The FBI is urging organizations and their end users to be careful when using search engines as cybercriminals are using search engine advertisement services to impersonate brands and direct users to fake websites designed to steal credentials and deploy ransomware.
According to a public service announcement from the FBI, cybercriminals have been buying advertisements that appear within search results using a domain that is similar to an actual business or service. The ads being purchased appear at the top of search results, and it is difficult to differentiate between actual search results and ads.
The ads link to a webpage that even looks identical to the impersonated business’ official site, but the fraudulent website instead contains malicious links or fake credential forms designed to deploy malware or steal credentials and other financial information.
“These advertisements have also been used to impersonate websites involved in finances, particularly cryptocurrency exchange platforms,” the FBI says in the advisory. “These malicious sites appear to be real exchange platforms and prompt users to enter login credentials and financial information, giving criminal actors access to steal funds.”
Although search engine advertisements are designed to help businesses promote products or services, they are being exploited by malicious actors, so end users should be cautious, the FBI warns.
End users should check the URL before clicking on an advertisement to make sure it is authentic, the agency says. In addition, users should also simply find the business’ URL directly rather than searching for it and use ad blocking extensions when performing internet searches.
For businesses, the FBI recommends using domain protection services that notify the organization that similar domains are registered to help prevent domain spoofing. Businesses should also educate users about spoofed websites and cybersecurity basics as well as providing resources end users need to do their jobs so they don’t search for tools online.
Leave a Reply