Hackers Poison Search Results to Deliver Cloaked Banking Phishing Pages
Attackers are manipulating Google and Bing search results to direct users to fake banking login pages using a technique called Chameleon SEO Poisoning.

Cybercriminals are increasingly sophisticated in their methods, now manipulating search engine results on platforms like Google and Bing to lure unsuspecting users into phishing traps. This new campaign, dubbed "Chameleon SEO Poisoning" by researchers at Fortra's FIRE (Fortra Intelligence and Research Experts), specifically targets bank customers by making fraudulent login pages appear as legitimate search results for high-intent queries such as "bank customer portal" or "credit card login."
The core of this attack lies in its deceptive cloaking mechanism. While automated scanners, security researchers, or even casual observers might see an inactive page or a harmless error when inspecting the malicious URL directly, the page dynamically transforms when a visitor arrives via a Google or Bing search result. This context-aware delivery allows the phishing pages to bypass many traditional security checks and reputation services, which often examine sites in isolation without considering the referral source. This evasion tactic grants attackers a longer window to harvest credentials before the malicious activity is detected and shut down.
This method represents a significant shift from traditional phishing tactics, which often rely on bulk email or SMS campaigns. Chameleon SEO Poisoning employs a "pull" model, drawing victims in precisely at the moment they are actively seeking to access their financial services. By leveraging search engine optimization (SEO) poisoning, attackers push their malicious sites higher in search rankings for specific, high-value keywords, making them appear as credible and relevant results.
Fortra Intelligence observed a notable increase in this activity during the second quarter of 2026, with several major financial institutions and their customers being targeted. The fake banking sites are meticulously crafted to be pixel-perfect replicas of legitimate portals, designed not only to steal usernames and passwords but also to hijack active user sessions. This level of detail aims to maximize the chances of successful credential theft and account compromise.
Security researchers emphasize that routine checks often fall short because they fail to replicate the user's context. To effectively identify these threats, security teams must test suspicious links using current browser profiles, including the correct search referral data, and ideally from the geographic region of the targeted bank's customer base. This approach helps reproduce the experience of an ordinary user rather than what a default script might encounter.
For consumers, the safest practice is to avoid using search results for accessing banking services altogether. Instead, users are strongly advised to utilize official mobile applications or pre-saved bookmarks. This simple habit significantly reduces exposure to deceptive pages that impersonate trusted brands and exploit the inherent trust users place in search engines.
Financial institutions and their security teams are urged to view search engine visibility as a critical part of their attack surface. Implementing context-aware monitoring, accelerating the review of cloaked content, and strengthening checks on newly registered domains are crucial steps in defending against these evolving threats. The prominence of a search result should never be mistaken for authenticity; verifying the path to financial services is paramount.