You Went Looking for Them: Fake Bill-Pay Sites and Fake Support Numbers in Your Own Search Results
August 25, 2026
The safest-feeling search you make all month is the one where you go looking for a company yourself. That is precisely why this works — nobody phoned you, nobody emailed you, and the top result was still bought by someone who is not them.
Nearly every piece of scam advice ever written rests on the same quiet assumption: the scam came to you. A text arrived about an unpaid toll. A pop-up appeared telling you to call a number. An invoice landed in your inbox for a renewal you do not remember. Someone rang. In every one of those, the first move was theirs, and that is why the advice works — "they contacted you" is the thing you are being taught to notice.
This one runs the other way. You needed to pay a bill, or you needed to reach a company about a charge, so you opened a browser and searched. You typed the company name yourself. You clicked the first thing you saw. And the first thing you saw was a paid advertisement bought by somebody who is not the company you were looking for. Nothing reached out to you. You went and found it, which is exactly why it slips past the rule you have learned.
Two very different operations use that same door, and it is worth separating them early because the harm and the fix differ. One is a real, operating business that buys your biller's name in search and takes your payment through its own platform, adding fees along the way. The other is an outright criminal, harvesting card numbers or getting a stranger onto your computer. The Federal Trade Commission put a number on the first kind on August 17, 2026. The FBI has been warning about the second since 2022. Both are below, along with the practical part — where to get a payment address or a support number that cannot be bought.
The safety rule with a hole in it
If you have read our pieces on the fake toll text, the "Windows update" screen that asks you to paste a command, or the Geek Squad renewal invoice, you will have noticed they share a spine: something arrived unbidden, and the fact that it arrived unbidden is the tell. That is a genuinely good rule and it disposes of most of what people are hit with.
The hole is that it says nothing at all about the case where you initiate. When you go looking, three separate defences switch off at once. You are not suspicious, because nobody approached you. You are usually in a hurry or mildly annoyed — a bill is due, a charge is wrong, something is broken — and hurry is the working condition every one of these operations is built around. And you have a specific expectation of what you are about to see, which means a page that looks roughly right gets waved through, because it is what you went there to find.
That is the whole mechanism. It does not require you to be careless or unusually trusting. It requires you to be busy and to be right about what you were looking for.
What the FTC described on August 17, 2026
On that date the FTC published a consumer alert titled "Searching online: bill pay impersonators," and it is unusually concrete because it is drawn from a case the agency had just settled. The alert's own summary of the mechanism: you need to pay a bill, so you search for the company's payment site, and "the top result may be a paid search text ad that will take you to another company's site." You click it, you do not realise the site has no relationship with the company you were looking for, and "when you go to pay your bill, the company may add additional fees you didn't expect."
The case behind it is FTC v. Doxo, Inc. On the same day, the FTC announced that the online bill-payment firm Doxo would pay $2.1 million to settle allegations that the company and two of its co-founders "used misleading search ads to impersonate consumers' billers." In a 2024 complaint the agency alleged that Doxo used search ads to get people onto its third-party payment platform to pay utility, car loan and other bills "by disguising itself as the official payment channel for those bills," that its landing pages often carried other companies' names and sometimes their logos, and that it did not actually have a relationship with the overwhelming majority of the companies it presented as part of its payment network. The FTC also alleged undisclosed "delivery fees" added to the bills, and a recurring subscription that consumers were signed up for without the price or the terms being clearly disclosed. At the FTC's request, a federal court found that Doxo had violated the Restore Online Shoppers' Confidence Act over those subscription charges.
The FTC's consumer alert names the kinds of billers involved in the complaint — Labcorp, AT&T and state toll authorities — which tells you the shape of the target list. These are bills that arrive irregularly, from organisations whose exact payment web address almost nobody has memorised. That is the profile: not your mortgage, which you pay from a bookmark every month, but the medical lab, the toll agency, the utility you moved to last year.
Two honest caveats. The order announced that day was a stipulated one, and stipulated final orders have the force of law once a district court judge approves and signs them. And a settlement is not a criminal conviction — this half of the problem is a lawful business being penalised for deception, not a thief. Which matters to you mainly in this way: the money usually did reach your biller. You just paid more than you needed to, possibly signed up for something recurring, and handed your card details to a company you had not chosen. The other half of the problem is not so tidy.
The criminal version of the same door
The FBI's Internet Crime Complaint Center published a public service announcement on December 21, 2022 — "Cyber Criminals Impersonating Brands Using Search Engine Advertisement Services to Defraud Users" — that describes the malicious version in plain terms. Criminals buy advertisements that appear in search results using "a domain that is similar to an actual business or service." Those ads "appear at the very top of search results with minimum distinction between an advertisement and an actual search result," and they link to "a webpage that looks identical to the impersonated business's official webpage." The FBI notes the two most common payloads: a download that is actually malware, named after the program you meant to download, and fake login pages for financial sites that simply collect your credentials.
A more recent PSA, dated June 18, 2026, describes how much machinery now sits behind that click. It warns about criminal use of "traffic distribution systems" — infrastructure that routes you onward after you click an advertisement, through "a complex chain of intermediate nodes to hide the final malicious destination." The part worth carrying away is the filtering. The FBI describes these systems collecting "IP address, operating system, location, device, and browser information" and deciding what to show based on it, so that operators "can identify users in regions they are not targeting, allowing them to avoid detection by displaying safe content to undesired targets, including security researchers."
That last detail quietly kills a check people rely on. "I had my son look at the link and it was fine" is not evidence. The same link can be genuinely fine for him and hostile for you, deliberately, and that is a design feature rather than an accident.
The FBI's advice to individuals in the 2022 PSA is worth repeating because it is more specific than the usual: check the URL before clicking an advertisement, since a malicious domain "may be similar to the intended URL but with typos or a misplaced letter"; rather than search for a business or financial institution, type its address into the browser directly; and use an ad-blocking extension when searching, turning it on and off per site if you want to keep supporting sites you like. It is unusual for a federal agency to recommend an ad blocker by name of function. They did.
The other half: the support number you found yourself
The same purchased slot works even better when what you are hunting is a phone number. You are locked out of an account, or a charge looks wrong, or the printer has stopped, and you search for a company's support line. The number at the top is answered by a call centre that is not the company, staffed by people who are polite, competent-sounding and in no hurry.
What happens next is the part we get called about afterwards. They ask you to install remote-access software — AnyDesk, TeamViewer, UltraViewer and similar tools are legitimate products used by real support desks, including ours, which is precisely why the request does not feel wrong. Once they are on the machine, they can show you anything they like. The classic finish is a refund: they have you sign in to online banking while they watch, then claim they refunded too much and ask you to send the difference back in gift cards, cryptocurrency or a wire. The overpayment never happened. What you saw on the screen was edited.
Microsoft states the underlying rule flatly on its own tech support scams page: "Microsoft error and warning messages never include phone numbers," and Microsoft "does not send unsolicited email messages or make unsolicited phone calls to request personal or financial information, or to provide technical support to fix your computer." It also notes that Microsoft "will never ask that you pay for support in the form of cryptocurrency like Bitcoin, or gift cards." All true, and all written about the pop-up version of the scam — a number that appeared on your screen uninvited.
Notice that the searched-for number gets past every one of those sentences. It did not appear in an error message. Nobody called you. You went and got it. The rule that actually covers this case has to be about where a number comes from, not about who moved first — and that is the section below.
Why the checks you already know do not catch this
The padlock proves nothing. It means the connection is encrypted, not that the operator is who you think. A criminal site gets a certificate in minutes for free, and a real-but-deceptive bill-pay platform obviously has a perfectly valid one.
"It looked exactly right" is expected, not reassuring. Both versions copy the real page, and the deceptive-business version does not need to copy anything — it can simply display the biller's name and logo, which is one of the practices the FTC order against Doxo specifically bars going forward.
Hovering over the link to read the address helps less than it used to, partly because ad URLs are display strings and partly because a look-alike domain is designed to survive a two-second glance. Read it as a security professional would: find the last dot before the first single slash, and read the two words immediately before it. That is the actual site. Everything to the left of it can say anything at all.
And "I have used this site before" is the weakest check of the lot here, because on this scam you very often have — you paid through the same third-party platform last quarter and it worked. It working is not evidence that it is who you think it is.
One thing this article is not about: fake download pages for software, where the trap is the installer rather than the payment or the phone number. That has its own mechanics and its own defences, and we covered it separately in the piece on fake "official" download sites, linked below.
The one-click control in Google Search almost nobody uses
On October 13, 2025, Google changed how ads are labelled in Search, and the change came with a control that happens to defeat this entire category. Google's own announcement: text ads on the results page are now grouped under a single "Sponsored results" label, that label "stays visible as people scroll," and there is a new "Hide sponsored results" control that "allows you to collapse text ads with a single click if you want to focus only on organic results." Google also states you will "never see more than four text ads in a grouping."
Use it. On any search where you are trying to reach a company, collapse the sponsored block before you read anything. The attack requires you to click a purchased slot; if the purchased slots are collapsed, there is nothing to click. It costs one click and it needs no software, no extension and no settings menu.
Two things to know about it. First, the label rollout was described as rolling out globally on desktop and mobile, so what you see may differ slightly by device — the word to look for is "Sponsored." Second, this is a Google control specifically. Other search engines label ads too, but the wording and the collapse control are not the same, so on Bing or elsewhere the discipline has to be the older one: find where the ads stop, and start reading there.
The FBI's ad-blocker suggestion is the heavier version of the same idea, and it has a side effect worth naming honestly: ad blockers also remove the advertising that funds a great many legitimate sites, including small local ones. The FBI's own phrasing anticipates this — the extensions "can be turned on and off within a browser to permit advertisements on certain websites while blocking advertisements on others." Blocking on the search engine and allowing elsewhere is a reasonable middle.
Two clicks that show you who actually bought the ad
If you are going to click a sponsored result anyway, there is a check that takes about five seconds and that almost nobody knows exists. Google requires advertisers to complete an identity verification process, which in its own words "requires that advertisers provide legal documentation with their name and location," and it then exposes that information on the ad itself.
Google's instructions are short: "On the ad, select More or Info," then "select About this advertiser." In practice that control appears as a three-dot or information icon beside the ad's web address. What comes back is a verified legal name and a country.
The value of this is that it collapses the question to something you can answer without any expertise. If you searched for your electric utility's payment page and the advertiser behind the top result is a legal entity you have never heard of, registered somewhere else, that is the whole answer — close it and scroll down. You do not have to work out whether the company is legitimate in general. You only have to notice it is not the one you were looking for.
For ads on sites and apps that partner with Google rather than on Search itself, Google's equivalent route is to select "More" or "AdChoices" on the ad and then "Why this ad?".
Get the address and the number from something you already own
This is the rule that actually covers the case, and it is deliberately not about spotting a fake. It is about never being in a position where spotting one matters: for money and for support calls, get the web address or the phone number from an artefact you already possess, not from a search engine.
You have more of those artefacts than you think. The paper bill or the billing email from the company itself carries the payment address and usually a service number. The back of your credit or debit card carries the only bank number you will ever need — this is the single best-known example of this rule, and it works because the card was issued to you. The sticker on the router or modem, and the paperwork from the day it was installed, carries your internet provider's support line. The box, the manual or the label on the printer carries the manufacturer's. An app you are already signed in to is itself an authenticated channel: the support option inside the account is not something a stranger can buy a slot in front of.
Then close the loop so you never have to search for it again. The first time you reach a real payment page, bookmark it, name the bookmark for the biller, and pay from the bookmark from then on. A folder of eight or ten of these covers essentially every recurring bill a household has, and once it exists, the search that starts this whole scam simply stops happening. If you must search — and sometimes you must — type the address you believe is right into the address bar rather than into the search box, which is also the FTC's advice in the August 2026 alert and the FBI's in the 2022 PSA.
For the phone half there is one more rule that has no exceptions worth carrying: no legitimate company will ever need remote control of your computer to process a refund, verify a charge, or prove that a payment went through. If a number you found in a search asks you to install anything at all, the call is over. Hang up and reach the company through the artefact instead.
The Southern California version of this
Two local details make this worse here than the national write-ups suggest, and both are about the same thing: around here, more bills than usual come from organisations whose payment address you have no reason to know by heart.
Start with electricity, because it is the one people assume is uniform. It is not. Several cities we serve are on their own municipal electric utilities rather than Southern California Edison — Glendale Water & Power, Pasadena Water and Power, Riverside Public Utilities and Anaheim Public Utilities are all city-owned — while much of the Coachella Valley is served by the Imperial Irrigation District. So "pay my electric bill" does not have one right answer in this region; it has a different right answer depending on which side of a city line the house sits on. People who have moved within Southern California are the most exposed of all, because the muscle memory points at the wrong utility entirely.
Then tolls, which the FTC named directly. In Orange County, The Toll Roads — State Routes 73, 133, 241 and 261 — are operated by the Transportation Corridor Agencies, and the agency currently carries a customer advisory about a nationwide text phishing scam on its own site. Note that this is a different door to the same brand from the one we wrote about before: the text-message version comes to you, and we covered it in the piece on fake toll texts. The version in this article is the one you go looking for, after the text has already made you anxious about whether you actually owe something. Realistically, a good number of people search for the toll agency precisely because they were sensible enough not to click the text.
The practical local version of the rule: know the name of the utility on your own bill, not the name of the big one everyone assumes. If you are not certain what it is, that alone is worth two minutes with the paper bill before you ever type the phrase into a search box.
If you already paid through the wrong site
Work in this order. First, confirm with the actual biller whether the bill is paid. This is the step people skip, and it is the one that costs money — go through the biller's own app or the number on your bill and check the balance and the due date. If the payment has not landed, you have both an unpaid bill and a card sitting with a company you did not choose, and the unpaid bill is the more urgent of the two.
Second, look at what was actually charged. Compare the amount that left your account with the amount of the bill. Fees added on top, and any second charge that looks like a membership or subscription, are the pattern the FTC described. Then look at your statement for a recurring charge you did not knowingly agree to — that is the part designed to keep charging quietly after the bill is long forgotten.
Third, call your card issuer using the number on the back of the card. Dispute what should not have been charged, and ask them to block any future recurring charge from that merchant. If your card details went into a site you now believe was outright fraudulent rather than merely deceptive, ask for the card to be cancelled and reissued instead of just disputing the transaction.
Fourth, change the password for any account you signed in to on that site, and change it anywhere else you used the same one. If it was a bank or biller login you typed into a look-alike page, treat those credentials as gone.
Finally, report it at ReportFraud.ftc.gov. This is not a formality — it is the reporting stream the FTC drew the Doxo case from, and consumer redress in that case came out of a settlement built on exactly these complaints.
If you already called and let someone in
Move fast and in this order. Disconnect the machine from the internet — unplug the Ethernet cable or turn off Wi-Fi — which ends the remote session immediately. Do not let anyone talk you out of this on the phone; hang up first if you have to.
From a different device that was not part of the session, change the passwords for your email first, then online banking, then anything else of consequence. Email comes first because it is the reset channel for everything else. If two-factor authentication is not on for those accounts, turn it on now.
Call your bank on the number on the back of your card. Tell them a stranger had remote access while you were signed in to online banking, and ask them to review recent activity. If you sent gift cards, contact the card issuer immediately with the numbers and the receipts — occasionally, if the funds have not been drained, they can be frozen. Wires and cryptocurrency are far harder, but report them anyway and quickly.
Then deal with the computer. Uninstall any remote-access software they had you install, and run a full scan. Be aware that uninstalling what you can see is not a guarantee — Microsoft's own guidance is that if you gave scammers access to your device, you should consider resetting it, which is a real inconvenience but is the only way to be certain. This is the point at which it is entirely reasonable to hand the machine to someone whose job it is. Report the scam to Microsoft at microsoft.com/reportascam, and to the FTC at ReportFraud.ftc.gov.
One last thing, and it is not optional: expect a second approach. People who have lost money get called back by someone offering to recover it, and that is a separate scam that runs on the wreckage of the first. We have written about it, and the rule is short — nobody who contacts you can get your money back for a fee.
The small-business version, and the control that works
For a business, this stops being a personal-vigilance problem and becomes a process problem, which is good news, because processes can be fixed once and stay fixed.
The exposure is that whoever pays your bills does it under time pressure, often for vendors they interact with rarely, and searching is the fastest way to get to a payment page. Every one of the conditions this scam needs is a normal Tuesday in accounts payable. The fix is a vendor list — a shared record with each vendor's account number, the exact payment URL, and the phone number taken from a contract or an invoice, not from a search. Pay from that list. Nobody pays a vendor from a search result, and a new vendor gets added to the list only by someone with authority to do it.
The support-call half needs one written rule that any employee can follow without judgement: nobody installs remote-access software, and nobody grants a screen-sharing session, on the strength of a number they found themselves or a call they received. Support sessions happen only with a provider you already have a relationship with, contacted through a number you already hold. If your staff know that rule is company policy, it takes the pressure off them entirely — they do not have to out-argue a professional on the phone, they just have to point at the rule.
Two more that cost nothing. Give card-payment authority to as few people as possible, and check the statement monthly for small recurring charges rather than only for large ones, because the subscription pattern the FTC described is deliberately sized not to be worth investigating. And if you use a bookkeeper or an outside AP service, make sure this rule is theirs too — the payment does not have to be made in your office to come out of your account.
The short version, and when to call us
Collapse or scroll past the sponsored block on any search where you are trying to reach a company. If you do click an ad, use "About this advertiser" and check that the verified name is the company you were looking for. Better still, do not search at all for money or for support: get the address from the bill, the number from the back of the card, the sticker on the router, or the app you are already signed in to, and bookmark the real payment page the first time you land on it. And hold one rule with no exceptions — nobody legitimate needs remote control of your computer to give you a refund.
If you think you paid the wrong site, check with the real biller before anything else, then call your card issuer on the number on the card. If you let someone in, disconnect first, change your email password from another device, and call your bank.
We clean up after these calls regularly across Southern California and the Coachella Valley — removing remote-access tools, checking what was actually done to a machine while a stranger was on it, securing the email account that everything else resets through, and rebuilding a machine properly when that is the honest answer. We also set households and small businesses up so this stops being a risk: a bookmarked payment folder, two-factor turned on where it matters, and a written rule for staff about who is allowed to connect. We do not sell antivirus subscriptions or take commissions from anyone, so if the right answer is that nothing was installed and you are fine, that is what you will be told.
Keep reading
- Is That Download Site Real? Fake "Official" Pages Now Outrank the Software They Copy
- Got a Text About an Unpaid Toll or a "Verify Your Account"? How to Tell If It's a Scam
- That "Geek Squad" or "Norton" Renewal Invoice Is a Scam — and So Is the "Refund"
- Someone Says They Can Get Your Money Back? That's the Second Scam
- That "Windows Update" Screen Telling You to Paste a Command Is a Scam
- Your Email Got Hacked? The Steps That Actually Lock the Intruder Out
- Your Password "Appeared in a Data Leak": What That Warning Means and What to Do
Free calculators
Service areas we cover
We don't sell hardware or warranties — call and we'll tell you what's worth buying and upgrading.
Call (626) 655-0020