GeoEdge security research finds attackers targeting high-intent US shoppers through deceptive ads, cloaked landing pages, and in-app campaigns, creating new exposure for commerce media, publishers, and app developers.
A $100B+ Shopping Season Creates a Predictable Window for Fraud
U.S. consumers are expected to spend nearly $147 billion on back-to-school and back-to-college shopping in 2026, making it the second-largest consumer spending event of the year, behind only the holidays. That scale has turned the season into a high-risk exploitation window for malvertising. GeoEdge has identified threat actors actively targeting US users with fraudulent deal ads, cloned retailer landing pages, malicious redirects, and deceptive in-app creatives designed to capitalize on the surge in seasonal shopping traffic across web and in-app inventory.
For the advertising ecosystem, the risk extends beyond the user. Malicious campaigns are following seasonal ad spend across web, apps, and retail media, putting publishers, app developers, and retail media networks directly in the delivery path while exposing gaps in creative review, inventory quality, and post-click ad safety controls across the programmatic supply chain.`
Threat Actors Are Following Back-to-School Ad Spend
Since July 1, GeoEdge has tracked a rise in malicious activity across both web and in-app inventory, with e-commerce, social, communication, utility, deal, and coupon environments seeing heavier targeting as back-to-school advertising increases.
Threat activity is dominated by fake online stores, deceptive discount ads, counterfeit-product offers, and fraudulent shopping deals, often supported by typosquatted domains, retailer impersonation, cloned storefronts, and multi-stage redirect chains designed to obscure the final destination.
Adjacent schemes involving scholarships, student loans, fundraisers, and school communications are frequently delivered through the same infrastructure, including reused domains, cloaking services, landing-page templates, and ad accounts.
GeoEdge security researchers have linked this activity to financially motivated fraud rings that reuse the same playbook across major shopping periods. Threat actors warm up campaigns with benign creatives, then switch payloads after approval, using geo-targeting, device profiling, browser fingerprinting, and delayed activation to evade automated review.
Once live, these campaigns can redirect users to credential-harvesting pages, fake checkout flows, scareware, rogue software downloads, or payment and gift-card fraud. AI-generated copy and creative are also being used to strengthen retailer impersonation and make malicious landing pages, fake promotions, and social engineering lures more difficult to distinguish from legitimate offers.
The 2026 Back-to-School Threat Mix
- Auto Redirect: Forced navigation to a malicious or deceptive destination without user interaction.
- Deceptive Site: Impersonated or fraudulent pages designed to steal credentials, payment data, or other sensitive information.
- Fake Antivirus & Cleaner Scams: Scareware that uses false infection alerts to push rogue software or unnecessary services.
- Financial / Gift Card Scam: Fraudulent checkout, payment, or gift-card flows designed to steal funds or codes.
- Tech Support Scam: Fake security alerts that direct users to fraudulent support numbers or remote-access schemes.
- Malware / Malicious: Ads or landing pages that deliver malicious code, rogue installers, or credential-stealing payloads.



Retail Media Is Now Part of the Malvertising Attack Surface
Retail media networks are increasingly exposed to the same malicious campaign infrastructure moving through the broader programmatic ecosystem. As sponsored placements expand across owned-and-operated properties and off-site inventory, creative validation must account for more delivery paths, third-party demand sources, redirects, and post-click destinations.
During high-volume periods like back-to-school, threat actors can exploit the gap between creative approval and post-click behavior. A compliant creative can clear review while cloaked redirects, dynamically resolved domains, or conditional landing pages remain dormant until the campaign reaches a specific region, device, browser profile, or user.
For retail media operators, validating the creative alone does not provide visibility into the full attack chain. Redirect behavior, destination domains, landing-page changes, third-party scripts, and post-approval payload switching can alter the user experience after the original asset has been approved.
As RMNs extend campaigns beyond owned-and-operated inventory into external publisher and app environments, the attack surface expands as well. More intermediaries and delivery paths create additional points where malicious behavior can emerge between creative approval and the final user experience.
In-App Inventory Gives Attackers Another Path to the User
In-app malvertising follows a related but distinct delivery path. App developers often have limited visibility into creatives delivered through third-party monetization partners, while network-level controls may not detect malicious behavior that activates only under specific user or device conditions.
This makes mobile in-app inventory an attractive vector during back-to-school, particularly as shopping, coupon, deal-finder, utility, and other high-use apps experience seasonal increases in traffic.
GeoEdge research across the app ecosystem has identified deceptive landing pages cloned from legitimate retailers, fake discount codes, and counterfeit-product ads among the dominant lures used to move users from legitimate app inventory into fraudulent experiences.
The security challenge extends beyond the creative rendered inside the app. Redirects, external browser sessions, dynamically loaded landing pages, and conditional payloads can move the attack outside the original ad environment, limiting visibility into the complete user journey.
Staying Ahead of the Threat
GeoEdge’s security research team continues to track these campaigns across web, in-app, and retail media environments, documenting how threat actors adapt their infrastructure, evade detection, and reach users through digital advertising. For more insight into the threats impacting your inventory, connect with the GeoEdge team.


