{"id":25610,"date":"2026-09-05T02:46:29","date_gmt":"2026-09-04T23:46:29","guid":{"rendered":"https:\/\/alienroad.com\/google-bilgi-bankasi\/social-engineering-phishing-and-deceptive-sites\/"},"modified":"2026-09-05T02:46:29","modified_gmt":"2026-09-04T23:46:29","slug":"social-engineering-phishing-and-deceptive-sites","status":"publish","type":"ar_kb","link":"https:\/\/alienroad.com\/google-bilgi-bankasi\/social-engineering-phishing-and-deceptive-sites\/","title":{"rendered":"Social engineering (phishing and deceptive sites)"},"content":{"rendered":"<p>Social engineering is content that tricks visitors into doing something dangerous, such as<br \/>\n  revealing confidential information or downloading software. If Google detects that your website<br \/>\n  contains social engineering content, the Chrome browser may display a &#8220;Deceptive site ahead&#8221;<br \/>\n  warning when visitors view your site. You can check if any pages on your site are suspected of<br \/>\n  containing social engineering attacks by visiting the Security Issues report in Search Console.\n<\/p>\n<p class=\"center\"><a class=\"external-link button button-primary\" href=\"https:\/\/search.google.com\/search-console\/security-issues\">Open<br \/>\n  the Security Issues Report<\/a><\/p>\n<h2 id=\"what-is-social-engineering\" tabindex=\"-1\">What is social engineering?<\/h2>\n<p>A <i>social engineering attack<\/i> is when a web user is tricked into doing something<br \/>\n  dangerous online.<\/p>\n<p>There are different types of social engineering attacks:<\/p>\n<ul>\n<li><b><a href=\"https:\/\/support.google.com\/websearch\/answer\/106318\" class=\"external-link\">Phishing<\/a>:<\/b><br \/>\n    The site tricks users into revealing their personal information (for example, passwords,<br \/>\n    phone numbers, or social security numbers). In this case, the content pretends to act, or looks and<br \/>\n    feels, like a trusted entity \u2014 for example, a browser, operating system, bank, or government.<\/li>\n<li><b>Deceptive content:<\/b> The content tries to trick you into doing<br \/>\n    something you&#8217;d only do for a trusted entity \u2014 for example, sharing a password, calling tech<br \/>\n    support, downloading software, or the content contains an ad that falsely claims that device<br \/>\n    software is out-of-date, prompting users into installing unwanted software.<\/li>\n<li><b>Insufficiently labeled third-party services:<\/b> A <i>third-party service<\/i><br \/>\n    is someone that operates a site or service on behalf of another entity. If you (third party)<br \/>\n    operate a site on behalf of another (first) party without making the relationship clear,<br \/>\n    that might be flagged as social engineering. For example, if you (first party) run a charity<br \/>\n    website that uses a donation management website (third party) to handle collections for your<br \/>\n    site, the donation site must clearly identify that it is a third-party platform acting on<br \/>\n    behalf of that charity site, or else it could be considered social engineering.<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.google.com\/transparencyreport\/safebrowsing\" class=\"external-link\">Google Safe<br \/>\n  Browsing<\/a> protects web users by warning users before they visit pages that consistently<br \/>\n  engage in social engineering.<\/p>\n<p>Web pages are considered social engineering when they either:<\/p>\n<ul>\n<li>Pretend to act, or look and feel, like a trusted entity, like your own device or browser,<br \/>\n    or the website itself, or<\/li>\n<li>Try to trick you into doing something you&#8217;d only do for a trusted entity, like sharing a<br \/>\n    password,  or calling a tech support number, or downloading software.<\/li>\n<\/ul>\n<h3 id=\"social-engineering-in-embedded-content\" tabindex=\"-1\">Social engineering in embedded content<\/h3>\n<p>Social engineering can also show up in content that is embedded in otherwise benign websites,<br \/>\n  usually in ads. Embedded social engineering content is a policy violation for the host page.<\/p>\n<p>Sometimes embedded social engineering content will be visible to users on the host page, as<br \/>\n  shown in the <a href=\"#example\">examples<\/a>. In other cases, the host site does not contain<br \/>\n  any visible ads, but leads users to social engineering pages via pop-ups, pop-unders, or other<br \/>\n  types of redirection. In both cases, this type of embedded social engineering content will<br \/>\n  result in a policy violation for the host page.<\/p>\n<h2 id=\"hacking-embedded\" tabindex=\"-1\">But I don&#8217;t engage in social engineering!<\/h2>\n<p>Deceptive social engineering content may be included via resources embedded in the page, such<br \/>\n  as images, other third-party components, or ads. Such deceptive content may trick site visitors<br \/>\n  into downloading <a href=\"https:\/\/www.google.com\/about\/unwanted-software-policy.html\" class=\"external-link\">unwanted<br \/>\n  software<\/a>.<\/p>\n<p>Additionally, <b>hackers<\/b> can take control of innocent sites and use them to<br \/>\n  host or distribute social engineering content. The hacker could change the content of the site<br \/>\n  or add additional pages to the site, often with the intent of tricking visitors into parting<br \/>\n  with personal information such as credit card numbers. You can find out if your site has been<br \/>\n  identified as a site that hosts or distributes social engineering content by checking the<br \/>\n  Security Issues report in Search Console.<\/p>\n<p>See our <a href=\"https:\/\/web.dev\/articles\/hacked\" class=\"external-link\">Help<br \/>\n  for Hacked Sites<\/a> if you believe that your site has been hacked.<\/p>\n<h2 id=\"example\" tabindex=\"-1\">Examples of social engineering violations<\/h2>\n<h3 id=\"deceptive-content-examples\" tabindex=\"-1\">Deceptive content examples<\/h3>\n<p>Here are some examples of pages that engage in social engineering practices:<\/p>\n<p><figure><img decoding=\"async\" alt=\"Social engineering popup that tries to make the user install an unwanted application\" title=\"Deceptive popup intended to trick the user into installing malware\" class=\"screenshot\" src=\"https:\/\/lh3.googleusercontent.com\/M1marY2U0TpG5jlbdOE-ISvmUaoLErD03-95JxDdxD89VDuUmgmctDiOOMmKOzZxB2Q=w280\"><figcaption>Deceptive popup intended to trick the user into installing malware.<\/figcaption><\/figure>\n<\/p>\n<p><figure><img decoding=\"async\" alt=\"Example of social engineering attempt claiming a browser update is required\" src=\"https:\/\/lh3.googleusercontent.com\/Opsb7huiddG8az9vN9rF6Ds0I_QLsJpd_VVQfjElnB9hZNQxnDwO21YJBloBq8YAs4OB=w673\"><figcaption>Deceptive popup claiming to help the user update their browser<\/figcaption><\/figure>\n<\/p>\n<p><figure><img loading=\"lazy\" decoding=\"async\" alt=\"Fake Google login page\" class=\"screenshot\" height=\"594\" src=\"https:\/\/lh3.googleusercontent.com\/uTWvxf7NR7alzT_VEF1wD31v3l6CeKG7M7nN4wpa-Z_nSGb5xsMUi19RTUTKQimqbu0=w577\" width=\"577\"><figcaption>Fake Google login page<\/figcaption><\/figure>\n<\/p>\n<aside class=\"note\">Note the deceptive URL. Other phishing sites like this could trick you into<br \/>\n  giving up other personal information such as credit card information. Phishing sites may look<br \/>\n  exactly like the real site\u2014so be sure to look at the address bar to check that the URL is<br \/>\n  correct, and also check to see that the website begins with <code>https:\/\/<\/code>.<\/aside>\n<h3 id=\"deceptive-ad-examples\" tabindex=\"-1\">Deceptive ad examples<\/h3>\n<p>Here are some examples of deceptive content inside embedded ads. These ads appear to be part<br \/>\n  of the page interface rather than ads.<\/p>\n<p><figure><img decoding=\"async\" alt=\"Deceptive ad claiming to be a media player update on the page\" class=\"screenshot\" src=\"https:\/\/lh3.googleusercontent.com\/DppbfyYk_wlh1FGF4yJC2JjngwUXWJ1byLiLcBC8XApJjf1Qw6JNdmKc9SO0EJ0XTBoQ=w320\"><figcaption>Deceptive popup claiming that the user&#8217;s software is out of date.<\/figcaption><\/figure>\n<\/p>\n<p><figure><img decoding=\"async\" alt=\"Deceptive ad claiming to be an installer for a required component\" class=\"screenshot\" src=\"https:\/\/lh3.googleusercontent.com\/bIKFz8xmrKW5dS7TS40NVQRqoy0eN3GB6FsE2l5tCWGexueJSlgxoQYCiIafk8YWFg=w320\"><figcaption>Deceptive popup claiming to come from the FLV developer<\/figcaption><\/figure>\n<\/p>\n<p><figure><img decoding=\"async\" alt=\"Deceptive ads claiming to be playback controller buttons on the host page\" class=\"screenshot\" src=\"https:\/\/lh3.googleusercontent.com\/oSuub3M4dcqc_UD5F1pCpPQEG_--gDnpro8PKG0V9kEirLl3Q9WjZQXeaLbZkT192P6l=w320\"><figcaption>Ads masquerading as page action buttons.<\/figcaption><\/figure>\n<\/p>\n<h2 id=\"fixing-the-problem\" tabindex=\"-1\">Fixing the problem<\/h2>\n<p>If your site is flagged for containing social engineering (deceptive content), ensure that<br \/>\n  your page doesn&#8217;t engage in any of the <a href=\"#examples\">practices<\/a>, and then follow these steps:<\/p>\n<ol>\n<li>\n    <b>Check in Search Console<\/b>.<\/p>\n<ul>\n<li>\n        <a href=\"https:\/\/support.google.com\/webmasters\/answer\/2739618\" class=\"external-link\">Verify that you own your site in Search Console<\/a><br \/>\n        and that no new, suspicious owners have been added.\n      <\/li>\n<li>\n<p>\n          Check the<br \/>\n          <a href=\"https:\/\/search.google.com\/search-console\/security-issues\" class=\"external-link\">Security Issues report<\/a><br \/>\n          to see if your site is listed as containing deceptive content (the<br \/>\n          reporting term for social engineering). If the report contains sample flagged URLs, visit<br \/>\n          some of those URLs listed in the report, but use a computer that&#8217;s not inside the network<br \/>\n          that is serving your website (clever hackers can disable their attacks if they think the<br \/>\n          visitor is a website owner).\n        <\/p>\n<p>\n          If the report doesn&#8217;t contain sample URLs and you&#8217;re confident your site doesn&#8217;t contain<br \/>\n          social engineering (deceptive content),<br \/>\n          <a href=\"https:\/\/support.google.com\/webmasters\/answer\/9044101#fix\" class=\"external-link\">request a security review<\/a><br \/>\n          in the Security Issues report.\n      <\/li>\n<\/ul>\n<\/li>\n<li>\n    <b>Remove deceptive content<\/b>. Ensure that none of your site&#8217;s pages contain<br \/>\n    deceptive content. If you believe Safe Browsing has classified a web page in error,<br \/>\n    <a href=\"https:\/\/www.google.com\/safebrowsing\/report_error\/\" class=\"external-link\">report it<\/a>.\n  <\/li>\n<li>\n    <b>Check the third-party resources included in your site<\/b>. Ensure that any ads, images, or<br \/>\n    other embedded third-party resources on your site&#8217;s pages are not deceptive.<\/p>\n<ul>\n<li>Note that ad networks may rotate the ads shown on your site&#8217;s pages. Therefore, you<br \/>\n        might need to refresh a page a few times before you&#8217;re able to see any social<br \/>\n        engineering ads appear.<\/li>\n<li>Some ads may appear differently on mobile devices and desktop computers. You can use<br \/>\n        the <a href=\"https:\/\/support.google.com\/webmasters\/answer\/9012289\" class=\"external-link\">URL<br \/>\n        Inspection tool<\/a> to view your site in both mobile and desktop views.<\/li>\n<li>Follow the <a href=\"#third-party-guidelines\">third-party service guidelines<\/a> for any third-party services,<br \/>\n        such as payment services, that you use in your site.<\/li>\n<\/ul>\n<\/li>\n<li>\n    <b>Request a review<\/b>. After you remove all social engineering content from your site, you can<br \/>\n    <a href=\"https:\/\/support.google.com\/webmasters\/answer\/9044101#fix\" class=\"external-link\">request a security review<\/a><br \/>\n    in the Security Issues report. A review can take several days to complete.\n  <\/li>\n<\/ol>\n<h3 id=\"third-party-guidelines\" tabindex=\"-1\">Third-party service guidelines<\/h3>\n<p>If you include a third-party service in your site, we recommend that you meet the following conditions<br \/>\n  in order to avoid being labeled as social engineering:<\/p>\n<ul>\n<li>On every page, the third-party site clearly includes the third-party brand in a way<br \/>\n    that ensures users understand who is operating the site. For example, by including the<br \/>\n    third-party brand at the top of the page.<\/li>\n<li>On every page that contains first-party branding, explicitly state the relationship between<br \/>\n    the first and third party, and provide a link for more information. For example, a statement<br \/>\n    like this:<\/p>\n<p><i>This service is hosted by Example.com on behalf of Example.charities.com. More<br \/>\n      information.<\/i><\/p>\n<\/li>\n<\/ul>\n<p>A good usability guideline is whether a user viewing the page in isolation understands which<br \/>\n  site they are on, and the relationship between the first and third party at all times.<\/p>\n<aside class=\"note\">\n  <b>Best practice:<\/b> If you need a third party to perform a basic support service<br \/>\n  for your site, a best practice is to use an industry standard third party for that service.<br \/>\n  For example, to manage user authentication on your site, use<br \/>\n  <a href=\"https:\/\/oauth.net\/\" class=\"external-link\">OAuth<\/a> rather than managing authentication<br \/>\n  yourself.<\/aside>\n<section background=\"grey\" header-position=\"top\">\n<p>\n    If you&#8217;re a Search Console user and are having trouble with persistent or unfixable security issues on your site, you can let us know.\n      <\/p>\n<p align=\"center\"><a class=\"button button-primary\" href=\"https:\/\/support.google.com\/webmasters\/contact\/report_security_issues\" class=\"external-link\">Report a security issue<\/a><\/p>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>Social engineering includes phishing and fake sites, and is a technique to trick users into doing something dangerous. This document provides an overview of social engineering and preventative measures.<\/p>\n","protected":false},"menu_order":136,"template":"","meta":{"footnotes":""},"ar_kb_kategori":[699],"ar_kb_etiket":[],"class_list":["post-25610","ar_kb","type-ar_kb","status-publish","has-post-thumbnail","hentry","ar_kb_kategori-preventing-and-monitoring-abuse"],"_links":{"self":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb\/25610","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb"}],"about":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/types\/ar_kb"}],"version-history":[{"count":0,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb\/25610\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/media\/27608"}],"wp:attachment":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/media?parent=25610"}],"wp:term":[{"taxonomy":"ar_kb_kategori","embeddable":true,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb_kategori?post=25610"},{"taxonomy":"ar_kb_etiket","embeddable":true,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb_etiket?post=25610"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}