When people ask what I do, they usually assume I spend my days looking at phishing sites. They’re not wrong. My team investigates phishing campaigns, fake storefronts, impersonation attacks, and just about every way attackers try to trick customers into handing over credentials or payment information. But lately, we’ve found ourselves spending more time looking at something else – fraudulent ads.
Over the last year, we’ve seen a noticeable increase in campaigns that start with a sponsored result instead of a phishing email. Someone searches for a brand they trust, clicks what looks like the right result, and never makes it to the legitimate website. Instead, they’re redirected into a fake storefront, a credential harvesting page, or some other piece of scam infrastructure. By the time anyone reports the phishing site, the damage has already started. The customer was intercepted several clicks earlier.
The Ad Is Rarely the Whole Story
One thing I love about threat hunting is that almost nothing exists in isolation. A fraudulent ad usually isn’t just a fraudulent ad, it leads somewhere. That destination connects to something else and that infrastructure has likely been used before.
What starts as a single sponsored result can quickly turn into a network of lookalike domains, fake storefronts, phishing kits, social impersonation, and redirect infrastructure, all supporting the same campaign. That’s the part I find interesting. The ad is just the breadcrumb. Following where it leads is where the investigation begins.
We Started Asking a Different Question
When we investigated these campaigns, we realized we were asking the wrong question. Instead of asking, “Where is the phishing page?” We started asking, “How did the customer get there?” That simple shift changed how we looked at these attacks.
Attackers aren’t waiting for people to stumble across a scam anymore. They’re actively competing for customer attention using many of the same tactics legitimate companies use: paid search, sponsored placements, branded keywords, and conversion funnels. They’re trying to win the customer before the real company does.
That’s a Blind Spot for Most Organizations
One thing that stands out when working these investigations is how fragmented the picture can be. Marketing notices branded traffic behaving strangely. Security gets reports about phishing sites. Customer support starts hearing from confused customers. Each team sees a piece of the campaign, but rarely the whole thing. By the time those dots get connected, customers have often already been exposed.
Why We Built Fraudulent Ads Monitoring & Takedowns
The more campaigns we investigated, the more obvious it became that we needed to start earlier. Not at the phishing page, not at the fake storefront but at the advertisement that sent the customer there in the first place. That’s what led us to build Fraudulent Ads Monitoring & Takedowns.
The goal wasn’t to create another ad monitoring tool. We wanted to give analysts the same workflow we’d built for ourselves: find the ad, investigate the redirects, understand the infrastructure behind it, connect it to the broader campaign, and get it removed before more customers end up in the funnel. Because in our experience, removing the ad isn’t really the win – stopping the campaign is.
The Attack Surface Has Changed
Threat hunting has a funny way of changing how you think. You stop looking at individual artifacts and start looking at how everything connects. That’s exactly what’s happening with fraud today. The phishing page is still there; the fake storefront is still there. But more and more, the attack actually starts much earlier, with the moment an attacker convinces someone to click. If we want to do a better job protecting customers, that’s where we need to start looking.
If this shift sounds familiar, or you’re curious about how these campaigns actually work in the wild, I’d love for you to join me on July 22 for our webinar, “The Fraud Funnel: How Modern Scams Find Victims.”