Most of us find our bank's login page the same way we find everything else: we search for it. You type "Chase customer portal" or "credit card login," click the first result, and sign in. That habit, so ordinary it barely registers as a decision, is exactly what a new wave of phishing is built to exploit.
Researchers at Fortra recently documented a technique they call Chameleon SEO Poisoning, and reported by Help Net Security. Over three months of tracking, Fortra's threat intelligence team saw a 40% jump in cases in the second quarter of 2026. What makes it worth understanding is not just that fake bank sites exist. It is how carefully these ones are engineered to appear at the exact moment you go looking for your bank, and to vanish the instant anyone tries to check them.
Let me walk through what is actually happening, why the usual safety nets miss it, and what genuinely stops it.
What happened
Fortra's researchers found criminals running counterfeit banking and credit-card login pages that consistently rank near the top of Google and Bing for high-intent searches, phrases like "[Bank Name] Customer Portal" or "Credit Card Login." These are the searches people make when they fully intend to sign in, which is what makes them so valuable to an attacker. Someone searching that phrase is not browsing. They are seconds away from typing a username and password.
Two details make this campaign stand out from ordinary bank phishing.
First, the pages are not hacked versions of real sites. They live on freshly registered lookalike domains, specifically typosquats built on unusual second-level domains such as .ph.com and .gr.com. To a hurried eye, a domain like yourbank.ph.com can pass for the real thing, especially inside a search result where the full address is easy to skim past.
Second, and this is the clever part, the fake sites are designed to hide from the tools meant to catch them. Fortra calls this "presentation control." The server watches how each visitor arrives and decides what to show them. That is the behavior that earned the technique its name, and it is worth taking apart.
How it works
There are three moving pieces: getting the fake page in front of you, disguising the domain, and hiding the page from anyone who investigates. Together they form a surprisingly complete little machine.
1. SEO poisoning puts the fake above the real
"SEO poisoning" is the practice of gaming search-engine rankings so that a malicious page outranks the legitimate one for a chosen keyword. Attackers build out pages, signals, and links designed to look authoritative to a search engine's ranking algorithm, and aim them at commercial, high-intent terms. When it works, the poisoned page sits at or above the top of the results for exactly the phrase a target is most likely to type. In this campaign, that phrase is your bank's login.
The important consequence for you: ranking is not a trust signal. A result being first, and even carrying a clean-looking address, tells you nothing about whether it is your bank. Search engines rank pages by relevance and authority signals, not by verifying who really owns them.
2. Typosquatting on odd domains hides the tell
The single most reliable way to catch a fake login page is to read the address bar, because a counterfeit cannot actually be your bank's genuine domain. This campaign is engineered to blunt that check. By registering typosquats on second-level domains like .ph.com and .gr.com, the attackers produce addresses that contain your bank's name and end in something that looks vaguely official. Glanced at at speed, under the assumption that the top search result is safe, the difference is easy to miss.
3. Presentation control makes the page play dead
This is the mechanism that keeps these sites online for days or weeks when most phishing pages are taken down in hours.
The server behind the fake site inspects the "referrer," the piece of information a browser passes along that says where a click came from. It then serves completely different content based on that signal:
Arrive by typing the address directly, or with no search-engine referrer attached, and the site serves a dead, broken, offline-looking page. Nothing to see. Nothing to report.
Arrive by clicking through from the poisoned search result, and the same domain instantly presents a polished, convincing fake bank login page, ready to capture whatever you type.
Fortra demonstrated this side by side: one domain, two completely different faces, decided entirely by how the visitor got there. This is a classic evasion tactic known as cloaking, and here it is aimed directly at defenders. Automated security scanners, malware crawlers, and takedown teams typically visit a reported URL directly, cold, with no search referrer. They see the dead page, conclude there is nothing malicious, and move on. The threat stays live for the only audience that matters to the attacker: real people clicking from a real search.
Why the usual protections miss it
It helps to be precise about why this is hard to stop, because the honest answer is that most of the layers people rely on were never positioned to catch it.
Search engines are not built to verify ownership, so a poisoned result can legitimately rank first. URL-reputation services and safe-browsing lists depend on a scanner having visited the page and judged it malicious, and cloaking is specifically designed so the scanner never sees the malicious version. Email filters are irrelevant here, because there is no email; the lure is a search result you went looking for yourself. And "just check the URL," the advice that usually works, is exactly what the typosquat-on-an-unusual-domain trick is built to defeat in the half-second before you sign in.
What is left, the thing every one of those layers routes around, is the real page as it is actually rendered in your browser, at the moment you land on it, with your real referrer attached. That is the one view the attacker cannot fake away, because it is the view they built the whole scheme to deliver. It is also the exact view a scanner never gets.
How Haven helps
This is the gap Haven is built to close, and this campaign is close to a textbook case for it.
Haven runs in your browser and analyzes the actual page in front of you at the moment you arrive, not a cold scan performed hours earlier from somewhere else. When you click through from a search result and the site drops its "dead page" disguise to show you a fake bank login, that live, fully rendered counterfeit is precisely what Haven inspects. Rather than trusting the ranking, the address, or how you got there, Haven examines the page itself, the way it impersonates a real bank's sign-in, and flags it as fake before you type your credentials.
That approach neutralizes each piece of the attack in turn. The poisoned ranking does not matter, because Haven does not treat "first result" as safe. The typosquat domain does not need to be spotted by you in a hurry, because Haven is reading the page, not relying on your glance. And the cloaking that defeats scanners works against them precisely because they visit cold; Haven is right there with you when the mask comes off, seeing the same fake login the attacker intended for you to trust. If you ever want a second opinion on a link before you click, you can also paste it into Haven's free link checker.
To be clear about scope: Haven works at the page, in the browser. It flags the fake bank login before you enter anything. It is not a password manager or a bank fraud service, and it cannot reverse a login you have already handed over on a fake site. What it does is make sure you almost never get there, by catching the counterfeit at the one moment, and from the one vantage point, that this attack was designed to keep hidden.
How to protect yourself
The researchers' own advice for consumers is refreshingly blunt, and it is worth following:
Stop searching for your bank's login page. Bookmark the real address once, from a session you trust, and use the bookmark every time. Or use your bank's official mobile app, which does not route through a search bar at all.
Treat the top search result as unverified, not trusted. Ranking is not proof of identity.
Slow down on the address bar before you sign in, and be suspicious of anything that is not your bank's exact, familiar domain, including addresses that end in unusual suffixes like
.ph.comor.gr.com.Turn on a passkey or a phishing-resistant second factor for your bank where it is offered, so a stolen password alone is not enough.
If you think you entered your details on a fake bank page, contact your bank immediately using the number on the back of your card, change your password, and watch for unauthorized activity.
The uncomfortable truth of this campaign is that it targets a habit almost everyone has, and it is specifically built to survive the checks we are told to rely on. The fix is partly a new habit, bookmark your bank, and partly a layer that watches the page when you cannot. Slow down at the sign-in screen, and give yourself a second set of eyes for the moment right before you type.
About Haven
Haven is a browser extension that helps you make safer trust decisions online, before a scam can cost you anything. It works at the moment you are about to click a link or enter your password, flagging fake and impersonated login pages, suspicious links, and lookalike sites. Rather than only checking a page against a list of known-bad sites, Haven analyzes the actual page in front of you, so it can catch brand-new and convincing fakes that other tools miss, even ones engineered to hide from scanners.
Haven is free for individual use. For teams, Haven for Business extends this browser-level protection across every employee. Haven is operated by MirrorTab, Inc.

