Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

The first search result may not be the company you meant to pay

You want to settle a bill quickly, so you click the first result. Check who will receive the money before approving a transfer or entering card details.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
9 September 2026
READING TIME
7 min read
TOPIC
Human Security
The first search result may not be the company you meant to pay

The bill is on the table, its deadline is today and the provider’s app has disappeared somewhere on your phone. You search for the company name followed by “pay bill”. The first result looks familiar, carries the right headline and promises a quick payment. Only afterwards do you discover that it belonged to a paid intermediary — or somebody merely impersonating the provider.

Not every third-party payment service is fraudulent. The problem begins when a result looks official when it is not, hides an extra fee or sends the money somewhere the customer did not intend to choose.

An advert can look like an ordinary result

Paid listings can occupy the first positions above the company’s genuine page. The advertising label may be easy to miss, while the headline can contain the name of an energy company, mobile operator or insurer. A high position does not establish who the advertiser is.

Read the domain before clicking, not only the large headline. Adding your provider’s name to somebody else’s domain does not make it the provider’s website. If the page describes itself as a “payment service”, establish who operates it, what it charges and when the biller will actually receive the money.

Begin with the document you already have

The safest route usually does not begin with a search engine. Use the address printed on a genuine bill, the official app you already installed or your own saved bookmark. You can also type a known company address yourself. When unsure, use the support number on an earlier statement or contract — not the advert you are trying to check.

Before paying, compare the recipient’s name, amount, customer or invoice reference and due date. Pause at an unexpected “activation fee”, a request to transfer funds to a personal account or a warning that only immediate payment will prevent disconnection.

Do not provide more information than a bill requires

A payment page should not need your email password, account recovery code or remote access to your telephone. If a supposed adviser asks you to install software, read out a text-message code or share the screen showing your bank, end the conversation.

When using a card, make sure you understand which merchant will appear on the statement and whether you accept the fee. A padlock beside the address means the connection is encrypted; it does not establish that the service is your provider’s official payment channel.

If the payment took the wrong route

Keep the receipt, site address, merchant name from the statement and all correspondence. Contact the genuine provider and ask whether it received the payment. Then report the issue to the intermediary and your bank or card issuer, explaining how the page presented itself and what it charged.

Do not immediately send a second payment because another urgent message appears. First find out where the initial money went and whether it can be reversed. Do not pay a “release” or “refund” fee to someone who contacts you unexpectedly after the report.

What the source says and what Breachroad recommends

On 17 August 2026, the US Federal Trade Commission warned that searching online for a place to pay a bill can surface a paid listing for an unrelated intermediary. The service may add a fee while the customer mistakes it for the biller’s official website. The FTC advises moving past the adverts and typing the company’s known address directly.

Breachroad’s practical rule is simple: begin a payment from an invoice, known app or saved bookmark, not from the order of search results. The habit helps at home and at work, where people pay for domains, deliveries, licences and supplier invoices.

Our guide to recognising phishing covers more warning signs. We help organisations turn these principles into everyday habits through cybersecurity training.

SHARE / COPY