For years, most online scams followed a familiar pattern. An email would arrive claiming to be from a trusted organisation, a text message would encourage the recipient to click a link, or a fake social media profile would impersonate a legitimate brand. The objective was always the same: convince someone to engage before they realised something wasn’t right.
While those threats continue to dominate, we’re increasingly seeing threat actors use search engines as another way of reaching potential victims.
Rather than relying on unsolicited emails or messages, these campaigns are designed to intercept customers already searching for legitimate information. In many cases, the attacker isn’t trying to create demand. They’re exploiting demand that already exists.
Search Engine Manipulation at Scale
One example we’ve encountered recently involved a collection of websites targeting airline-related search terms. Unlike traditional phishing websites, these pages weren’t designed to imitate a login portal or payment page. Instead, they appeared to exist almost entirely for search engines.
The websites contained large volumes of AI-generated content built around common customer searches, including bookings, baggage enquiries, customer support and flight information. Throughout the content, the airline’s name, common search phrases and a fraudulent support number were repeated dozens of times.
To anyone reviewing search results, the listing appeared legitimate. Google’s title and search snippet prominently displayed the airline’s name alongside what appeared to be an official contact number. A customer searching for assistance could easily believe they had found the correct result before ever clicking the page.
(Example of an AI-generated webpage designed to manipulate search results for a trusted brand. The page repeatedly references branded search terms and displays a fraudulent support number (redacted) to intercept users seeking legitimate customer assistance.)
Once opened, the websites themselves often offered very little value. Much of the content consisted of repetitive AI-generated text whose primary purpose appeared to be reinforcing search keywords rather than providing useful information. The content wasn’t written for people. It was written to maximise visibility in search engines.
We’ve observed similar techniques across multiple campaigns. Fake gambling information websites have been created around branded search terms before redirecting users through affiliate networks. We’ve also investigated AI-generated documents hosted on trusted third-party platforms that appear designed primarily to influence search results rather than provide meaningful content.
While this article focuses primarily on websites, the same techniques are increasingly being applied to documents, community platforms and other indexed content that can appear in search results.
Regardless of the end objective, the underlying approach remains remarkably consistent: generate large volumes of search-optimised content, gain visibility in search results and intercept users before they reach the legitimate organisation.
The website itself isn’t always the scam. Increasingly, it’s the mechanism used to connect a user with the scam.
AI Has Changed the Economics
Search engine manipulation isn’t new. Techniques such as search spam, keyword stuffing and SEO abuse have existed for years, with threat actors attempting to push malicious content ahead of legitimate search results.
What’s changing isn’t the tactic itself. It’s the scale at which it can now be deployed.
Much of the discussion surrounding artificial intelligence focuses on whether it allows attackers to create more convincing phishing emails or more realistic fake websites. From what we’re seeing, the more significant change isn’t sophistication. It’s scale.
Creating search-optimised content once required a meaningful investment of time. Threat actors needed to write articles, identify relevant search terms, structure pages appropriately and produce enough unique content for search engines to index. AI has dramatically reduced both the time and cost required to produce this content.
Today, a single actor can generate hundreds of pages containing unique headings, metadata, frequently asked questions and long-form content in a matter of minutes. The quality doesn’t need to be exceptional. It only needs to be convincing enough that a malicious page appears alongside, or ahead of, legitimate search results.
This fundamentally changes the economics of these campaigns. Rather than investing significant time into producing a handful of websites, threat actors can now generate hundreds and simply rely on volume to achieve results. When producing content becomes almost effortless, generating hundreds of websites becomes a viable strategy. Even if only a small percentage achieve meaningful visibility, the campaign can still be successful.
From Websites to Campaigns
Search results have traditionally been viewed as a marketing concern, focused on visibility and customer acquisition. Increasingly, they’re becoming another threat surface where organisations can lose control of the customer journey before a victim has even reached the legitimate website.
This also changes how we think about disruption. Traditionally, responding to an online scam meant identifying a malicious website and working to have it removed. While that remains important, AI is allowing threat actors to rebuild campaigns faster than ever before.
If one website is removed, another can often be generated and deployed within minutes using the same underlying approach. The challenge is no longer simply removing individual pages. It’s identifying the infrastructure, patterns and behaviours that underpin an entire campaign.
So, What’s Next?
It’s still early, and AI-generated search manipulation isn’t yet the dominant form of online abuse. However, the increase we’ve observed over recent months suggests this is a trend organisations should be paying close attention to.
As AI continues to reduce the effort required to produce search-optimised content, we expect threat actors to target a broader range of branded search terms, customer support queries and other high-intent searches. Rather than relying solely on phishing emails or fake login pages, campaigns are likely to compete directly with legitimate organisations for visibility in search results.
This presents a different challenge for organisations responding to these threats. In many cases, removing a single webpage won’t meaningfully disrupt the campaign. By the time one page is taken down, several more may already exist.
The focus therefore shifts from responding to individual websites towards identifying campaigns early, reporting malicious content as broadly as possible and disrupting threat actors faster than they can adapt. Success won’t always be measured by removing every page. Increasingly, it will depend on reducing exposure, slowing campaigns down and making it significantly harder for threat actors to reach potential victims.
Search engine manipulation is unlikely to replace traditional phishing, social engineering or other established attack techniques. Instead, it’s becoming an increasingly important addition to the threat actor’s toolkit.
For organisations responsible for protecting customers, staying ahead won’t always mean removing every malicious page. Increasingly, success will depend on identifying campaigns early, responding broadly and disrupting threat actors faster than they can adapt.