Back-to-School Shopping Is a $100B+ Target for Malvertising

GeoEdge security research finds attackers targeting high-intent US shoppers through deceptive ads, cloaked landing pages, and in-app campaigns, creating new exposure for commerce media, publishers, and app developers.

 

A $100B+ Shopping Season Creates a Predictable Window for Fraud

U.S. consumers are expected to spend nearly $147 billion on back-to-school and back-to-college shopping in 2026, making it the second-largest consumer spending event of the year, behind only the holidays. That scale has turned the season into a high-risk exploitation window for malvertising. GeoEdge has identified threat actors actively targeting US users with fraudulent deal ads, cloned retailer landing pages, malicious redirects, and deceptive in-app creatives designed to capitalize on the surge in seasonal shopping traffic across web and in-app inventory.

For the advertising ecosystem, the risk extends beyond the user. Malicious campaigns are following seasonal ad spend across web, apps, and retail media, putting publishers, app developers, and retail media networks directly in the delivery path while exposing gaps in creative review, inventory quality, and post-click ad safety controls across the programmatic supply chain.`

 

Threat Actors Are Following Back-to-School Ad Spend

Since July 1, GeoEdge has tracked a rise in malicious activity across both web and in-app inventory, with e-commerce, social, communication, utility, deal, and coupon environments seeing heavier targeting as back-to-school advertising increases.

Threat activity is dominated by fake online stores, deceptive discount ads, counterfeit-product offers, and fraudulent shopping deals, often supported by typosquatted domains, retailer impersonation, cloned storefronts, and multi-stage redirect chains designed to obscure the final destination.

Adjacent schemes involving scholarships, student loans, fundraisers, and school communications are frequently delivered through the same infrastructure, including reused domains, cloaking services, landing-page templates, and ad accounts.

GeoEdge security researchers have linked this activity to financially motivated fraud rings that reuse the same playbook across major shopping periods. Threat actors warm up campaigns with benign creatives, then switch payloads after approval, using geo-targeting, device profiling, browser fingerprinting, and delayed activation to evade automated review.

Once live, these campaigns can redirect users to credential-harvesting pages, fake checkout flows, scareware, rogue software downloads, or payment and gift-card fraud. AI-generated copy and creative are also being used to strengthen retailer impersonation and make malicious landing pages, fake promotions, and social engineering lures more difficult to distinguish from legitimate offers.

 

The 2026 Back-to-School Threat Mix

  • Auto Redirect: Forced navigation to a malicious or deceptive destination without user interaction.
  • Deceptive Site: Impersonated or fraudulent pages designed to steal credentials, payment data, or other sensitive information.
  • Fake Antivirus & Cleaner Scams: Scareware that uses false infection alerts to push rogue software or unnecessary services.
  • Financial / Gift Card Scam: Fraudulent checkout, payment, or gift-card flows designed to steal funds or codes.
  • Tech Support Scam: Fake security alerts that direct users to fraudulent support numbers or remote-access schemes.
  • Malware / Malicious: Ads or landing pages that deliver malicious code, rogue installers, or credential-stealing payloads.
Figure 1. Back-to-school ad promoting a free iPhone 16e giveaway, flagged for Auto Redirect behavior.
Figure 1: iPhone 16e giveaway ad identified as part of an auto-redirect campaign
Figure 2. Back-to-school skincare ad from offering 20% off 90-day routines, flagged for Auto Redirect behavior.
Figure 2. Malicious back-to-school skincare ad promoting 20% off 90-day routines, detected triggering an unauthorized auto-redirect.
Figure 3. Back-to-school ad for a toaster oven, flagged for Auto Redirect behavior.
Figure 3. Back-to-school toaster oven ad identified as part of an auto-redirect campaign, redirecting users.

Retail Media Is Now Part of the Malvertising Attack Surface

Retail media networks are increasingly exposed to the same malicious campaign infrastructure moving through the broader programmatic ecosystem. As sponsored placements expand across owned-and-operated properties and off-site inventory, creative validation must account for more delivery paths, third-party demand sources, redirects, and post-click destinations.

During high-volume periods like back-to-school, threat actors can exploit the gap between creative approval and post-click behavior. A compliant creative can clear review while cloaked redirects, dynamically resolved domains, or conditional landing pages remain dormant until the campaign reaches a specific region, device, browser profile, or user.

For retail media operators, validating the creative alone does not provide visibility into the full attack chain. Redirect behavior, destination domains, landing-page changes, third-party scripts, and post-approval payload switching can alter the user experience after the original asset has been approved.

As RMNs extend campaigns beyond owned-and-operated inventory into external publisher and app environments, the attack surface expands as well. More intermediaries and delivery paths create additional points where malicious behavior can emerge between creative approval and the final user experience.

 

In-App Inventory Gives Attackers Another Path to the User

In-app malvertising follows a related but distinct delivery path. App developers often have limited visibility into creatives delivered through third-party monetization partners, while network-level controls may not detect malicious behavior that activates only under specific user or device conditions.

This makes mobile in-app inventory an attractive vector during back-to-school, particularly as shopping, coupon, deal-finder, utility, and other high-use apps experience seasonal increases in traffic.

GeoEdge research across the app ecosystem has identified deceptive landing pages cloned from legitimate retailers, fake discount codes, and counterfeit-product ads among the dominant lures used to move users from legitimate app inventory into fraudulent experiences.

The security challenge extends beyond the creative rendered inside the app. Redirects, external browser sessions, dynamically loaded landing pages, and conditional payloads can move the attack outside the original ad environment, limiting visibility into the complete user journey.

 

Staying Ahead of the Threat

GeoEdge’s security research team continues to track these campaigns across web, in-app, and retail media environments, documenting how threat actors adapt their infrastructure, evade detection, and reach users through digital advertising. For more insight into the threats impacting your inventory, connect with the GeoEdge team.

Alisha is a Technology Writer and Marketing Manager at GeoEdge. Her writing focuses on current events in the AdTech ecosystem and cyberattacks served through the digital advertising supply chain. You can find Alisha on LinkedIn to discuss brand building and happenings in AdTech.
NOT ALL MALVERTISING SOLUTIONS ARE CREATED EQUAL

Malvertising, the practice of sprinkling malicious code into legitimate-looking ads is growing more sophisticated. GeoEdge’s holistic ad quality solution has you covered.

TRUSTED BY:

450+ Publishers & Platforms