FDIC Logo

FDIC-Insured - Backed by the full faith and credit of the U.S. Government

How Cybercriminals Are Using Fake Websites to Steal Your Information


When most people think about online scams, they picture an obviously suspicious email, a strange text message or a phone call from someone claiming they need immediate payment.

Related Page: HOW TO SPOT FAKE EZ PASS (WHAT SCAMMERS DON'T WANT YOU TO KNOW)

But some of today’s scams are much harder to spot.

Cybercriminals are increasingly using fake websites and search engine advertisements to impersonate legitimate companies and services. The goal is simple: get you to a fraudulent website, convince you that you are logging into the real thing, and then use the information you provide to access your accounts or redirect your money.

The FBI recently warned about this growing threat, which can target everything from employee payroll and unemployment accounts to health savings accounts, retirement accounts and financial accounts.

As a community bank, we want our customers and neighbors to understand how these scams work—and, more importantly, how to avoid them.

The Dangerous Link Might Be the First Result You See

Imagine you need to check your payroll information.

You open Google and search for your employer's employee portal. At the top of the results, you see what appears to be the right website.

You click it.

The page looks completely legitimate. It has the company's logo. The colors look right. The login screen looks familiar.

You enter your username and password.

That's when the problem begins.

You may have just handed your credentials directly to a cybercriminal.

According to the FBI, criminals are purchasing search engine advertisements designed to imitate legitimate businesses and services. These advertisements can appear prominently in search results and send people to fraudulent websites that closely resemble the real thing.

And because the fraudulent website may look nearly identical to the legitimate one, it can be extremely difficult to recognize the scam at a glance.

 

A Tiny Difference in a Web Address Can Mean a Big Difference

One of the biggest clues is often the website address itself.

A fraudulent website might use a URL that looks almost identical to the real one, with a small change such as:

  • A misspelled company name
  • An extra letter or number
  • A different domain ending
  • A slightly altered company name
  • A different domain altogether

For example, someone trying to visit a legitimate website at:

companyname.com

could accidentally land on something resembling:

company-name.com

or

companyname-login.com

To someone moving quickly, the difference may be easy to miss.

That's exactly what scammers are counting on.

 

Why Multifactor Authentication Isn't a Complete Solution

Many people assume that multifactor authentication (MFA) means they're protected even if they enter their password on a fraudulent website.

Unfortunately, that's not always true.

If a criminal captures your username and password, they may attempt to trick you into providing the additional authentication code required to access your account.

The FBI specifically warns that criminals may impersonate bank employees, technical support representatives or other trusted organizations and ask victims for a one-time passcode.

Here's an important rule to remember:

Never give a one-time authentication code to someone who contacts you unexpectedly.

A legitimate bank employee should never need you to read a one-time passcode to them over the phone.

If someone calls claiming to be from your bank and asks for a security code, stop the conversation and contact the bank using a trusted phone number—such as the number on the back of your debit card or on an official statement.

The Target Isn't Always Your Bank Account

One of the most concerning parts of this scam trend is how many different types of accounts can be targeted.

Cybercriminals aren't necessarily trying to steal money immediately. Sometimes they're looking for information that gives them access to future payments.

For example, if criminals gain access to an employee's payroll account, they may be able to change the direct-deposit information so future paychecks go to an account controlled by the criminal.

Similar attacks can target:

  • Payroll and employee self-service accounts
  • Unemployment benefits
  • Health savings accounts
  • Retirement accounts
  • Financial accounts
  • Business banking accounts

In other words, protecting your login credentials isn't just about protecting your password. It's about protecting where your money goes.

Watch For the Warning Signs

Scammers are becoming better at making fraudulent websites look convincing, but there are still things you can do to protect yourself.

1. Don't automatically click the first search result

The first result on Google isn't necessarily the safest result.

Advertisements can appear above the organic search results, and criminals can use those advertisements to promote fraudulent websites.

Instead of automatically clicking the first result, slow down and verify where you're going.

2. Look carefully at the URL

Before entering a password, financial information or other sensitive information, look at the address bar.

Does the domain look exactly right?

Don't just look for a familiar company name. Read the entire web address.

When something feels slightly different, stop.

3. Type important websites yourself

For websites you use to manage money or sensitive information, consider typing the official web address directly into your browser.

Even better, save the legitimate website as a bookmark or favorite and use that bookmark whenever you need to log in.

This removes the search engine from the equation entirely.

4. Be suspicious of unexpected phone calls

A criminal who has your username and password may still need another piece of information to get into your account.

That's where social engineering comes in.

Someone may call and say:

"We're seeing suspicious activity on your account."

They may know your name, the name of your bank or other details about you. They may even sound professional and convincing.

Then they ask for a verification code.

Don't provide it.

Hang up and contact the organization directly using a trusted number.

5. Pay attention to unusual email activity

The FBI also warns that an unexpected flood of spam emails can sometimes be a sign that an account has been compromised.

Why would criminals want to bury your inbox?

If an organization sends you a legitimate notification about a password change, account access or suspicious transaction, criminals don't want you to see it.

Thousands of junk messages can provide the perfect distraction.

If your inbox suddenly becomes overwhelmed with spam, don't simply delete everything and move on. Check your important financial and other sensitive accounts for unusual activity.

What Should You Do if You Think You've Been Scammed?

If you believe you've entered your credentials into a fraudulent website, act quickly.

Start by contacting the organization associated with the account. If financial information may have been exposed, contact your bank or financial institution immediately.

Depending on the situation, you may need to:

  1. Change your compromised password.
  2. Change that password anywhere else you reused it.
  3. Contact your bank or financial institution.
  4. Review recent transactions and account activity.
  5. Verify your payroll or direct-deposit information.
  6. Report suspicious transactions immediately.
  7. Monitor your accounts for additional unauthorized activity.

If money has already been transferred fraudulently, speed matters. The FBI recommends contacting your financial institution as soon as possible and requesting a recall or reversal when appropriate.

You can also report internet fraud to the FBI's Internet Crime Complaint Center, known as IC3.

A Few Extra Seconds Can Protect a Lot More Than a Password

Online security can sometimes feel overwhelming because the threats keep changing.

But protecting yourself doesn't require becoming a cybersecurity expert.

A few simple habits can make a meaningful difference:

Don't trust a search result just because it looks right.

Don't enter sensitive information until you've verified the website.

Use bookmarks for important login pages.

Never share a one-time security code with someone who calls you unexpectedly.

And when something feels wrong, stop.

That last one may be the most important.

Scammers create urgency because they don't want you to stop and think. Whether it's a message saying your account has been locked, a phone call claiming there's suspicious activity or a search result that looks like the website you need, take a moment to verify before you act.

We're Here to Help Protect More Than Your Money

At Liberty Savings Bank, protecting customers isn't just about having secure technology. It's also about helping people recognize the threats that technology can't always prevent on its own.

Fraudsters are constantly finding new ways to make scams look legitimate. That's why awareness is one of the most important tools you have.

If you ever receive a suspicious call, message or notification involving your financial accounts, don't be embarrassed to ask questions. It's always better to pause and verify than to move quickly and regret it later.

Your money is important. So is your information.

Take a few extra seconds. Check the website. Verify the caller. And when in doubt, contact your bank directly using a trusted phone number.

A little caution can go a long way.

Blog CTA

Subscribe to our blog