phishing
June 23, 2026 ¡ Last updated on July 2, 2026
The Most Dangerous Link on the Page - Google Ads

# Storytelling
Why malicious Google Ads keep catching people out, and how to turn it into an awareness campaign

Ant Davis

If you have listened to my podcast for any length of time, you will have heard me say a version of the same thing over and over again. Do not click the ad. Go directly to the URL, or even better, use a bookmark.
It sounds almost too obvious to bother with. It is honestly one of the most useful things we tell people, and the reason we keep banging on about it is that malicious ads keep turning up on our running order, month after month, story after story. If you do security awareness for a living, that makes this a lovely topic to work with. Everyone uses search, nobody needs a single bit of jargon to get it, and the behaviour you are asking for at the end is tiny. So let me give you the topic, and then what I would actually do with it.
The bit to explain to people
When someone searches for a brand, a login page, a bit of software or a support number, their brain quietly decides the result at the top is the official one. It is at the top, isn't it. It has got the right logo. The web address looks close enough. In you go.
Except that top result is very often an advert, and an advert is bought, not earned. Anyone with a card and a bit of front can pay to sit above the real company. And the fake usually looks every bit as tidy as the real thing, sometimes tidier. That is the part worth emphasising with your people. The attacker is not doing anything clever with code here. They are just buying the spot your brain already trusts.
That is why this works so well as a message. It is a human problem rather than a technical one, which means an actual human stands a chance of stopping it.
There is something else worth pointing out, because it makes this one stand apart. We spend most of our time these days warning people that attackers play on their emotions. The panic of a missed delivery, the fear of a locked account, the pull of an offer too good to turn down. Almost every scam we pick apart on the show is leaning on a feeling to get you moving before you have had a chance to think. This one is different. There is no emotional hook, no pressure, no manufactured drama at all. It is pure imitation. The attacker builds a convincing copy, parks it in a spot you already trust, and you do the rest entirely on your own. That is exactly what makes it worth teaching, because it breaks the pattern people reckon they have already learned.
Why it is worth building a campaign around
The thing that makes this a proper topic rather than a one off is that it keeps coming back in slightly different shapes. A good recent one was  a fake Claude downloader being pushed through Google Ads , a counterfeit of the real download page sitting right there in the sponsored slot, ready to hand you malware instead of the app you actually went looking for. That is the whole con in one neat package. You search for a tool you trust, you click the result at the top, and you have no idea you have just been steered somewhere nasty. It is not the first time we have flagged a fake page riding the sponsored slot on the show, and it will not be the last.
It is not only Google either. We covered the Crocodilus banking malware being spread mainly through malicious adverts on Facebook, which shocked absolutely no one.
Here is the bit that really matters though, because it changes how you tell people to defend against this. A lot of these malicious ads are not posted from some dodgy account knocked up for the purpose. They go out through legitimate ad accounts that have been compromised. We covered a phishing campaign aimed squarely at TikTok for Business accounts, and the whole reason attackers chase business accounts like that is the advertising. Take over a real, trusted account and you have got a believable platform to push your rubbish from.

ďťż
ďťż
And we have seen this one with our own eyes.  We found a malicious ad pushing Google itself , of all things, and when we had a proper look at who had actually posted it, the account belonged to Sydney Zoo. The zoo were obviously not running a Google scam, their ad account had been taken over and used to do it. We reached out to let them know and reported the ad. The lesson in that is a sharp one for your people, because it means you cannot even fall back on checking whether the advertiser looks legitimate. The advertiser might be a real, trusted organisation whose account got hijacked while they were busy doing something far more wholesome, like looking after actual animals.
The brand changes, the platform changes, but the advert as the way in keeps coming back. That is your evidence base, and it is not going to run dry.
There is a timing angle to all this that makes it worth raising right now. For years, a lot of people were quietly protected from this without ever realising it, because their ad blocker was stripping the sponsored results out of search before they ever clapped eyes on them. No ad shown, no malicious ad to click. Chrome has now pulled the rug on the most effective ad blockers, which I get into properly in the companion piece to this one, and the upshot is that a chunk of people are suddenly seeing sponsored results sat at the top of their searches for the first time in years. They are out of practice, they are not primed to be wary of that slot, and that is precisely the gap an attacker is banking on. So the human habits below matter more now, not less.
We're bringing bookmarks back
Here is where it gets practical, and here is the behaviour I would build the whole thing around.
If you log into a site regularly, bookmark it, and then actually use the bookmark. Every time. You are not searching for your bank, your payroll system or whatever key tools your people log into all day, you are going straight to the address you already trust. No ad to fall for, no lookalike domain to squint at, nothing to get wrong.
So I would make bookmarks the campaign. Not a line at the bottom of a poster, the actual headline. We're bringing bookmarks back. Think Justin Timberlake, SexyBack, except, you know, bookmarks. It is daft, and that is exactly why people will remember it. Show them how to bookmark a page, how to set up the bookmarks bar, how to drop the handful of sites they sign into most into a folder so it is one click away. Almost nobody teaches this, which is mad, because the bookmarks bar is one of the most underrated security controls going.
I will let you into something. Before I log into the platform we record the show on, it is bookmarked. I never go digging for it in an email or typing it from memory, because that is precisely the moment you end up on the wrong site. That one little habit is doing quiet security work for me every single week.
A few other things that tend to land well when you take this out to a business. Put a real malicious ad next to the genuine result, side by side, screenshots, big as you like. People remember the comparison far more than they remember a warning. Remind them too that this one will not feel like the scams they have been trained to spot. There is no panicked email, no countdown, no threat, so they cannot sit and wait for that familiar prickle of something being off. The page looks right, and looking right is the whole trick. And say the awkward bit out loud, the part people genuinely resist. A clean, professional looking ad is not proof that anything is legitimate. It only proves someone paid for the slot and hired a half decent designer.
The bit to take away
The most dangerous link on the page is very often the one sitting right at the top, dressed up to look the most trustworthy of the lot. Your job is to flip that instinct, so your people read the ad slot as the least trustworthy part of the page instead of the most. Pair that with a proper, slightly silly push on bookmarks and you have got a campaign that costs nothing, needs zero technical knowledge to follow, and quietly closes off a whole category of attacks we have watched land over and over again.
Go direct to the URL. Better still, use the bookmark. We're bringing bookmarks back, and your people will be safer for it.
Like
Comments (0)
Popular
ďťż
Dive in
Related
Content
What Spaced Repetition Research Says About Why Annual Training Doesn't Stick
By Ant Davis â˘Â Jul 20th, 2026 ⢠Views 3
Content
What Spaced Repetition Research Says About Why Annual Training Doesn't Stick
By Ant Davis â˘Â Jul 20th, 2026 ⢠Views 3

