Fake bank websites play dead to evade security scanners
Overview
A new phishing technique called Chameleon SEO Poisoning has been identified by Fortra's threat intelligence team. This method involves creating fake banking websites that are optimized to appear in search results for terms like 'Bank Name Customer Portal'. These deceptive sites can evade security scanners by disguising themselves, making it difficult for users to recognize them as fraudulent. Fortra reported a significant increase in these phishing attempts, with a 40% rise noted in the second quarter of 2026. This situation poses a serious risk to individuals seeking to access their banking information online, as attackers aim to steal credentials through these disguised sites.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Fake banking websites targeting customers of various banks.
- Action Required: Users should verify website URLs before entering credentials and utilize security software that can detect phishing attempts.
- Timeline: Ongoing since at least Q2 2026
Original Article Summary
A phishing method, named Chameleon SEO Poisoning, that uses manipulated search results and cloaked fake banking websites to steal credentials while evading security scanners has been discovered by Fortra. The company’s threat intelligence unit, Fortra Intelligence and Research Experts (FIRE), spent three months tracking the technique and reports a 40% jump in cases during the second quarter of 2026. Attackers rank these pages for high-intent keywords such as “Bank Name Customer Portal” or “Credit Card … More → The post Fake bank websites play dead to evade security scanners appeared first on Help Net Security.
Impact
Fake banking websites targeting customers of various banks.
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Ongoing since at least Q2 2026
Remediation
Users should verify website URLs before entering credentials and utilize security software that can detect phishing attempts.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Phishing, Malware.