The new AI-powered ‘Search Generative Experience’ (SGE), has come under fire for recommending sites associated with malware, scams, and deceptive practices. This raised concerns around the trustworthiness of search results, as well as the potential exploitation of users’ trust in Google’s algorithms.
Introduced earlier this month, Google’s SGE aims to provide users with quick summaries and recommendations related to their search queries, using AI to generate conversational style responses.
However, SEO consultant Lily Ray uncovered that the feature is inadvertently directing users to malicious sites, increasing the risk of falling victim to online scams.
Investigations conducted by cybersecurity researchers at BleepingComputer revealed a disturbing pattern among the sites recommended by Google’s SGE. These sites, often utilising the .online top-level domain (TLD) and identical HTML templates, engage in tactics such as browser notification spam, fake giveaways, and tech support scams.
After clicking on the recommended sites, users are subjected to a series of redirects, ultimately leading them to deceptive pages masquerading as legitimate services. Some of these pages prompt users to subscribe to browser notifications, a tactic commonly exploited by scammers to inundate unsuspecting users with unwanted advertisements.
In experiments, the redirects frequently led to fake captchas or YouTube-like sites, enticing users to subscribe to browser notifications. Subsequently, users received spam notifications promoting tech support scams, counterfeit giveaways, and other offers.
Furthermore, some of the redirects facilitated the installation of malicious browser extensions, potentially hijacking users’ search results and exposing them to further risks.
Recommended reading
- EU Probes Apple, Google, and Meta Over DMA Compliance
- Chatbot Numbers Rise as LLMs Take the Tech World by Storm
- 100,000 Hacker Credentials Exposed From Info-stealer Malware
The challenge lies in the conversational tone of Google’s AI-generated responses, which can inadvertently lend credibility to the recommended sites. This poses a significant threat to users who may trust Google’s recommendations implicitly.
Google responded to these inquiries by affirming their commitment to combating spam and ensuring the integrity of search results.
“We continue to update our advanced spam-fighting systems to keep spam out of Search, and we utilise these anti-spam protections to safeguard SGE,” Google told BleepingComputer.
“We’ve taken action under our policies to remove the examples shared, which were showing up for uncommon queries.”
In the face of evolving tactics employed by malicious actors, users are urged to remain vigilant and sceptical, relying on critical thinking and verification to safeguard against online threats.





