Hackers Poison Google and Bing Results With Banking Phishing Pages
Hackers are manipulating Google and Bing search results to push fake banking websites toward users searching for legitimate login pages. The campaign, known as Chameleon SEO Poisoning, uses lookalike domains and search-engine optimization techniques to make fraudulent banking pages appear trustworthy.


The attackers use cloaking techniques to hide the phishing content from security scanners and researchers. While direct visitors may see harmless pages or fake 404 errors, users arriving through search results can be shown convincing banking portals designed to steal login credentials and potentially hijack sessions.
Users should avoid accessing banking services through unfamiliar search results and instead use the official banking app or a trusted bookmark. Organizations should monitor suspicious lookalike domains, unusual search rankings and cloaked phishing pages. The key lesson is simple: a high-ranking Google or Bing result does not guarantee that a website is legitimate.
NPAV Total Security helps protect users from phishing websites, malicious links, malware, and other online threats—adding an extra layer of security against deceptive banking pages and SEO-based phishing attacks.