FBI issues threat alert on cyber criminals impersonating brands and defrauding users with search engine ads

Share post:

The Federal Bureau of Investigation (FBI) has issued a new threat alert about cyber criminals impersonating brands and using search engine advertisement services to defraud users.

The December 21, 2022, public service announcement stated that threat actors are purchasing these ad services to impersonate brands in order to lure users to malicious websites.

These sites, which “look exactly like the impersonated business’s official webpage,” tempt victims to download malware or enter login credentials and financial information, the FBI said.

Cyber criminals buy ads that appear in web search results by using a domain that looks similar to a legitimate business. These advertisements link to a webpage that is identical to the impersonated business and contains links to download malware-infected software. The download page appears to be legitimate, and the download is named after the program that the user intended to download. These cyberattack methods have also been used to impersonate financial websites, particularly cryptocurrency exchange platforms.

The FBI then advises users to verify the URL before clicking, to type the business url directly into the search engine rather than looking up the business, and to install an ad blocking extension.

The sources for this piece include an article in ic3.

SUBSCRIBE NOW

Related articles

Cyber Security Today, May 3, 2024 – North Korea exploits weak email DMARC settings, and the latest Verizon analysis of thousands of data breaches

This episode reports on warnings about threats from China, Russia and North Korea, the hack of Dropbox Sign's infrastructure

Hashtag Trending for World Password Day, Thursday, May 2nd, 2024

Security firm Okta warns of an unprecendented password stuffing attack that is piggybacking on regular user’s mobile and...

Google Chrome’s new post-quantum cryptography causes connection issues

The latest update to Google Chrome, version 124, which integrates a new quantum-resistant encryption mechanism, has led to...

UK legislation bans weak passwords

Starting Monday, the UK will enforce new laws banning the sale of devices with weak default passwords such...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways