The numbers
π΅οΈThe mechanism, step by step
Attackers register recently created domain names close to a bank's real name, then apply standard search engine optimization techniques to rank for targeted searches like "bank name customer login" or "blocked debit card". The page behaves differently depending on who arrives: visited directly or by a security scanner, it shows a dead or offline page; visited by clicking an actual search result, it shows a convincing copy of the banking site. This referrer-dependent behavior is what makes the technique hard to detect automatically.
Source: Fortra (FIRE), via Help Net Security.What this means for you
The habit that protects here is simple but runs against a common one: never search for your bank's website through a search engine, even by typing its exact name. The top result isn't necessarily the real one β rankings can be manipulated. Use an already-saved bookmark, the official app, or type the full address yourself. According to Fortra, these fake sites don't stop at the password: they also ask for answers to security questions, which can later be used to bypass two-factor authentication.
Frequently asked questions
How can a fake site outrank the real one on Google?
Through standard SEO techniques applied to a recently registered domain β an abuse of the same rules a legitimate site follows, not a flaw in Google.
Why do these sites evade security scanners?
They show different content depending on the visitor's origin: offline for a scanner, active for a real visitor arriving from search.
What do these fake sites do once a password is entered?
They also ask for answers to security questions, usable to bypass two-factor authentication.
Related reading
Egidio β The Threat Laboratory, "Fake banking sites: fooling Google and your instincts," egidio.app/en/laboratoire/seo-poisoning-fake-banking-sites/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.