Search Results Hijacked: Banking Phishing Pages Found in Google & Bing

Attackers are now manipulating search engine results on Google and Bing, causing highly ranked links to redirect users to fraudulent banking login pages. This method, dubbed “Chameleon SEO Poisoning,” exploits user intent by targeting searches such as “bank customer portal” or “credit card login,” replacing legitimate service results with mimicry sites that steal credentials. ([cybersecuritynews.com](https://cybersecuritynews.com/hackers-poison-google-bing-results/))

Cybersecurity researchers at Fortra Intelligence and Research Experts (FIRE) observed a sharp rise in this tactic during Q2 2026, with several major financial institutions and their customers becoming targets. The deceptive pages appear among search results but are in fact controlled by threat actors. ([cybersecuritynews.com](https://cybersecuritynews.com/hackers-poison-google-bing-results/))

How the Attack Works

The technique begins with the creation of lookalike domains—addresses that closely resemble the real bank’s site. These fake portals are optimized for specific search queries so that they rank highly in search engine result pages (SERPs). Rather than relying on spam emails or messages, this strategy waits for victims to search for their bank. When users click the poisoned link, they encounter a replica site built to harvest login credentials and hijack ongoing sessions. ([cybersecuritynews.com](https://cybersecuritynews.com/hackers-poison-google-bing-results/))

A key element is “cloaking.” If someone visits the site directly (for example, via a security researcher, registrar, or online scanner), they might see harmless content or a generic 404 error. But when a visitor arrives via a search result from Google or Bing, the attacker’s server delivers the malicious banking portal. This selective display enables the fraudulent page to stay live for longer, avoiding detection. ([cybersecuritynews.com](https://cybersecuritynews.com/hackers-poison-google-bing-results/))

Challenges for Detection and Defense Measures

Traditional security tools often fall short because they typically evaluate a site in isolation—without the context of how a user arrived there. As a result, routine scans may only see benign content and incorrectly clear the malicious domains. ([cybersecuritynews.com](https://cybersecuritynews.com/hackers-poison-google-bing-results/))

To counter these attacks, experts recommend mirroring the exact path a real user would take: use a consumer browser, include the search engine referral, and, where relevant, check from a location typical for the bank’s customers. Monitoring newly registered lookalike domains and unexpected top-ranked results for banking terms also helps. ([cybersecuritynews.com](https://cybersecuritynews.com/hackers-poison-google-bing-results/))

For individuals, the safest way to reach banking sites is through a trusted URL—using saved bookmarks or official mobile apps—rather than clicking search results. For organizations, search visibility needs to be treated as part of the attack surface. Employing contextual monitoring, accelerating review of cloaked content, and scrutinizing rapid domain registrations are key defenses. ([cybersecuritynews.com](https://cybersecuritynews.com/hackers-poison-google-bing-results/))

Indicators of compromise noted by researchers include private second-level domains like “.ph.com” and “.gr.com,” which have been used in these campaigns. These domains often look legitimate but are several steps removed from actual bank domain registrations. ([cybersecuritynews.com](https://cybersecuritynews.com/hackers-poison-google-bing-results/))

This trend demonstrates that prominence in search results—once seen as a marker of trust—is increasingly being hijacked to facilitate sophisticated phishing. Users, security teams, and financial institutions must verify their pathways to services to stay ahead of these evolving threats.

Analysis: This emerging “search poisoning” strategy represents a significant evolution in phishing tactics. By moving the attacker’s trigger from user-initiated messages to passive searches, the threat enters the general trust people place in search engines. As monitoring and prevention tools adapt, it’s crucial that defensive focus shifts toward realistic simulations of user behavior rather than isolated site inspections. Expect domain registration practices to become tighter, and for organizations to deepen collaboration with search platforms to reduce the time poisoned results stay live.