Technique
SEO Poisoning
Also known as: Search Poisoning, Spamdexing
Manipulating search engine results to surface malicious websites, fake customer support numbers, or fraudulent download pages for common queries. Attackers use blackhat SEO tactics (keyword stuffing, cloaking, link farms, bot traffic) to push poisoned pages to the top of search results, exploiting v…
Common attack flows
How it fits in a scam
Before
This is often where the scam begins.
Defense
How to defend against this
How to spot it
- Search result URL does not match the expected official domain of the company or service
- Multiple redirects before reaching final page content
- Website loaded from search result has excessive pop-ups
- ads or immediate download prompts
- Customer support phone number found via search does not match number on official company website or app
- Misspelled or unusual domain names in search results for well-known brands
- Search result page content looks templated or stuffed with repetitive keywords
- Caller from number found via search immediately requests remote access or payment
Further reading
CrowdStrike
Overview of SEO poisoning techniques including typosquatting, blackhat SEO tactics, and private link networks
Bitdefender
Detailed breakdown of 7 attack methods including keyword stuffing, fake business listings, and social media boosting
Zscaler
Explains spamdexing, timing exploitation of trending searches, and zero trust defense strategies
Coalition
Real-world case of SEO poisoning used to harvest crypto account credentials leading to fraudulent transfer
HuffPost
Consumer-focused reporting on fake customer support numbers placed via SEO poisoning in Google results