Home Tip Sheets Ad Phishing
Phishing

Ad Phishing

Fake ads and deceptive links are everywhere. Learn how to spot them before they hook you.

3.4B
phishing emails sent every single day
36%
of data breaches involve phishing
$17k
average loss per phishing attack

What Is Phishing?

Phishing is a type of online fraud where criminals impersonate trusted organisations - banks, government agencies, popular brands - to trick you into revealing passwords, credit card numbers, or personal information.

Ad phishing specifically uses fake advertisements on websites, social media and search engines to lure victims. These ads may appear at the top of Google results, in your social media feed, or on legitimate news sites.

The links lead to convincing fake websites designed to steal your information or install malware.

How to Spot a Phishing Attempt

Urgency & threats
"Your account will be closed in 24 hours!" Panic is a manipulation tactic.
Suspicious URLs
Hover over links. "paypa1.com" or "amazon-secure-login.net" are fake.
Generic greetings
"Dear Customer" instead of your real name is a strong phishing signal.
Too good to be true
Free iPhones, prize winnings, or massive discounts are almost always bait.
Unexpected attachments
Never open attachments you weren't expecting - even from known contacts.
No padlock / HTTPS
Legitimate sites use HTTPS. If the padlock is missing, don't enter any data.
Poor design quality
Blurry logos, odd fonts, and spelling errors are signs of a fake page.
Requests for payment info
No legitimate ad or email should ask for full card details upfront.
How to Check a Link Before Clicking
1
Hover before clicking
On a computer, hover your mouse over a link to see the actual URL in the bottom of the browser before clicking.
2
Check the domain carefully
Look at the root domain (the part before .com/.net). "secure-paypal-login.com" is NOT PayPal - paypal.com is.
3
Use a link scanner
Paste suspicious links into Google Safe Browsing (safebrowsing.google.com/safebrowsing/report_phish/) to check.

What to Do If You've Been Phished

1
Don't panic - act fast
The quicker you respond, the more damage you can limit. Take a breath and work through the steps below.
2
Change your passwords immediately
Start with your email, then banking and any account that used the same password.
3
Enable two-factor authentication
Even if your password was stolen, 2FA prevents criminals from logging in without your phone.
4
Contact your bank
If you entered card or banking details, call your bank immediately and ask them to freeze your account.
5
Run a malware scan
Use reputable security software to scan your device for any malware that may have been installed.
6
Report to CyberTips
File a report at 1-441-777-0875 or online. Include screenshots of the fake ad or email for investigation.

Spotted a phishing ad?

Report it so we can alert others and work with platforms to remove it. Your report protects the whole community.

File a Report
1-441-777-0875

More Tip Sheets

View all
Cyberbullying
Recognize and stop online harassment
Read more
Mobile Phone Safety
Keep your phone and data secure
Read more
Seniors Safety
Online safety tips for older adults
Read more
Summer Jobs
Avoid job scams targeting young people
Read more