Fake Small-Business Websites Hide Bank Login Traps on Secret Subdomains

The website looks like a neighborhood florist. It has a menu, a welcoming offer, and the familiar polish of a small business trying to win customers.

Then a different link under the same address asks for things no florist could need. The change is easy to miss when you are trying to solve a problem.

Authentic screenshot of an online banking one-time passcode page used by the Bizmakers phishing campaign

Overview

What the visitor sees

A link appears to lead to online banking. Its main domain, however, can look like the website of a florist, restaurant, veterinarian, or another ordinary local business.

One example presented itself as Ivy Glen Florist in Louisville. Its public pages had a navigation menu, service descriptions, an order button, and a welcome offer.

Other sites used different business names and cities. Their apparent purpose was not selling flowers or booking appointments. The public-facing sites provided cover for hidden banking pages.

What investigators verified

Allure Security’s investigation documented dozens of fabricated small-business websites linked to phishing pages on subdomains. The pages impersonated at least two dozen financial institutions.

The researchers observed forms for usernames, passwords, and one-time passcodes. They also found a mechanism that let an operator guide a victim through the login sequence in real time.

The business names were invented for the operation, according to the investigation. The legitimate banks and credit unions being copied were targets of impersonation, not participants in it.

What remains unknown

The researchers confirmed at least one victim reached a matching path associated with a Microsoft click identifier. They did not directly observe a search advertisement for every site.

They also did not recover a public database of stolen credentials or publish a total victim count. Those gaps matter when describing the campaign’s scale and outcomes.

Here is the practical distinction:

  • The ordinary-looking business site was camouflage.
  • The banking page on a related subdomain was the theft attempt.
  • A real bank login or verification code was what the operator wanted.
  • The legitimate bank was being copied, not running the page.
  • A polished website or HTTPS padlock did not establish ownership.

Why a Florist Website Belongs in a Banking Scam

Most people know to question a banking URL that obviously misspells a bank’s name. This operation takes a different route. Its parent domain does not announce itself as banking.

A visitor checking the main address might find a plausible local business. An automated scanner could see those harmless pages and miss a bank form on a hidden path.

The scam site did not rely on a single fake storefront. Allure found many invented businesses with variations in names, locations, colors, phone numbers, and page categories.

That variety can make each site look independent. Yet repeated text, identical welcome offers, and reused page structures tied the sites together in the research.

Some copy was clumsy. One wedding page described helping customers who needed guidance on “florist,” a word that did not fit naturally into the sentence.

That mistake was useful to investigators, but it is not a detection method readers should depend on. A future version could correct the awkward wording.

The important clue is the mismatch between the claimed bank and the domain serving the form. Begin a real banking session inside the bank’s app or known address.

How the Fake Small-Business Bank Phishing Scam Works

Step 1: The attacker builds a believable public business

The first layer is a complete-looking website. It can include a homepage, service pages, a local-sounding phone number, a privacy link, and a cookie notice.

Those details do not prove a business exists. In this campaign, the sites made a suspicious domain appear ordinary when someone inspected only the homepage.

The public site is not necessarily where a victim begins. It is a credibility shield for the address used by the phishing pages underneath it.

Step 2: A hidden address shows a copied bank sign-in

The malicious pages lived on subdomains and appeared only at particular paths. The researchers observed a verification path and another route that referenced a Microsoft click parameter.

That parameter does not prove every victim came from a paid Microsoft advertisement. It does show that at least one confirmed victim path passed through that kind of click reference.

At the right address, the visitor saw a banking interface copied from a real platform and rebranded for a bank, credit union, or investment firm.

The copied styling is part of the deception. A page can borrow fonts, colors, and layout from a legitimate institution while being controlled by someone else.

Step 3: The page collects the first login details

The victim types a username and password into the lookalike form. The details go to the phishing operation, not to the institution displayed on the page.

That first theft may not be enough to enter a protected account. Many financial institutions require a second factor or additional identity challenge.

The operation was built to handle that obstacle instead of stopping at a password form. Its next screen asks how the customer receives a passcode.

Step 4: A real passcode is turned into the attacker’s passcode

According to Allure’s technical analysis, the operator can enter the stolen credentials at the real institution while the victim waits at the fake page.

When the bank sends a genuine one-time code, the fake page prompts the victim to type that code into the attacker’s form.

That is why the message from the bank may be real even though the website requesting the code is fraudulent. The code was triggered by an attempted login.

Use of a real verification message can reassure a worried customer. It should instead prompt a question: Who initiated this login, and where am I entering the code?

Non-functional reconstruction of a bank login form on a hidden phishing subdomain, shown for illustration only

Step 5: The operator moves the victim through the form

The researchers found a page component that checked for instructions about once per second. That let a human operator show an error or advance the form.

If a code expired, the page could ask again. If the bank offered a different verification channel, the page could present another choice.

To the victim, those changes might resemble a sluggish but functioning login. In reality, the operator was trying to keep the person engaged during a live takeover attempt.

This is more than a static password trap. The live exchange can bypass the protection people expect from a one-time code.

Step 6: The victim is sent to the real site

After the collection stages, the phishing page could redirect to the legitimate institution. A real homepage appearing at the end can make the earlier form look like a temporary glitch.

It does not erase what was entered before the redirect. A person who supplied a password and code should treat the account as potentially compromised.

The research did not establish how many accounts were entered successfully. It did establish a mechanism capable of collecting the information needed for account access.

The Evidence Is Strong, but the Numbers Need Care

The campaign involved many fake businesses and many institution templates. That supports describing it as a coordinated phishing operation rather than an isolated complaint.

It does not support claiming that every fake business had thousands of visitors. No trustworthy public total for successful thefts appeared in the investigation.

Allure traced form submissions to an endpoint that accepted different stages of data, including credentials, the passcode delivery choice, and the passcode itself.

The team could not retrieve the stolen records from a public leak. That limitation narrows the outcome claim but does not undermine the observed phishing forms.

One especially revealing detail was reuse. Names from other institutions remained in some page code after the template was changed for a new target.

That is evidence of a multi-brand kit, not evidence that every bank named in the code had confirmed victims. Keep that distinction in mind.

How to Check a Banking Link Without Opening the Trap

A message can also come from an account you recognize. If that person’s account was compromised, familiar sender details still do not authenticate the banking page.

Search results have their own trap. A matching business name in search does not mean a bank link under that domain is official.

Watch the address as the page changes. A redirect to a real bank after you submit information is not proof the earlier page was legitimate.

If your browser saved a password for the wrong domain, review the password manager entry. A saved login can make a return visit look routine.

Some password managers refuse to fill on mismatched domains. Treat that refusal as a warning, not a reason to paste the password manually.

The safest check is independent navigation. It removes the attacker’s chosen link from the decision, which is more reliable than guessing from visual design.

Do not decide based on the padlock alone. HTTPS tells you a connection is encrypted. It does not tell you the organization on the page owns the site.

Read the actual domain after the last dot before the first slash. A banking-looking subdomain attached to a florist domain is not a bank domain.

Beware of a familiar logo inside an unfamiliar address. A copied logo is easier to create than a legitimate banking relationship.

Open your financial institution’s app yourself. If you need a browser, type a saved, verified address or use a bookmark you created earlier.

If the message claims your account needs verification, look for the same notice after signing in through that independent route. Do not use the supplied link as the test.

When uncertain, call the number on your physical card or a statement you already trust. Avoid phone numbers presented on the suspicious page.

A business site’s existence does not validate a banking subdomain. The legitimate florist, restaurant, or clinic you see might even be unrelated to the hidden page.

In this particular campaign, researchers concluded the small businesses themselves were invented. Other campaigns may abuse real sites, so focus on the banking destination.

What to Do if You Have Fallen Victim to This Scam

  1. Stop using the page. Close it without entering another code. Do not accept a request to retry with a different card or account.
  2. Contact the institution through a trusted channel. Use its app, statement, or card number. Tell fraud support that you entered credentials on a lookalike page.
  3. Change the affected password. Do this from the real website or app. Replace reused passwords on other accounts with unique ones.
  4. Disclose any verification code you entered. Tell the bank whether you supplied an SMS, email, app, or phone code. This changes the urgency of its response.
  5. Ask for an account review. Check sign-ins, linked devices, transfer recipients, contact details, and any security setting changed without your approval.
  6. Protect payment information. If a card number was entered, ask the issuer whether it should be blocked or replaced and dispute unauthorized charges promptly.
  7. Keep evidence. Save the message, URL, screenshots, and timestamps. Do not return to the live phishing page just to collect more material.
  8. Scan if you downloaded anything. A password form alone does not prove malware, but an unexpected download warrants a reputable security scan, including Malwarebytes.
  9. Reduce future link exposure. A reputable browser or network filter, such as AdGuard, can help block known malicious destinations. It cannot replace direct verification.
  10. Report the attempt. Send it to your institution and the platform that delivered the link. In the United States, report fraud at ReportFraud.ftc.gov.

If money has already moved, say so immediately when you call the bank. Ask for its fraud and recovery team, not general customer service.

Be wary of anyone who later promises to retrieve funds or reverse a bank transfer for an upfront fee. That can be a second scam targeting the same person.

Frequently Asked Questions

Was Ivy Glen Florist a real business involved in bank fraud?

Allure Security described it as one of the invented sites in this campaign. The public florist pages served as cover for hidden phishing infrastructure.

Did the banks and credit unions create these sign-in pages?

No. The campaign copied their appearance and login flow. Treat the legitimate institution as the organization to contact for help, not as the operator of the fake page.

Does a real verification text mean the banking page is safe?

No. The attacker may have triggered that text by trying your credentials at the real bank while you were on a fraudulent page.

Did investigators prove the links came from search ads?

They saw a Microsoft click-related path and confirmed one victim path associated with it. They did not directly observe an advertisement for every fake business.

Can I be harmed by only viewing the fake business homepage?

The documented theft stages required interaction with a hidden banking page. Viewing the homepage alone is not the same as submitting credentials or a code.

What if I entered a password but not the one-time code?

Change the password through the real bank immediately and tell its fraud team. A stolen password may still be useful for account probing or reuse elsewhere.

The Bottom Line

This scam hides a bank-login trap behind websites that look unrelated to banking. The false storefront is the disguise; the credential and passcode forms are the danger.

Do not judge a banking request by a polished page or an encrypted connection. Start the session in your bank’s own app or verified address, especially after an unexpected link.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

Outsider Phishing Kit Built 100,000 Fake Pages to Steal Cards and Codes

Next

GitBait Bank Phishing Hides Fake Mexican Logins on Trusted GitHub Pages