In recent years, search engine marketing platforms have become a playground for cybercriminals. Phishing attacks are no longer confined to shady emails or suspicious links; they’re now appearing as top results in Google, Bing, Facebook, and X ads.
It’s a growing, underreported threat. And it’s getting smarter.
In this post, we’ll explore how cybercriminals exploit the trust users place in search engine results. Through real-world examples, particularly in the SaaS space, we’ll show how threat actors leverage user behavior to maximize their success.
With attackers evolving their tactics and scaling their reach, it’s time to take a closer look at how these phishing operations work—and what we can do to stop them.
Exploiting Google’s Ad Review Process
Cybercriminals are increasingly bypassing Google’s ad review systems by exploiting a critical loophole. Here’s how it works:
- They submit ads that appear completely benign during the review process.
- Once approved, they silently modify the tracking templates, without changing the visible destination URL.
- The result: users are redirected to phishing sites that mimic legitimate websites, often indistinguishable from the real thing.
These malicious ads can remain live for hours, sometimes longer, before they’re flagged and removed. That delay is more than enough for attackers to harvest credentials, payment data, or other sensitive information at scale.
It’s a persistent, evolving tactic, and a stark reminder of the limits of automated ad verification.
Phishing-as-a-Service (PhaaS): A Growing Threat
Phishing is no longer the domain of lone hackers. It’s become a full-fledged service economy.
- Phishing kits are sold online like IKEA™ furniture: ready-to-assemble, complete with step-by-step instructions.
- Attackers can now launch entire campaigns with startling efficiency: registering domains, creating advertiser accounts, and running ads just like any legitimate marketing team would.
- Once the data is harvested, it’s monetized through the same underground marketplaces that supplied the phishing tools in the first place.
It’s fast. It’s scalable. And it’s dangerously accessible. Fraud at scale, available to anyone with a credit card.
Poisoning Search Engines with SEO
Beyond paid ads, attackers are also manipulating organic search results. SEO poisoning is an increasingly common tactic used to push malicious sites higher in rankings by mimicking legitimate SEO strategies.
Common techniques include:
- Typosquatting: Registering lookalike domains like goggle.com or paypai.com.
- Keyword stuffing & cloaking: Showing one version of a page to search engines and a different one to users.
- Private link networks: Creating fake, interlinked websites to artificially inflate search rankings.
These methods exploit the trust users place in top search results, leading them directly to scams, malware, or phishing pages.
That trust is now a weapon.
Hospitality in the Crosshairs
The hospitality industry is especially vulnerable; built on online bookings and customer trust, it’s become a prime target for phishing campaigns.
A typical attack chain looks like this:
- Research: Cybercriminals identify trending search terms and high-traffic booking-related queries.
- Setup: They clone legitimate hotel websites and subtly modify them for malicious use.
- Optimization: Using SEO poisoning and paid ads, they push these fake sites to the top of search rankings.
- Distribution: Victims are lured through Google Ads, organic results, or social platforms.
- Monetization: Harvested data, credit card info, login credentials, and personal details, are sold or used for fraudulent transactions.
The user thinks they’re booking a room. They’re actually handing over their identity.

Economics of Multi-Chain Attacks
The most effective cyber campaigns today combine phishing with SEO poisoning. These multi-chain attacks are designed for maximum reach and impact. They’re costly to execute but generate substantial returns, while causing severe financial and reputational damage to their victims.
Fighting Back: Where to Start
Combating these sophisticated threats requires more than just ad reviews or spam filters. A multi-faceted approach is essential, starting with shared responsibility across all parties:
- Platforms must invest in faster detection and response mechanisms to catch these attacks before they escalate.
- Businesses need to closely monitor their digital risk footprints to spot vulnerabilities and mitigate exposure.
- Users must be better educated on identifying phishing attempts and distinguishing between real ads and malicious domains.
For security teams, effective mitigation lies in partnerships and integrated solutions:
- Digital risk monitoring and malicious domain takedown services to stay ahead of emerging threats.
- Anomaly detection driven by industry-specific threat intelligence to quickly identify suspicious patterns.
- Security as a product partner: Integrating Security Operations Centers (SOCs) with product teams to streamline fraud reporting and automate incident response for faster action.
Tools Worth Knowing
- HonestAds GitHub Tool: A script that helps expose Google Ads transparency data.
- Google Ads Transparency Center: Check if your domains are being targeted by malicious ads.
Conclusion: Staying Ahead of Cyber Threats
Cybercriminals are constantly adapting, and their tactics, like exploiting ad reviews and SEO poisoning, demand our attention. At Mews, we’re committed to staying ahead of these threats, ensuring our developers and users are protected. By understanding these risks and taking proactive steps, we can better safeguard our digital spaces.
This post is based on a talk presented at Bsides Prague 2025. You can find the full program here.