.

The UK’s National Cyber Security Centre says generative AI can now create convincing phishing lures “without the translation, spelling and grammatical mistakes that often reveal phishing.” The FBI says the same: criminals use AI to limit the grammar and spelling errors that used to mark a message as fake, so it reads as believable. That means the one thing most people were trained to look for no longer tells you much.

Why these emails are so convincing now

  • The writing is clean. A scam email reads like a normal business email, because a machine wrote it in seconds, in whatever tone the attacker asked for.
  • It’s personal. Attackers can feed public details about your company into an AI tool, pulled from your website, your team’s LinkedIn profiles, or a press release, and get a message tailored to you: the right names, the right job titles, and a believable reason to be in touch.
  • There’s more of it. AI makes each message faster to produce, so attackers send far more. The FBI’s Internet Crime Complaint Center added a section on AI to its annual report for the first time, tied to more than 22,000 complaints and nearly $893 million in reported losses.

These days, the scam email isn’t the obvious one anymore. Instead of “Dear customer, your account is suspended,” someone in your finance team gets a message that looks like it’s from a supplier they really deal with, mentions a real project, and asks to update the bank details for the next invoice. It reads exactly like a real supplier email. The only thing wrong is that the supplier never sent it.

Your spam filter won’t catch them all

It’s tempting to assume your email security will handle this. It catches a lot, and you should keep it switched on. But a well-written, personalized email that asks a normal-sounding question doesn’t always look dangerous to a filter, especially when it carries no obvious bad link or attachment. Both the NCSC and the FBI expect AI to push more of these messages through, which is why the last line of defense is a person who knows what to check.

It’s not just email anymore

AI has done the same thing to phone calls and texts. The FBI warns that criminals can clone a voice from a short audio clip, enough to leave a voicemail that sounds like your boss or a family member asking for an urgent payment. The same thing that makes AI emails so convincing makes AI phone scams convincing too. The defense is the same: if a call or voicemail asks for money or logins, hang up and call the person back on a number you already have.

Here are the signs you should still pay attention to

If you can’t trust how an email is written, look at what it’s asking you to do. That’s where the real warning signs are, and AI hasn’t changed them:

  • It asks for money, gift cards, or a payment to a new account.
  • It asks for a login, a verification code, or personal details.
  • It creates pressure: a deadline, a threat, or a “do this now.”
  • It asks you to change the bank details for an invoice or a supplier.
  • It comes with a link or attachment you weren’t expecting.
  • The display name looks right, but the actual email address doesn’t match it.

Every one of these is about what the email is asking for. So the rule to teach your team is simple: when a message is about money, logins, or how you pay someone, slow down before you act.

How to protect your team

  • Check money and login requests another way. If an email asks you to pay a new account or change a supplier’s bank details, call the person on a number you already have. Don’t reply to the email or use a number it gives you.
  • Stop telling staff to watch for bad spelling. Tell them to look at what the email is asking for, and to slow down when it’s about money or logins.
  • Make one rule for payment changes: confirm every change to bank details by phone, even when it’s urgent.
  • Turn on phishing-resistant MFA or passkeys, so a stolen password is harder to use even if someone gets tricked.
  • Make it easy to report a suspicious email and make sure nobody feels silly for checking.
  • Remind the team now and then that scam emails look perfect these days. A quick five-minute chat beats a poster nobody reads.

Frequently asked questions

Can you still spot a phishing email by bad spelling and grammar?

Not reliably. Attackers use AI to write clean, correct emails now, so a message with perfect spelling can still be a scam. Judge it by what it asks you to do.

What are the warning signs that still work?

The request itself: paying money, changing bank details, sharing a login or code, or being pushed to act urgently. Those signs don’t depend on how the email reads.

Is AI-generated phishing really more effective?

Yes. The NCSC and the FBI have both warned that AI makes phishing more convincing and more personal, and the FBI has tied AI to tens of thousands of fraud complaints and hundreds of millions in losses. Cleaner, tailored messages get opened and clicked more often.

Will my spam filter stop AI phishing?

It will catch a lot, and you should keep it on. But a well-written, personalized email with no obvious bad link can still look legitimate to a filter, so don’t rely on it alone. A trained person is the backstop.

What should staff do if they aren’t sure about a message?

Slow down and check through a channel they trust, like calling a known number or asking the person directly. And report it, even if it turns out to be genuine.

Sources and further reading

•  NCSC: The near-term impact of AI on the cyber threat — the UK cyber agency on AI producing phishing lures without the usual spelling and grammar mistakes.

•  FBI IC3: Criminals Use Generative AI to Facilitate Financial Fraud — how criminals use AI-generated text and cloned voices, and how it removes the usual signs of fraud.

If you’d like help teaching your team what to watch for, or turning on phishing-resistant logins so a fooled password doesn’t turn into a break-in, your IT provider can set both up. And if you don’t have an IT provider, feel free to reach out to us and we’ll help you sort it.

Featured Image Credit

This Article has been Republished with Permission from The Technology Press.