Back to news
Cybersecurity Alert
August 26, 2026 by EmailMeNow IT Consulting

Chameleon SEO Poisoning: Fake Bank Login Pages Rank in Google and Bing

Fortra FIRE reports a 40% Q2 2026 surge in Chameleon SEO poisoning — cloaked fake bank login pages that rank in Google and Bing but play dead to scanners. Audits (ideal 100%): texascapitalbank.com 85%, chase.com 79%, fortra.com 64%, bankofamerica.com 53% — 0/11 at 100%. Bank of America documents YubiKey; none advertise Google Authenticator.

Source: Fortra FIRE · Help Net Security

NewsPhishingSEO PoisoningBanksMFAYubiKeyAuthenticator AppsGoogleBingCybersecurity
Laptop search results for a bank login with a suspicious lookalike URL ranked above the real site

Fake bank login pages are showing up in Google and Bing searches. Criminals are manipulating search results so fraudulent banking portals appear when people search for their bank online. Someone can be tricked into giving away bank sign-in details without a suspicious email or text.

Fortra FIRE tracked the technique for three months, reported a more than 40% jump in Q2 2026, and named it Chameleon SEO poisoning. Help Net Security published the analysis on August 24, 2026. CyberPress and Cybersecurity News repeat the same presentation control: direct visit or scanner → dead/404 page; Google or Bing referrer → pixel-perfect fake bank login. Fortra says several major financial institutions and their users were targeted; it does not publish a victim-bank list, and this post does not invent one.

This is a pull attack (search → click → credentials) — different from FaceTime bank scams (live video OTP theft) or Gmail recovery-contact injection (real Google mail). It is not a duplicate of the national or Texas bank MFA scorecards — those grade documented login methods; this post covers search-engine delivery and referrer cloaking.

Laptop search results for a bank login with a suspicious lookalike URL ranked above the real site

Snapshot

FieldDetail
TechniqueChameleon SEO poisoning — SEO-ranked typosquats + referrer-aware cloaking
Search enginesGoogle and Bing high-intent queries (“customer portal”, “credit card login”)
InfrastructureRecently registered lookalikes on private second-level domains (e.g. .ph.com, .gr.com)
EvasionDirect visit / scanner → dead page; search referrer → fake bank login
Fortra trend+40% cases in Q2 2026 vs prior tracking window
CourtListener0 Texas federal RECAP hits for "SEO poisoning" or "Chameleon SEO" (re-checked Aug 26, 2026)

How Chameleon SEO poisoning works

StepWhat happens
1. RegisterAttackers register lookalike domains (typos, TLD swaps, private SLDs)
2. SEO poisonPages optimized for “Bank Name customer portal” / “credit card login”
3. RankFraudulent results climb above or beside the legitimate bank URL
4. CloakServer checks Referer and user-agent — scanners and direct typing see 404 / offline
5. HarvestSearch click → convincing login clone → password + SMS OTP stolen

FIRE’s demo is the tell: type the typosquat directly and it looks dead; click the same URL from a poisoned search result and a fake login appears. Standard link checkers that browse in isolation will miss it.

Google search results for a bank portal with a typosquatted top result marked suspicious

What security teams should test

Fortra recommends mimicking a victim’s traffic footprint, not curling the URL:

TestWhy
Spoof Referer (https://www.google.com/ or Bing)Cloaking keys off search origin
Use a consumer browser UA (Chrome/Edge on Windows)Script agents often get the benign page
Route through residential geo matching the bank’s customersSome campaigns geo-filter
Prioritize new typosquats on private SLDsPrimary Chameleon infrastructure pattern

Brand teams should monitor search rankings for portal/login keywords pointing at domains they do not own — the search box is now an attack surface, not just email and SMS.

What customers should do

  1. Stop searching for bank login pages. Bookmark the official URL or use the bank’s app from the App Store / Play Store listing you installed yourself.
  2. Read the full domain before typing a password — .ph.com / .gr.com suffixes and one-character swaps are common.
  3. Prefer phishing-resistant MFA on the real bank origin: passkeys and FIDO security keys fail on a fake domain; SMS OTP does not.
  4. If you already entered credentials on a suspicious page: change the password from a clean device, call the number on your card back, and review recent transfers.

MFA: YubiKey, Google Authenticator, and passkeys

Public docs for a national + Texas peer set. Fail = documented consumer path is primarily SMS / voice OTP. Strong = consumer FIDO / YubiKey-class key. Passkeys help on the real origin (WebAuthn checks the domain); they do not protect a password typed into a clone on a typosquat.

BankYubiKey / FIDOOpen TOTPGrade
Bank of AmericaYes (USB key)NoStrong
ChaseNoNoFail
Wells FargoNoNoFail
Texas Capital BankNoNoPartial
Frost BankNoNoFail
ComericaNoNoFail
Texas Regional BankNoNoFail

YubiKey / Google Authenticator: Only Bank of America documents a consumer FIDO USB key. None advertise self-serve Google Authenticator. Chase and Wells Fargo document passkeys (better than password-only) and still Fail our SIM-swap rule because SMS/voice remains a documented 2-step method. Texas Capital is Partial (RSA SecurID for some users, not retail YubiKey / open TOTP).

Docs: MFA support directory · National banks MFA scorecard · Texas banks MFA scorecard

ProductBest forGet it
YubiKey 5C NFCUSB-C laptops + NFC phonesAmazon
YubiKey 5 NFCUSB-A desktops + NFC phonesAmazon
YubiKey 5 / 5C NFC caseKeychain protection for the keyAmazon
Proton PassPasskeys + authenticator-style TOTP vaultProton Pass

We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Passkeys and hardware security keys resist fake domains; SMS OTP does not

Independent cybersecurity audits

EmailMeNow domain audits on August 26, 2026. 100% is the ideal. 0 of 11 reach it. Scores measure public identity / transport / website posture. They do not prove a search result is authentic — a typosquat can still look legitimate in the SERP.

OrganizationDomainOverallvs 100%
Texas Capital Banktexascapitalbank.com85%−15
Microsoft Bingbing.com85%−15
JPMorgan Chasechase.com79%−21
Help Net Securityhelpnetsecurity.com68%−32
Wells Fargowellsfargo.com67%−33
Frost Bankfrostbank.com67%−33
Fortrafortra.com64%−36
Texas Regional Banktrb.bank58%−42
Googlegoogle.com55%−45
Bank of Americabankofamerica.com53%−47
Comericacomerica.com37%−63
DomainIdentityTransportWebsite
texascapitalbank.com90%45%90%
bing.com90%15%94%
chase.com75%15%94%
helpnetsecurity.com90%15%37%
wellsfargo.com50%15%87%
frostbank.com50%15%87%
fortra.com75%15%45%
trb.bank40%45%65%
google.com50%70%37%
bankofamerica.com50%45%37%
comerica.com10%15%40%

How to read this: Chase leads banks at 79% with 15% transport — scammers abuse brand trust and search placement, not chase.com DNS alone. Bank of America is 53% overall (37% website) on this pass — strong MFA docs ≠ perfect domain hygiene. Google and Bing scores frame the search platforms victims trust; they are not proof every top result is safe. Fortra (researcher) is 64%, not a victim domain.

Audit links: texascapitalbank.com · bing.com · chase.com · helpnetsecurity.com · wellsfargo.com · frostbank.com · fortra.com · trb.bank · google.com · bankofamerica.com · comerica.com

Padlocks stop short of a 100 percent finish line, illustrating domain audits that miss the ideal score

Illustration only — scores are in the tables above, not in the artwork.

Website stack note

Passive website-tech probes on August 26, 2026:

DomainStack signal
helpnetsecurity.comPHP 8.0.27 past EOL; WordPress 7.0.4 behind current (7.1)
texascapitalbank.comDrupal 10 major version behind (latest 11.4.5)
fortra.comStack undetected; Let’s Encrypt TLS into Nov 10, 2026 (75d)
chase.com, bankofamerica.com, wellsfargo.com, frostbank.com, comerica.com, trb.bank, google.com, bing.comNo notable CMS/PHP aging flags in this pass

Stack hygiene on the real bank site does not validate a search-result URL on a typosquat.

Blacklist and lookalike domains

Email blacklist checks (public DoH, August 26, 2026): chase.com, bankofamerica.com, wellsfargo.com, frostbank.com, comerica.com, texascapitalbank.com, trb.bank, helpnetsecurity.com, google.com, and bing.com were clear on mail/domain lists we can query. Chase and Texas Capital showed SPFBL notes on CDN/web IPs only — not counted as mail reputation hits. fortra.com MX seg1.helpsystems.com (3.148.84.59) hit SpamRATS all — shared HelpSystems/Fortra mail infra noise, not a Chameleon finding.

DNS lookalike scans (EmailMeNow cybersquat engine — registered DNS signals only):

Brand scannedCheckedTo reviewBEC staging
bankofamerica.com2421751
chase.com118962
wellsfargo.com1941192
frostbank.com180302
comerica.com164500
texascapitalbank.com29050
trb.bank87142
fortra.com102470

High-interest registered names (investigate; not proof the Chameleon campaign used them):

LookalikeTechniqueNote
bankofamer1ca.comhomoglyphBEC staging (NS, MX)
wellsfargo-secure.comaffixBEC staging — “secure” themed
weilsfargo.comhomoglyphBEC staging (NS, MX)
chase.io / chasen.comtld-swap / insertionChase BEC staging
frosfbank.com / frosthank.comtyposFrost BEC staging

Chameleon campaigns also use private SLD registrations that may not appear in classic .com typosquat sweeps. Pair continuous monitoring with search-brand keyword alerts: Cybersquat Domain Monitoring.

CourtListener and weekly scan sources

Texas federal RECAP (txsd / txed / txnd / txwd) on August 26, 2026: 0 hits for "SEO poisoning" and 0 for "Chameleon SEO" / "SERP phishing". A national RECAP search for "Chameleon SEO" also returned 0. This is a technique report, not a named-org “was breached” filing.

SourceFinding
BleepingComputerNo dedicated Fortra FIRE Chameleon article; other SEO-poison campaigns exist
CyberScoop / MERENANo matching Chameleon / fake-bank SERP alert in this pass
DeXpose / GalaxyWardenNot a leak-site listing
SEC Item 1.05Not applicable (no named public issuer)

Sources: Fortra FIRE — The Chameleon Threat; Help Net Security (Aug 24, 2026); CyberPress; Cybersecurity News. Independent EmailMeNow domain audits, website-tech probes, blacklist checks, cybersquat scans, and CourtListener RECAP August 26, 2026. MFA grades reflect public documentation, not a private account enumeration.

Run a free audit at audit.emailmenow.com or contact EmailMeNow for phishing response aimed at the 100% ideal.