There are conflicting incentives for search engines (Yahoo seems much worse than Google for this) to allow paid results for phishing sites above the real result. I can often tell exactly which phishing site a user is getting directed to instead of the real domain that they want.