Someone goes looking for a popular pair of sneakers. They spot a great deal in an ad, click it, check out, and feel good about the purchase. Everything looks official. A couple of weeks later, the shoes still haven’t arrived. They never will.
Almost everyone has a version of that story, either their own or one from someone close to them. What makes it unsettling isn’t the fake checkout page at the end. It’s that the victim did everything voluntarily. They searched, they chose, they clicked, and they handed over their payment details believing they were in control the entire time.
That’s the shift worth paying attention to. By the time a security team sees a phishing page, the attack is already well underway. The more useful question, and the one most investigations skip, is simpler: how did the customer get there in the first place?
In a recent webinar, “The Fraud Funnel: How Modern Scams Find Their Victims,” Bolster AI CEO Rod Schultz and lead security analyst Lauren Baer walked through that question. They traced a live investigation from the ad a victim clicked all the way to the infrastructure behind it, and made the case for why security teams need to start much earlier in the attack than they do today.
The Question Most Investigations Skips
Security teams have gotten very good at the end of the attack. They find the phishing page, pull the domain registration, and file the takedown. The problem is that by that point, the damage is mostly done, and the piece that would actually stop the next victim is missing.
“Usually by the time an investigation reaches us, we already have the endpoint of the attack,” Baer explained. That could be a fake login page, a storefront, the ad itself, or a customer note that says a link didn’t feel right. “The piece that’s always missing is how we got here in the first place.”
That missing context changes everything about the response. It tells you whether you’re dealing with a single malicious website or a coordinated campaign with dozens of moving parts. Understand the acquisition path, and you can often uncover the rest of the infrastructure, identify victims before they’re impacted, and disrupt the attack early instead of cleaning up after it.
Attackers Have a Marketing Team Now
“Funnel” is a marketing word, not a security one. That’s exactly why it fits.
Schultz’s point is that attackers didn’t invent anything new. They borrowed three decades of refined marketing technology, the same digital tracking, search targeting, and audience data that legitimate businesses use to match supply with demand, and pointed it at fraud. “The goal of the attacker is to trick the victim into interacting with something that they think is real,” he said. Large language models made that dramatically cheaper and faster to pull off at scale.
The funnel runs in stages. At the top is acquisition: paid search, sponsored placements, and social promotion, all designed to create credibility before the victim suspects anything. Then comes trust, built through impersonation, fake storefronts, and lookalike sites. Then the exploit, whether that’s installing an app, entering credentials, or buying a product that may never arrive.
“They’ve acquired you, they’re going to build trust through impersonation, fake storefronts, and lookalike sites, and then create some sort of urgency,” Schultz said. A price that expires in 24 hours. An account that’s supposedly been compromised. Once the campaign works, attackers reskin it and move to the next vertical, from financial services to insurance to retail.
Baer sees the same pattern from the investigation side, and the sophistication is what stands out. “Attackers aren’t just launching isolated phishing incidents anymore,” she said. “They’re building end-to-end customer journeys, very similar to how legitimate marketing teams acquire customers.” Rotating domains, tested creatives, targeted audiences, continuous optimization based on what converts. From an investigation standpoint, that means the work is no longer about a single malicious URL. It’s about an entire ecosystem.
One Ad, an Entire Ecosystem
To make it concrete, Baer walked through a real investigation, lightly anonymized here.
It started the way these often do, with a malicious ad impersonating a well-known European jewelry brand. In the ad library, nothing jumped out. Legitimate-looking product images, professional branding, familiar language. A click sent the victim to a lookalike retailer that had copied the brand’s imagery, layout, and prices almost exactly. To an average shopper, it read as real.
Most investigations would stop there: flag the ad, note the URL, call the incident contained. But the ad was only the entry point. “Attackers are investing in visibility to bring victims into their ecosystem,” Baer said, the same way a legitimate business pays to acquire customers.
The lookalike site wasn’t operating alone. Behind it sat multiple advertiser accounts, multiple lookalike domains, and a “buy with an expert” prompt that handed the victim off to a WhatsApp conversation with someone entirely outside the visible advertising chain. Take down the domain, and the attacker simply points the same ad somewhere new.
“If we investigate this as just the fake website, we’re treating the symptom rather than the entire attack,” Baer said. Follow the full chain instead, from the ad to the site to the WhatsApp handoff, and you can trace it back to the beginning, find the other ads and sites built the same way, and dismantle the campaign rather than one disposable piece of it.
That’s the logic behind Fraudulent Ads Monitoring and Takedowns: connect the ad, the redirect, the destination, and the supporting infrastructure into one investigation. Because attackers beat manual takedowns by recreating ads under new advertiser accounts, reappearance monitoring matters as much as the first removal. Enforcement compounds instead of restarting, at up to 20x lower cost per takedown than manual methods.
Who Owns This Problem?
Fraud ads sit in an awkward gap. Security inherits the incident. Marketing loses the traffic, the ad spend, and the customer trust. Neither team fully owns it, and attackers are very comfortable in that gap.
“As we see these worlds of cyber and fraud start to connect, we’re starting to identify a gap in who owns this problem,” Schultz said. His recommendation is to treat customers as an attack surface in their own right, one that needs an owner, tools, and a process. The CISO or CIO is the natural home, since that role exists to step back and evaluate security posture across the whole enterprise. If ownership lands elsewhere, in legal, brand, or marketing, that’s workable too, as long as the owner is empowered to tell the story to leadership in concrete terms rather than vague warnings about fraud.
This is the convergence of cyber and fraud that keeps coming up in these conversations, and it’s why the answer increasingly looks like connecting external signals into a single operational view rather than a scatter of separate tools.
What Security Teams Can Do Now
Barer’s advice was refreshingly practical, and the first few steps don’t require new tooling at all. They build on each other.
Ask how the attack was found. Shift the opening question from “what did the phishing site do” to “how did the customer get here.” Every team can start doing this today.
Investigate the acquisition channel. Was it a search ad, a sponsored social post, or another paid placement? This is what tells you how victims are actually being reached.
Correlate the infrastructure. Connect the ad to the redirect, the destination, and the related domains. Treat them as one case, not separate alerts.
Look beyond the single artifact. One ad or one domain is rarely the whole picture. Map what’s connected to it, because that’s where the campaign lives.
Why This Matters Now
Both speakers landed on the same theme: the human has become the persistent weakest link, and AI is widening the gap.
“Attackers exploit the weakest link, and this is by far one of the weakest, because it’s been given the least amount of thought,” Schultz said. Customer-facing fraud has historically gotten the least security attention, which is exactly what makes it attractive. As AI makes campaigns cheaper, faster, and easier for anyone to launch, he expects this to move from an afterthought to a first-class, top-of-mind problem, with every attack surface exploited in newer and more inventive ways.
The response, he argued, is to pull back to the infrastructure level, get to the root cause faster instead of treating symptoms one at a time, and put the picture in front of whoever owns the problem so they can act on it.
The Bottom Line
The scam website was never the beginning of the attack. The ad was, and often the whole funnel behind it was built and optimized long before any customer clicked.
Seeing that funnel changes what a defense looks like. Detection has to start at acquisition, not in the aftermath. Investigation has to follow the chain, not stop at the artifact. And enforcement has to keep campaigns down as attackers rebuild them, which is where AI-native detection, evidence-backed takedowns, and reappearance monitoring earn their place. There are human analysts in the loop for the complex and ambiguous cases, but the scale and speed come from the platform.
Attackers borrowed the marketing playbook. It’s time defenders read it too.
Webinar Highlights
This article is based on the webinar “The Fraud Funnel: How Modern Scams Find Their Victims,” featuring Rod Schultz, CEO at Bolster AI, and Lauren Baer, lead security analyst at Bolster AI. To see the full investigation walkthrough and Q&A, watch the session.