Cloaked SEO poisoning attacks surged by 40% in the second quarter of 2026, according to researchers at Fortra. This tactic, also known as “Chameleon SEO poisoning,” uses cloaked search engine results to spread phishing sites.
“Chameleon SEO poisoning,” uses cloaked search engine results to spread phishing sites.
“FIRE has been actively monitoring and mitigating a wave of these cloaked SEO poisoning attacks over the past three months and have confirmed they are targeting several major financial institutions and their users,” Fortra says. “Unlike traditional, easily flagged phishing campaigns, these ‘chameleon’ attacks are specifically designed to slip past standard automated scanners while appearing at the very top of Google or Bing search results. Threat actors invest time and resources in SEO poisoning to get pages to rank higher than the legitimate pages they are imitating. The longer they can evade detection, and therefore mitigation and takedown, the greater their success rate will be in achieving their phishing objectives.”
This tactic relies on users finding the phishing page for themselves rather than receiving a link in an email. Users are less likely to be suspicious if they click on a site from a trusted search engine.
“By heavily utilizing SEO poisoning on Search Engine Result Pages (SERPs), attackers rank at the top for high-intent keywords like ‘Bank Name Customer Portal’ or ‘Credit Card Login’ on search engines like Google or Bing,” Fortra says. “It is important to clear up a common misconception here: these are not compromised domains by nature. Instead, these domains are typo-squats that have been recently registered on second-level domains (SLDs) like .ph.com, .gr.com, and similar variants.”
The researchers advise users to rely on “official mobile applications or manually bookmarked URLs” to navigate to their banking services, rather than searching for them and clicking on the top result.
KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 Platform to strengthen their security culture and reduce workforce risk.
Forta has the story: https://www.fortra.com/blog/the-chameleon-threat
