Rocktober Cybersecurity: The Website May Be Safe. The Link May Not Be.

October is Cybersecurity Awareness Month — or around here, Rocktober.

For this month's cybersecurity reminder, let's talk about something that catches even experienced Internet users:

Just because you trust the website you're visiting does not mean you should trust every link, advertisement, or sponsored result displayed on it.

Welcome to Malvertising

Many popular websites don't create or directly control every advertisement that appears on their pages. Advertising may be supplied through third-party advertising networks, and criminals actively look for ways to abuse those systems.

This is commonly called malvertising — malicious advertising.

A malicious advertisement may look completely ordinary. It might advertise software, a product, a news story, technical support, a security warning, or something related to what you were just searching for.

Click it, however, and you may be sent somewhere very different.

The FBI has warned that criminals use advertising, manipulated search results, compromised websites, and chains of redirects to send people to fraudulent websites. Those sites may attempt to steal passwords, display fake login pages, convince users to install a "required update," or download malware.

And here's the important part:

The website where you saw the link may be perfectly legitimate.

Sites such as news aggregators, search engines, social media platforms, and other ad-supported websites can display content or advertising supplied by outside systems. Seeing a link on a familiar website should not be treated as proof that the destination has been inspected or approved.

Search Results Aren't Automatically Safe Either

Searching for something on Google, Bing, Yahoo, or another search service doesn't guarantee that the first result is the real one.

Criminals purchase advertisements and create convincing copies of legitimate websites. A fake site may have the company's logo, colors, login screen, and almost everything else you expect to see.

The address may be different by only a letter or two.

This is especially dangerous when you're searching for:

  • Banking or financial websites

  • Employee or payroll services

  • Microsoft 365 or other login pages

  • Software downloads

  • Technical support

  • Popular utilities and applications

The FBI has specifically warned about criminals purchasing search advertisements that impersonate legitimate employee self-service websites. Victims believe they're logging into the real site and instead hand their username, password, and sometimes even their MFA code directly to the attacker.

"But I Have MFA"

Good. Keep using it.

But MFA isn't permission to stop paying attention.

Some modern phishing sites are specifically designed to capture both your password and the authentication information you provide afterward. If a website you didn't intend to visit asks you to log in, approving the MFA request doesn't magically make that website legitimate.

Always ask yourself:

Where am I actually entering my password?

A Few Habits Make a Big Difference

You don't have to become a cybersecurity expert. Slow down for a couple of seconds before clicking.

For important websites you use regularly, use a bookmark or enter the known address directly instead of searching for the site every time.

Be cautious with links marked Sponsored, Ad, or similar wording. Advertising placement is not a security endorsement.

Before entering your ICC username and password, look at the address in the browser. A page that looks like Microsoft isn't necessarily Microsoft.

Be particularly suspicious of websites suddenly telling you that your computer is infected, your browser needs an update, you need to install a security tool, or you must run a command to continue.

And don't download software just because an advertisement says it's the software you were looking for. Go to the software publisher's official website or another trusted source.

The Internet Has Changed

For years, cybersecurity awareness focused heavily on email:

Don't click strange links in email.

That's still good advice, but criminals didn't stop with email.

They're buying advertisements. They're manipulating search results. They're creating fake websites. They're compromising legitimate websites. And they're using the same advertising and Internet infrastructure that legitimate companies use to get your attention.

So here's the Rocktober takeaway:

Trusting the website you're on is not the same as trusting the link you're about to click.

Take an extra second.

Look at where you're going.

And when something doesn't look right, don't click your way forward.