When “Verified” Google Bots Are the Suspicious Traffic

A major global financial institution recently saw a sharp rise in bot traffic hitting their deployments. The search queries coming through were bizarre and clearly unrelated to financial services. Concerned, their security team deployed Vercel’s BotID with its invisible CAPTCHA to filter the traffic and pinpoint the source before things escalated.

The results, however, defied expectations. The traffic wasn’t coming from malicious scrapers or attack infrastructure. Every single request traced back to bots.fyi-verified Google crawlers—Googlebot, Google AdsBot, and other legitimate Google services.

international shipping from uk to usa royal mail✅【TG:@-----】✅【欧美7折代付】【7折代缴Fedex】

lucky activate sim card✅【TG客服@----】✅【全球SIM定制】【源头批发】

JPNTT Docomo电商注册卡TG飞机@----

2025年全球接码注册TG飞机@----

8位顺子靓号(----.vip)

estes express lines colorado springs reviews✅【TG:@-----】✅【7折付关税】【7折代付快递费】

your香港卡✅【TG客服@----】✅【全球SIM定制】【源头批发】

data sim hong kong✅【TG:@-----】✅【双向Esim】【货源稳定】

estes express lines colorado springs reviews✅【TG:@-----】✅【7折付关税】【7折代付快递费】

秦皇岛google外贸推广【TG飞机∶@-----】INS,FACEBOOK代推广】秦皇岛google外贸推广【T

postnl hk✅【TG:@----】✅【7折付关税】【7折代付快递费】

💘Google account for sale ❤T:----❤ Main business: foreign trade website construction Google SEO [white hat, bag ranking] Gambling home page does all kinds of extrapolation so

how to find tracking number on amazon after delivery✅【TG:@----】✅【欧美7折代付】【7折代缴Fedex】

注册whats注册教程2025TG飞机@----

注册闲鱼注册教程2025TG飞机@----

shopee注册接码🔥〖✈️TG:@----〗🔥〖全球直达〗〖源头直码〗

东欧接码注册卡预付费短信卡TG✈@----

日本OCN Mobile ONE短信卡TG飞机@----

牙买加双向短信🔥〖✈️TG:@----〗🔥〖双向短信〗〖定制接码〗

日本Excite Mobile语音卡TG飞机@----

北美接码注册卡0月租短信卡TG✈@----

JPUQ Mobile跨境电商手机卡TG飞机@----

Verified Google bots were systematically searching for strings that had no connection to banking or finance. The question was why.

A Legacy of SEO Poisoning

An audit of the institution’s site history revealed the answer. Years earlier, before their migration to Vercel, the older infrastructure had been compromised via an SEO poisoning attack. In such an attack, malicious actors manipulate a site so search engines index attacker-controlled content. If a site has a search endpoint like /search?q=, attackers generate thousands of URLs such as /search?q=spam-keyword and trick search engines into indexing them.

Those poisoned pages then surface in search results, funneling users to spam or malicious content hosted on what looks like a legitimate domain.

In this case, Google had indexed thousands of these poisoned pages years ago. Even though the institution had since moved to entirely new infrastructure on Vercel, Google’s index still held those URLs. The search giant’s crawlers were now methodically re-crawling that stale content, causing the strange query patterns in current logs. What looked like an active attack was actually Google refreshing outdated indexed pages from a historical breach.

Identification Before Blocking

Because BotID clearly identified the traffic as legitimate Google, the team could pivot from a defensive stance to a clean-up operation. The correct steps were:

  1. Update robots.txt to disallow crawling of search parameter patterns.
  2. Submit removal requests via Google Search Console for the poisoned indexed URLs.
  3. Monitor de-indexing progress while letting legitimate Google crawlers operate normally.

Had they acted on the surface symptoms, they might have tried to block Google’s bots outright—an exercise that would be both technically futile and damaging to their search ranking.

Bot Identification as Root-Cause Analysis

The episode underscores a key engineering principle: identifying bot traffic is just as crucial as blocking it. Vercel’s verified bot registry, which powers BotID, prevented a costly misclassification of legitimate crawlers and exposed the real problem—not active malice, but lingering technical debt manifesting through search engine behavior.

When logs show unusual patterns, the most valuable move is often to understand the source before touching any firewall rules. Proper identification tells you whether you’re facing a live threat or a symptom of something older and deeper.