Skip to main content

SEO poisoning

SEO poisoning is the manipulation of search rankings so malicious or impersonating pages appear high in results for trusted brand or topic queries, luring users into clicking them.

How it works

Attackers build out pages stuffed with the right keywords, link networks, and sometimes hacked legitimate sites to rank for searches like a brand name plus "login" or "download". The ranked page then serves phishing, fake downloads, or scams. It is the organic-search cousin of malvertising.

Because users trust top results, a poisoned listing can outperform an obvious ad.

How it relates to brand impersonation

SEO poisoning hijacks the trust people place in search to deliver brand impersonation. The pages it promotes are lookalike or compromised sites that monitoring and takedowns can address.

How nebty helps

nebty monitors search results for pages impersonating your brand and takes down the fraudulent destinations, so a poisoned listing does not keep sending customers to a scam.

Domain monitoring

How a poisoned result reaches you

SEO poisoning targets the searches people make when they already trust the answer, like a brand name plus login, download, or support. Attackers rank for these by building keyword-stuffed pages and link networks, and sometimes by compromising legitimate sites with good standing and quietly hosting their content there. The compromised-site angle is what makes it effective: the ranking domain may be a real business with years of authority, so it clears the suspicion an obviously new domain would not. Users trust organic results more than ads, so a poisoned listing can outperform paid placements. The defence is to watch search results for your brand terms, not just your own domains, and to take down the malicious destinations once found, whether they sit on a lookalike domain or a hijacked legitimate one.

A concrete example

Searching "Solara Finance login" one morning returns an unexpected first organic result: a page on the website of a small sports club, compromised months earlier, now quietly hosting a copy of the Solara Finance sign-in. The club domain is fifteen years old with a clean reputation, so it ranks above the noise and clears the suspicion a fresh domain would raise. The fix runs on two tracks: the club host removes the injected pages, and the URL goes to Safe Browsing so browsers warn anyone who still finds it in a cached result.

How to spot and stop it

  1. Search your brand plus login, download, and support regularly, or automate it. You are looking for results you do not control.
  2. Report malicious results to Safe Browsing and to the host of the ranking page. On compromised sites the owner usually removes the injection quickly once told.
  3. Own the obvious queries: publish clear login and download pages on your own domain so a poisoned result has to outrank the legitimate answer.

Frequently asked questions

How is SEO poisoning different from malvertising?

Malvertising buys its way to the top of the results page through paid ads. SEO poisoning earns the position organically, through manipulated rankings, which makes it cheaper for attackers to sustain and harder for platforms to police, since there is no ad account to suspend.

Can Google remove poisoned search results?

Google flags dangerous pages through Safe Browsing and demotes manipulative sites, but that takes time and does not touch the page itself. Removing the content at the host, alongside the report to Google, is what actually ends the campaign.

See who is impersonating your brand

The free nebty report scans the web for lookalike domains and fake profiles targeting your brand, with no obligation.

Get your free report