Site security and violations

Social engineering and deception

Bu sayfayı yapay zekâya sor

2 min read

Social engineering is deception aimed at extracting money or sensitive data — card details, credentials, phone numbers — from ordinary users. It is the most serious category in this list, because Yandex may show a warning about the site directly in search results.

The three tactics Yandex describes

  • Getting the click. Clickbait headlines and misleading content: fake news sites, imitation dating services or lotteries, offers of free or absurdly cheap goods, prizes, and easy-money platforms.
  • Manufacturing trust. Impersonating an official site through similar domains, interface elements and content; publishing fake positive reviews or false information.
  • Harvesting data. Fake checkout pages asking for card details; fake login and account-recovery forms; forms that promise access to content in exchange for a phone number or card and never deliver — including forms that quietly activate a paid auto-renewing subscription whose terms the user never sees.

The assumption Yandex makes about you

The remediation guidance is notable for what it assumes: if your site is suspected of social engineering, it may have been compromised by attackers. The first instruction is to check for malicious code, not to review your marketing. Phishing pages are routinely hosted on hacked legitimate sites — in a forgotten subdirectory, on an unused subdomain, inside an uploads folder — without the owner ever seeing them.

Where to look on a site you believe is clean

  • Files added or modified recently in web-writable directories, especially uploads.
  • Subdomains and directories nobody maintains: old campaigns, staging copies, a decommissioned CMS.
  • Pages in the console’s index reports that you do not recognise — Yandex crawled them, which means they exist.
  • Admin accounts you did not create, and plugins nobody remembers installing.

The legitimate-site version of this violation

Two patterns can be entirely unintentional: a subscription whose renewal terms are disclosed somewhere other than the point of payment, and a lead form promising something the user does not actually receive. Both match the description of collecting data under false pretences regardless of what was intended. Stating the terms next to the button rather than in a linked document costs nothing and removes the ambiguity.

Alien Road

Biz bunu nasıl uyguluyoruz

When this violation appears on a site whose owner is plainly not a fraudster, we start from Yandex’s own assumption and search for pages the owner does not know about. Every case we have handled was hosted content in a directory nobody had opened in years. The audit that finds it is the console’s own page list: if Yandex crawled a URL and nobody on the team recognises it, that is the thread to pull.

İlgili hizmetler

Share

© Copyright 2026 Alien Road. All rights reserved.