Fake bank login pages are showing up in Google and Bing searches. Criminals are manipulating search results so fraudulent banking portals appear when people search for their bank online. Someone can be tricked into giving away bank sign-in details without a suspicious email or text.
Fortra FIRE tracked the technique for three months, reported a more than 40% jump in Q2 2026, and named it Chameleon SEO poisoning. Help Net Security published the analysis on August 24, 2026. CyberPress and Cybersecurity News repeat the same presentation control: direct visit or scanner → dead/404 page; Google or Bing referrer → pixel-perfect fake bank login. Fortra says several major financial institutions and their users were targeted; it does not publish a victim-bank list, and this post does not invent one.
This is a pull attack (search → click → credentials) — different from FaceTime bank scams (live video OTP theft) or Gmail recovery-contact injection (real Google mail). It is not a duplicate of the national or Texas bank MFA scorecards — those grade documented login methods; this post covers search-engine delivery and referrer cloaking.

Snapshot
| Field | Detail |
|---|---|
| Technique | Chameleon SEO poisoning — SEO-ranked typosquats + referrer-aware cloaking |
| Search engines | Google and Bing high-intent queries (“customer portal”, “credit card login”) |
| Infrastructure | Recently registered lookalikes on private second-level domains (e.g. .ph.com, .gr.com) |
| Evasion | Direct visit / scanner → dead page; search referrer → fake bank login |
| Fortra trend | +40% cases in Q2 2026 vs prior tracking window |
| CourtListener | 0 Texas federal RECAP hits for "SEO poisoning" or "Chameleon SEO" (re-checked Aug 26, 2026) |
How Chameleon SEO poisoning works
| Step | What happens |
|---|---|
| 1. Register | Attackers register lookalike domains (typos, TLD swaps, private SLDs) |
| 2. SEO poison | Pages optimized for “Bank Name customer portal” / “credit card login” |
| 3. Rank | Fraudulent results climb above or beside the legitimate bank URL |
| 4. Cloak | Server checks Referer and user-agent — scanners and direct typing see 404 / offline |
| 5. Harvest | Search click → convincing login clone → password + SMS OTP stolen |
FIRE’s demo is the tell: type the typosquat directly and it looks dead; click the same URL from a poisoned search result and a fake login appears. Standard link checkers that browse in isolation will miss it.

What security teams should test
Fortra recommends mimicking a victim’s traffic footprint, not curling the URL:
| Test | Why |
|---|---|
Spoof Referer (https://www.google.com/ or Bing) | Cloaking keys off search origin |
| Use a consumer browser UA (Chrome/Edge on Windows) | Script agents often get the benign page |
| Route through residential geo matching the bank’s customers | Some campaigns geo-filter |
| Prioritize new typosquats on private SLDs | Primary Chameleon infrastructure pattern |
Brand teams should monitor search rankings for portal/login keywords pointing at domains they do not own — the search box is now an attack surface, not just email and SMS.
What customers should do
- Stop searching for bank login pages. Bookmark the official URL or use the bank’s app from the App Store / Play Store listing you installed yourself.
- Read the full domain before typing a password —
.ph.com/.gr.comsuffixes and one-character swaps are common. - Prefer phishing-resistant MFA on the real bank origin: passkeys and FIDO security keys fail on a fake domain; SMS OTP does not.
- If you already entered credentials on a suspicious page: change the password from a clean device, call the number on your card back, and review recent transfers.
MFA: YubiKey, Google Authenticator, and passkeys
Public docs for a national + Texas peer set. Fail = documented consumer path is primarily SMS / voice OTP. Strong = consumer FIDO / YubiKey-class key. Passkeys help on the real origin (WebAuthn checks the domain); they do not protect a password typed into a clone on a typosquat.
| Bank | YubiKey / FIDO | Open TOTP | Grade |
|---|---|---|---|
| Bank of America | Yes (USB key) | No | Strong |
| Chase | No | No | Fail |
| Wells Fargo | No | No | Fail |
| Texas Capital Bank | No | No | Partial |
| Frost Bank | No | No | Fail |
| Comerica | No | No | Fail |
| Texas Regional Bank | No | No | Fail |
YubiKey / Google Authenticator: Only Bank of America documents a consumer FIDO USB key. None advertise self-serve Google Authenticator. Chase and Wells Fargo document passkeys (better than password-only) and still Fail our SIM-swap rule because SMS/voice remains a documented 2-step method. Texas Capital is Partial (RSA SecurID for some users, not retail YubiKey / open TOTP).
Docs: MFA support directory · National banks MFA scorecard · Texas banks MFA scorecard
Recommended MFA tools
| Product | Best for | Get it |
|---|---|---|
| YubiKey 5C NFC | USB-C laptops + NFC phones | Amazon |
| YubiKey 5 NFC | USB-A desktops + NFC phones | Amazon |
| YubiKey 5 / 5C NFC case | Keychain protection for the key | Amazon |
| Proton Pass | Passkeys + authenticator-style TOTP vault | Proton Pass |
We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Independent cybersecurity audits
EmailMeNow domain audits on August 26, 2026. 100% is the ideal. 0 of 11 reach it. Scores measure public identity / transport / website posture. They do not prove a search result is authentic — a typosquat can still look legitimate in the SERP.
| Organization | Domain | Overall | vs 100% |
|---|---|---|---|
| Texas Capital Bank | texascapitalbank.com | 85% | −15 |
| Microsoft Bing | bing.com | 85% | −15 |
| JPMorgan Chase | chase.com | 79% | −21 |
| Help Net Security | helpnetsecurity.com | 68% | −32 |
| Wells Fargo | wellsfargo.com | 67% | −33 |
| Frost Bank | frostbank.com | 67% | −33 |
| Fortra | fortra.com | 64% | −36 |
| Texas Regional Bank | trb.bank | 58% | −42 |
| google.com | 55% | −45 | |
| Bank of America | bankofamerica.com | 53% | −47 |
| Comerica | comerica.com | 37% | −63 |
| Domain | Identity | Transport | Website |
|---|---|---|---|
| texascapitalbank.com | 90% | 45% | 90% |
| bing.com | 90% | 15% | 94% |
| chase.com | 75% | 15% | 94% |
| helpnetsecurity.com | 90% | 15% | 37% |
| wellsfargo.com | 50% | 15% | 87% |
| frostbank.com | 50% | 15% | 87% |
| fortra.com | 75% | 15% | 45% |
| trb.bank | 40% | 45% | 65% |
| google.com | 50% | 70% | 37% |
| bankofamerica.com | 50% | 45% | 37% |
| comerica.com | 10% | 15% | 40% |
How to read this: Chase leads banks at 79% with 15% transport — scammers abuse brand trust and search placement, not chase.com DNS alone. Bank of America is 53% overall (37% website) on this pass — strong MFA docs ≠ perfect domain hygiene. Google and Bing scores frame the search platforms victims trust; they are not proof every top result is safe. Fortra (researcher) is 64%, not a victim domain.
Audit links: texascapitalbank.com · bing.com · chase.com · helpnetsecurity.com · wellsfargo.com · frostbank.com · fortra.com · trb.bank · google.com · bankofamerica.com · comerica.com

Illustration only — scores are in the tables above, not in the artwork.
Website stack note
Passive website-tech probes on August 26, 2026:
| Domain | Stack signal |
|---|---|
| helpnetsecurity.com | PHP 8.0.27 past EOL; WordPress 7.0.4 behind current (7.1) |
| texascapitalbank.com | Drupal 10 major version behind (latest 11.4.5) |
| fortra.com | Stack undetected; Let’s Encrypt TLS into Nov 10, 2026 (75d) |
| chase.com, bankofamerica.com, wellsfargo.com, frostbank.com, comerica.com, trb.bank, google.com, bing.com | No notable CMS/PHP aging flags in this pass |
Stack hygiene on the real bank site does not validate a search-result URL on a typosquat.
Blacklist and lookalike domains
Email blacklist checks (public DoH, August 26, 2026): chase.com, bankofamerica.com, wellsfargo.com, frostbank.com, comerica.com, texascapitalbank.com, trb.bank, helpnetsecurity.com, google.com, and bing.com were clear on mail/domain lists we can query. Chase and Texas Capital showed SPFBL notes on CDN/web IPs only — not counted as mail reputation hits. fortra.com MX seg1.helpsystems.com (3.148.84.59) hit SpamRATS all — shared HelpSystems/Fortra mail infra noise, not a Chameleon finding.
DNS lookalike scans (EmailMeNow cybersquat engine — registered DNS signals only):
| Brand scanned | Checked | To review | BEC staging |
|---|---|---|---|
| bankofamerica.com | 242 | 175 | 1 |
| chase.com | 118 | 96 | 2 |
| wellsfargo.com | 194 | 119 | 2 |
| frostbank.com | 180 | 30 | 2 |
| comerica.com | 164 | 50 | 0 |
| texascapitalbank.com | 290 | 5 | 0 |
| trb.bank | 87 | 14 | 2 |
| fortra.com | 102 | 47 | 0 |
High-interest registered names (investigate; not proof the Chameleon campaign used them):
| Lookalike | Technique | Note |
|---|---|---|
bankofamer1ca.com | homoglyph | BEC staging (NS, MX) |
wellsfargo-secure.com | affix | BEC staging — “secure” themed |
weilsfargo.com | homoglyph | BEC staging (NS, MX) |
chase.io / chasen.com | tld-swap / insertion | Chase BEC staging |
frosfbank.com / frosthank.com | typos | Frost BEC staging |
Chameleon campaigns also use private SLD registrations that may not appear in classic .com typosquat sweeps. Pair continuous monitoring with search-brand keyword alerts: Cybersquat Domain Monitoring.
CourtListener and weekly scan sources
Texas federal RECAP (txsd / txed / txnd / txwd) on August 26, 2026: 0 hits for "SEO poisoning" and 0 for "Chameleon SEO" / "SERP phishing". A national RECAP search for "Chameleon SEO" also returned 0. This is a technique report, not a named-org “was breached” filing.
| Source | Finding |
|---|---|
| BleepingComputer | No dedicated Fortra FIRE Chameleon article; other SEO-poison campaigns exist |
| CyberScoop / MERENA | No matching Chameleon / fake-bank SERP alert in this pass |
| DeXpose / GalaxyWarden | Not a leak-site listing |
| SEC Item 1.05 | Not applicable (no named public issuer) |
Related coverage
- National banks MFA — SMS vs YubiKey & authenticator apps
- Texas banks MFA scorecard
- MFA support directory — YubiKey, authenticator apps & passkeys
- FaceTime bank scam (live-call OTP theft)
- Beazley Q2 2026 — SEO-poisoned installers in ransomware cases
- IBM Cost of a Data Breach 2026 (finance sector breach costs)
- Top Texas banks email security
Sources: Fortra FIRE — The Chameleon Threat; Help Net Security (Aug 24, 2026); CyberPress; Cybersecurity News. Independent EmailMeNow domain audits, website-tech probes, blacklist checks, cybersquat scans, and CourtListener RECAP August 26, 2026. MFA grades reflect public documentation, not a private account enumeration.
Run a free audit at audit.emailmenow.com or contact EmailMeNow for phishing response aimed at the 100% ideal.