Cybercriminals continue to refine their methods for stealing credentials, initiating fraudulent transfers, and impersonating trusted financial institutions. One tactic gaining traction across the industry is the use of spoofed URLs and search engine manipulation to redirect Treasury and Commercial users to fraudulent login pages that appear legitimate.
But attackers are no longer relying on deceptive URLs alone.
They increasingly deploy Browser in the-browser (BitB)—a technique that simulates trusted login pop ups inside the browser—bypassing even vigilant users’ habit of checking the URL.
This expanded attack landscape represents a strategic risk for any commercial organization relying on online treasury portals. Losses can occur quickly, often within minutes of credential compromise. This article provides an updated view of these threats and practical guidance on how organizations can strengthen their defenses.
1. The most common vector right now: Search engine manipulation (SEO poisoning)
Attackers are prioritizing SEO poisoning to place fraudulent domains and paid ads at the top of search results—often above legitimate banking portals. Treasury users who are searching terms online should be wary of the following:
- "Tresury Center login"
- "Commercial Banking login"
- "MTB login"
These phrases may unknowingly trip up a searcher to click on a spoofed site that’s presented as an advertisement or a top result. Because many commercial users rely on search instead of bookmarks, this method is consistently effective.
What to do:
- Do not navigate to financial portals via search engines.
- Bookmark your verified login URLs and use those bookmarks exclusively.
- If you arrive at a login page via a search result or ad, stop and launch it instead from your saved bookmark.
2. How modern impersonation attacks work
URL spoofing
URL spoofing uses look alike website addresses to convince users they are accessing a legitimate banking portal. Fraud actors register domains that differ subtly from official bank URLs, using:
- Different top level domains (.net instead of .com)
- Typos or visually similar characters
- Hyphens or extra letters
- Alternate domain structures
The spoofed URL then leads to a cloned login page designed to harvest credentials and MFA codes.
Script spoofing / IDN homograph attacks
Script spoofing (often called IDN homograph attacks) exploits characters from different alphabets—Latin, Cyrillic, Greek—that look identical to English letters. This creates URLs that appear legitimate even to trained users.
Browser in the-browser (BitB): A new phase of credential theft
While URL based deception relies on tricking users into visiting a fake site, BitB removes the need for a deceptive URL altogether.
BitB attacks create a fake browser window inside a real webpage using HTML, CSS, and JavaScript—perfectly simulating a trusted login pop up (e.g., Microsoft, Google, or other identity providers). Because the simulated window can display any URL the attacker chooses, users may believe they are entering credentials into a legitimate authentication form. Research across 2025–2026 notes a measurable rise in BitB campaigns and highlights how the technique bypasses traditional red flags because the victim never leaves the attacker controlled page.
Attackers frequently route victims through a fake CAPTCHA before presenting the BitB login window, helping the malicious site evade automated scanning; credentials entered into these windows are immediately harvested.
The result is a high fidelity credential theft technique that undermines the assumption that “checking the URL” is sufficient protection.
3. What fraudulent login pages look like
Despite appearing polished, many spoofed interfaces share common red flags:
- Prompts indicating “your information is being updated”
- Requests for repeated MFA or SMS code entry
- Fake case numbers or support messages
- Countdown timers implying urgency
- Messages requiring an “administrator” to log in
These are engineered to normalize unusual behavior and prolong the attacker’s control of the session.
4. Why Commercial Banking clients are primary targets
Treasury and Commercial accounts present attackers with:
- Higher transfer limits
- Multiple linked accounts
- Payment initiation capabilities
- Larger potential dollar losses
Once credentials are compromised—via URL spoofing, SEO poisoning, or BitB—criminal groups often initiate multiple high value transfers within minutes.
5. How M&T will-and will not-contact you
How we communicate with clients:
- We may send proactive security alerts via official bank channels (e.g., secure messages within online banking, email from an @mtb.com domain, or calls from your known M&T team) to inform you of threats and recommended actions.
- We may request that you call your known Relationship Manager or the number listed on mtb.com to verify activity or update security settings.
- We will direct you to log in by navigating to your saved bookmark or by typing the URL manually—not by clicking a link from a search engine or ad.
How we will not communicate:
- Legitimate bank representatives will never call or text you to ask for login credentials or authentication codes.
- We will not ask you to read back one time passcodes sent to your device.
- We will not pressure you to bypass normal dual control, approval, or callback procedures.
- We will not ask you to install remote access software or browser extensions to “fix” a login issue.
If you receive any request that conflicts with the above, stop and contact your M&T Relationship Manager using a known phone number or the number listed on mtb.com.
6. Steps organizations should take now
A. Bookmark trusted login pages
Avoid using search engines to access banking portals. Bookmark verified login URLs and confirm they display the correct domain before signing in.
B. Strengthen authentication and internal controls
- Require 2FA for all payment initiation
- Use role based permissions to limit authorization access
- Verify emailed payment changes via out of band channels (phone or a separately initiated email thread)
C. Train employees on modern deception techniques
Emphasize that:
- Search results and ads can be manipulated (SEO poisoning)
- Pop up login windows can be forged (BitB)
- MFA prompts should only occur when the user initiates an action
D. Monitor transaction behavior
Watch for:
- Multiple outbound transfers in a short period
- Transfers just under threshold limits
- Newly updated beneficiary details
7. The strategic risk of inaction
Relying on outdated assumptions—such as the belief that URL inspection alone can prevent fraud—puts organizations at heightened risk. Today’s attacks combine:
- SEO poisoning
- URL spoofing
- Homograph attacks
- BitB deception
Commercial clients that don’t update their processes face risks including credential theft, unauthorized payments, operational disruption, and reputational damage.
8. If suspicious activity occurs
If a user believes they have interacted with a spoofed site, a suspicious search result, or an abnormal authentication flow:
- Immediately stop the session
- Report the incident internally
- Contact your banking relationship manager or the published fraud hotline
Rapid escalation is essential because attackers often act within minutes.