Attackers manipulate search results to steal banking credentials

0
238
Fake banking sites climb search rankings to target customers Credit: Cyber Security News
Fake banking sites climb search rankings to target customers Credit: Cyber Security News

Bank customers searching online for a login page are being targeted through a campaign that places fake banking websites among legitimate Google and Bing results.

Called Chameleon SEO Poisoning, the campaign turns searches such as bank customer portals and credit card logins into phishing opportunities. Victims who click a highly ranked result can be taken to convincing copies of banking websites designed to steal passwords and hijack active sessions.

Security researchers identified a sharp increase in the activity during the 2nd quarter of 2026. The campaigns targeted customers of several major financial institutions. The fraudulent sites are designed to appear harmless during routine security checks, allowing attackers to remain active longer and capture credentials.

The attackers use search engine optimisation poisoning to push malicious pages higher for high-intent searches. Rather than compromising legitimate websites, they register lookalike domains and create pages based on terms commonly used by bank customers.

The campaign differs from traditional phishing because it does not depend on bulk emails or text messages. Instead, it reaches users when they are actively searching for their bank.

The key technique is cloaking. When a security researcher, automated scanner, registrar or hosting provider visits a malicious domain directly, the site may show an inactive page or a fake 404 error. However, when the same address is accessed through a Google or Bing search result, it can display a convincing banking portal.

This allows the malicious pages to stay active for days or weeks. It can also cause security teams to dismiss alerts as false positives because automated tools may receive harmless content instead of the phishing page.

Researchers recommend testing suspicious results in the same conditions as affected users, including using a current consumer browser profile, passing the relevant search referral and, where necessary, checking from the geography of the targeted customers.

Defenders should also monitor newly registered lookalike domains and unusual high-ranking results for branded banking searches.

For consumers, the safest option is to access banking services through the official mobile app or a saved bookmark instead of relying on search results.

The campaign highlights a broader concern: search visibility has become part of the cybersecurity attack surface. A high-ranking result does not guarantee authenticity, making it important for banks, security teams and users to verify how they reach financial services.

Also read: Viksit Workforce for a Viksit Bharat

Do Follow: The Mainstream LinkedIn | The Mainstream Facebook | The Mainstream Youtube | The Mainstream Twitter

About us:

The Mainstream is a premier platform delivering the latest updates and informed perspectives across the technology business and cyber landscape. Built on research-driven, thought leadership and original intellectual property, The Mainstream also curates summits & conferences that convene decision makers to explore how technology reshapes industries and leadership. With a growing presence in India and globally across the Middle East, Africa, ASEAN, the USA, the UK and Australia, The Mainstream carries a vision to bring the latest happenings and insights to 8.2 billion people and to place technology at the centre of conversation for leaders navigating the future.