Hackers are increasingly using online ads for malicious purposes. Often, it’s happening through routine Google searches.
These schemes are dubbed malvertising, and cyber criminals are striking more often and with increased sophistication. In fall 2023, cybersecurity software firm Malwarebytes tracked a 42% increase month-over-month in malvertising incidents in the U.S. All types of brands are being targeted, whether it’s for phishing purposes or for actual malware, said Jérôme Segura, senior director of research at Malwarebytes. “What I’m seeing is just the tip of the iceberg,” he said.
Many of these rogue ads appear as sponsored content during a search engine query on a desktop or mobile device. But malicious code can also be hidden in ads that appear on mainstream websites consumers routinely visit. Some of these ads will only ensnare consumers who click on them, but in some cases, people can be vulnerable in a more passive way — sometimes just by visiting an infected site, said Erich Kron, security awareness advocate for KnowBe4, a security awareness and training company.
Corporate employees can also be targets of malvertising, Segura said. He cited a few actual examples that were recently uncovered involving big companies. Lowe’s staff members were targeted via a Google ad for an employee portal claiming to be associated with the retailer. Clicking on the link, “myloveslife.net,” which contains a misspelling of the company’s name, took users to a phishing page with Lowe’s logo. This had the potential to confuse employees since many don’t know offhand the URL for their internal website. “You see the brand, even the official logo of that brand, and for you it’s enough to think it’s real,” Segura said.
Segura also cited an ad meant to impersonate Salesforce-owned communication tool Slack. Initially, by clicking on the ad, he was redirected to a price page on Slack’s official website. But suspecting bad actors were at play, Segura dug deeper and uncovered an impersonation ploy, which involved trying to convince unsuspecting users to download something purporting to be the Slack app.
It’s not Google’s fault, but don’t trust it
Malvertising is not new, but cybercriminals are getting smarter and the ads are often so realistic that it’s easy to be duped. The problem is exacerbated by the fact that so many people use and trust Google as a search engine, where many of the malicious ads can be found. It’s not a problem with Google, per se; malicious ads can also show up in queries using other search engines like Microsoft’s Bing. It’s just that Google is such a widely used search engine and people trust it and let their guard down. “You see something appearing on a Google search, you kind of assume it is something valid,” said Stuart Madnick, professor of information technology at MIT Sloan School of Management.
Consumers can also fall prey to malicious ads on trusted websites they visit regularly. Many of these ads are legitimate, but some bad ones can slip through the cracks. “It’s like the post office. Does the mailman check every letter you get to make sure it’s really from Publishers Clearing House?” Madnick said.
Be very careful about where and when you click
Consumers can take steps to protect themselves against malvertising attempts. For instance, they should avoid clicking on sponsored links that come up during an internet search. Often, the first ad below the sponsored one will be the product they are looking for, and since it isn’t sponsored, there’s less chance of being sidelined by malicious code or a phishing attempt.
If you do click on a sponsored link, check the URL at the top of the web page to make sure it’s really where you meant to be before taking any other actions. For example, if you’re trying to visit Gap.com, make sure you’re not really on Gaps.com. Consumers who find themselves on a suspicious site should close the window immediately, said Avinash Collis, assistant professor at Carnegie Mellon University’s Heinz College. In most cases, this will avoid further trouble, he said.
Consumers also need to be careful about clicking ads they see on trusted websites, Kron said. They may, for instance, see ads for products that are much lower in cost than elsewhere. But Kron recommends not clicking and instead visiting the trusted website of the product seller. Most of the time, consumers will be able to search on the provider’s site if a special deal exists, or the deal will be highlighted on the main page of the trusted website, he said.
Also avoid calling a telephone number listed in a sponsored ad because it could be a fake telephone number. If you call it, cyber thieves could gain access to your computer or your personal information, depending on the scheme, said Chris Pierson, CEO of BlackCloak, a cybersecurity and privacy platform that provides digital executive protection for corporate executives.
Consumers should make sure they are calling a number from official product documentation they have in their possession, Pierson said. Alternatively, consumers could visit the company’s home page for this information. “Doing a [web] search could return results that are not sponsored by the company and telephone numbers that are associated with cybercriminals. All it takes to get an ad out there is money and, of course, cybercriminals that are stealing money, have the ability to pay for that bait,” Pierson said.
Avoid ‘drive-by-downloads’
Consumers should also make sure the operating system and internet browsers are up-to-date on their computer and mobile phone.
So-called drive-by-downloads, which can impact people who merely visit a website infected with malicious codes, generally rely on a vulnerability in the user’s browser. This is not as much of a threat for people who keep their browsers and browser extensions up-to-date, Kron said.
Consumers could also consider installing anti-malware software on their computer and phone. Another option is to avoid ads by installing an ad blocker extension such as uBlock Origin, a free and open-source browser extension for content filtering, including ad blocking. Some consumers may also opt to install a privacy browser such as Aloha, Brave, DuckDuckGo or Ghostery on their personal devices. Many privacy browsers have embedded ad blockers; consumers may still see sponsored ads, but they will see fewer of them, which minimizes the chances of malvertising.
Consumers who come across suspicious ads should report them to the applicable search engine for investigation and removal if deemed malicious, Collis said. This can help protect other people from being ensnared.
Proper safety precautions are especially important since there are millions of ads on the internet and cyber thieves are relentless. “You should assume that this could happen to you no matter how careful you are,” Madnick said.
The SpaceX Starship sits on a launch pad at Starbase near Boca Chica, Texas, on October 12, 2024, ahead of the Starship Flight 5 test. The test will involve the return of Starship’s Super Heavy Booster to the launch site.
Sergio Flores | Afp | Getty Images
Over the weekend, Elon Musk got his new company town along the Texas Gulf Coast. Controlling the city are three SpaceX employees, who all ran unopposed.
As NBC News reported, the election determining incorporation of the city of Starbase concluded on Saturday night, with 212 votes in favor and only six against. Just 143 votes were needed for the measure to pass.
Starbase was victorious in becoming a type C city, which in Texas applies to a previously unincorporated city, town or village of between 201 and 4,999 inhabitants. The city includes the SpaceX launch facility and company-owned land covering a 1.6 square-mile area.
The mayor is 36-year-old Bobby Peden, who has spent more than 12 years working for SpaceX and is currently vice president for Texas test and launch operations. Prior to joining the rocket maker in 2013, Peden was a graduate research assistant at the University of Texas at Austin, according to his LinkedIn profile.
Starbase has two commissioners, both from the SpaceX employee ranks.
One is Jenna Petrzelka, 39, who was an operations engineering manager at SpaceX until July, and now identifies as a philanthropist, according to her application to be on the ballot. She’s married to Joe Petrzelka, a vice president of Starship engineering and almost 14-year veteran at SpaceX.
The other commissioner is Jordan Buss, 40, a senior director of environmental health and safety for SpaceX who joined the company in 2023.
Musk, who has assumed a central role in President Donald Trump’s administration responsible for slashing the size of the federal government, began acquiring land for SpaceX in Boca Chica, Texas, about a decade ago. The first integrated Starship vehicle launched from the site, known as Starbase, in April 2023, and exploded in mid-flight.
The U.S. Fish and Wildlife Service soon disclosed details about the aftermath of the explosion, including that a “3.5-acre fire started south of the pad site on Boca Chica State Park land,” following the test flight.
State and federal regulators have fined SpaceX for violations of the Clean Water Act, and said the company had repeatedly polluted waters in the Boca Chica area. Environmental advocates and indigenous groups have also sued both the Federal Aviation Administration and SpaceX over the company’s flight tests and launch activity in the area.
Those groups said in legal filings that SpaceX caused harm to local habitat and endangered species due to vehicle traffic, noise, heat, explosions and fragmentation caused by the company’s construction, rocket testing and launch practices.
A SpaceX spokesperson didn’t immediately respond to a request for comment.
In a post on X on Saturday, the account for StarbaseTX wrote, “Becoming a city will help us continue building the best community possible for the men and women building the future of humanity’s place in space.”
Shares of Hims & Hers Health fell in extended trading on Monday after the company reported first-quarter earnings that beat analysts’ expectations but offered weaker-than-expected guidance.
Here’s how the company did based on average analysts’ estimates compiled by LSEG:
Earnings per share: 20 cents vs. 12 cents
Revenue: $586 million vs. $538 million
Revenue at the telehealth company increased 111% in the first quarter from $278.2 million during the same period last year, according to a release. Hims & Hers reported a net income of $49.5 million, or 20 cents per share, compared to $11.1 million, or 5 cents per share, during the same period a year earlier.
For its second quarter, Hims & Hers said it expected to report revenue between $530 million and $550 million, short of the $564.6 million expected by analysts polled by StreetAccount. The company said its adjusted earnings before interest, taxes, depreciation and amortization, or EBITDA, for the quarter will be between the range of $65 million and $75 million, while StreetAccount analysts were expecting $70.4 million.
Hims & Hers’ stock has had a turbulent start to the year, notching several double-digit moves over the past few months. On April 29, shares rocketed up 20% after Novo Nordisk said it would offer its weight loss drug Wegovy through telehealth providers such as Hims & Hers.
The company said Monday that more collaborations are coming.
Read more CNBC tech news
“Over time, we expect wider collaboration across the industry, inclusive of pharmaceutical players, innovative leaders in diagnostic and preventative testing, and world class providers,” Hims & Hers CEO Andrew Dudum said in the release. “We believe this will strengthen our ecosystem and position us to curate a best-in-class offering that can reach tens of millions of people.”
Hims & Hers reported adjusted EBITDA of $91.1 million for its first quarter, up from $32.3 million last year and above the $61.3 million expected by StreetAccount.
Earlier on Monday, Hims & Hers announced Nader Kabbani will join the company as its chief operations officer. Kabbani spent nearly 20 years at Amazon, where he oversaw the launch of Amazon Pharmacy, the company’s acquisition of PillPack and its global Covid-19 Vaccination Task Force.
Hims & Hers will hold its quarterly call with investors at 5:00 p.m. ET.
Hinge Health on Monday updated its prospectus to include the results from its first quarter, which showed accelerating revenue growth over its fourth quarter.
The digital physical therapy startup filed to go public in March, but it has not shared a price range yet. Hinge said that revenue in its first quarter climbed 50% to $123.8 million, up from $82.7 million during the same period last year. Hinge reported $117.3 million in revenue during its fourth quarter, up 44% from the same period in 2023.
Hinge said its net income for the period was $17.1 million after taxes, up from a net loss of $26.5 million after taxes during the same period last year.
The company is attempting to go public at a time of extreme economic uncertainty and market volatility, spurred largely by President Donald Trump’s sweeping tariff policy. Several companies, including online lender Klarna and ticket marketplace StubHub, have delayed their long-awaited IPOs.
Hinge’s updated prospectus signals to investors that the company is planning to forge ahead.
More CNBC health coverage
While the company’s revenue jumped 50%, the cost of goods sold fell slightly. That allowed Hinge to lift its gross margin to 81% from 70% a year earlier and record an operating income of $13.1 million after losing $31. 4 million in the same period a year earlier.
Hinge uses software to help patients treat acute musculoskeletal injuries, chronic pain and carry out post-surgery rehabilitation remotely. Large employers cover the costs so their employees can access Hinge’s app-based virtual physical therapy, as well as its wearable electrical nerve stimulation device called Enso.
Daniel Perez, Hinge’s CEO, and Gabriel Mecklenburg, the company’s executive chairman, co-founded the company in 2014 after experiencing personal struggles with physical rehabilitation.
Correction:A previous version of this story incorrectly stated that Q1 2025 was the company’s first profitable quarter. Hinge was profitable previously.