30 September 2026
Why the Top Google Search Result Isn't Always Safe
By Jack Wetson-Catt
Illustration by PabitraKaity on Pixabay
Someone on your team needs a program installed, or needs to log into a supplier's portal. They open Google, type the name, and click the first thing that comes up. Most of the time that's exactly the right instinct: the top result is normally what they were looking for.
Scammers have worked out how to exploit that instinct. They buy the ad space above the genuine result, using the real company's name and a web address that looks close enough to pass, so the first thing a busy employee clicks is the fake one.
What's actually going on
The technique is called malvertising, short for malicious advertising. An attacker buys a paid search ad against a term people already trust, a well-known piece of software, a bank's login page, a supplier's name, and builds a landing page that copies the real one closely enough to fool a quick glance.
Click it, and one of two things usually happens. If you were after software, the download installs malware instead of, or alongside, the program you wanted. If you were logging in, the page simply hands your username and password straight to the attacker.
Ad networks do check what gets submitted, but attackers have got good at getting past that too. A common trick is cloaking: show the ad reviewer a harmless, unrelated page, and show everyone else the real, malicious one once it's live. The ad passes review and keeps running.
Why it works on a genuinely careful team
None of this depends on anyone being careless. Three things make it convincing:
- It sits above the result they were actually looking for, so it's the first thing on the page.
- It carries the real company's name and logo, plus a web address that reads as close enough not to raise an eyebrow.
- It shows up on a search the person started themselves, which feels nothing like a random email or text out of the blue.
This isn't a hypothetical. Fake ads for genuinely popular free tools, including 7-Zip, VLC and CCleaner, have appeared at the top of Google's own search results, leading to downloads that installed information-stealing malware instead of the real program. It's a documented, recurring pattern, not a one-off.
How big a problem this actually is
Google's own 2025 Ads Safety Report puts a number on the scale of it: the company blocked or removed more than 8.3 billion ads and suspended 24.9 million advertiser accounts over the year, including 602 million ads and 4 million accounts tied specifically to scams. Google also says attackers are increasingly using generative AI to produce convincing fake ads faster and at greater scale, which points to this getting harder to spot over time rather than easier.
The NCSC has published its own guidance on malvertising too, aimed mainly at advertisers and the wider ad industry supply chain rather than end users directly, and it's worth knowing what it actually says: "user awareness training is no substitute for building systems that are secure by design." In other words, the UK's own cyber security authority sees this partly as an industry problem that needs fixing upstream, not something a business can train its way out of entirely. That doesn't make the habits below pointless. They cut your risk a lot. But it's also why keeping devices patched and properly protected matters just as much as staff awareness does.
What this means day to day
For a small or mid-sized business, the risk shows up in two ordinary moments: someone downloading software, and someone logging in.
A software download that goes wrong can hand an attacker the passwords and session cookies saved in that person's browser, sometimes enough to get into other accounts even where multi-factor authentication is switched on. A login page that goes wrong is more direct still, since the username and password go straight to the attacker the moment they're typed in. The same kind of credential-stealing malware is often exactly how a single bad click turns into something much bigger; it's the same starting point behind what actually happens once ransomware gets into a small business, not just an inconvenience for one person.
How to protect your team
- Scroll past anything marked "Sponsored" or "Ad". The genuine result is normally just below it. That one habit avoids most of this on its own.
- Don't download software from an ad. Go to the maker's website directly by typing the address yourself, or use the ordinary, non-ad search result.
- Bookmark the logins that matter. For your bank, Microsoft 365, and anything else important, use a saved bookmark rather than searching for it fresh each time.
- Keep devices patched and malware protection switched on. Cyber Essentials's update management and malware protection controls exist precisely because a device that's fully patched and properly protected is far harder to compromise even when someone does click the wrong link.
- Say this out loud to your team. Most people have genuinely never been told the top result can be a trap. Once they know, they stop clicking it without thinking.
Folding a quick check of this into a wider monthly IT routine is a good way to make sure the habit doesn't quietly slip, rather than relying on one training session to stick forever.
If someone's already clicked
- If they only looked at the page and closed it, there's likely nothing more to do beyond keeping an eye out.
- If they typed a password in, change it immediately, along with any other account using the same password, and confirm multi-factor authentication is switched on.
- If they downloaded and ran a file, disconnect the device from the network and get your IT provider to check it for malware before using it again.
- Report the site. You can report a scam website directly to the NCSC, which can lead to it being taken down before it catches someone else.
This kind of everyday risk is exactly what our cyber security work is built around, the technical protections and the staff habits together, rather than leaving it to chance. If you'd like us to look at where your business currently stands, book a call with our team and we'll take it from there.
Frequently Asked Questions
Are all Google ads unsafe?
No. The vast majority of paid search ads are entirely genuine, and Google removes billions of policy-breaking ads a year. The risk is specific: an ad using a trusted name to send you to a fake version of that site, which slips through often enough to be worth a moment's caution.
What is malvertising?
Malvertising, short for malicious advertising, is when a scammer buys online ad space, often against a trusted brand or software name, to send people to a fake site that steals logins or installs malware.
How can I tell if a search result is a genuine ad or a scam?
You often can't tell just by looking. The safest habit is to skip sponsored results entirely when downloading software or logging into something important, and use the ordinary result, a saved bookmark, or an address typed in directly instead.
Does an ad blocker stop this?
It helps. A reputable ad blocker hides most sponsored results, which removes the fake link from the page before anyone can click it. It isn't a complete fix on its own, so the habits above are still worth keeping.
What should I do if someone on my team clicked a scam ad?
It depends what happened next. If they entered a password, change it and check multi-factor authentication is on. If they downloaded and ran a file, disconnect the device and have it checked for malware. Either way, it's worth reporting the site to the NCSC so it can be taken down.
Written by
Jack Wetson-CattJack co-founded Atema in 2017 and leads the team day to day, bringing years of IT experience across telecoms, finance and legal to how Atema supports its own clients.
