Quick summary: The DOJ says criminals bought sponsored search ads on Google and Bing to funnel bank customers to cloned login pages, harvesting credentials and stealing about $14.6 million. Sergei Anatolyevich Filimonov was extradited and indicted for building databases with over 5,000 stolen credentials. The FBI labels the tactic "SEO poisoning" and urges users to avoid search results for banking logins — use verified apps or bookmarks, enable MFA, and report fraud to IC3.
DOJ: Paid Search Ads on Google and Bing Fueled $14.6M Bank-Login Scam — Developer Extradited

Typing your bank's name into a search engine and clicking the top result is a common shortcut — but federal investigators say criminals exploited that habit to steal credentials and drain accounts.
What happened: On Sept. 8 the Department of Justice announced the extradition of Sergei Anatolyevich Filimonov, a 36-year-old Russian national and web developer accused of helping build and maintain infrastructure used in the operation. Prosecutors allege the group paid for sponsored search ads that appeared when customers searched for their banks, then routed those clicks to cloned websites that captured login credentials.
According to the indictment, credentials entered on those spoofed pages were used to access real accounts, check balances and initiate unauthorized wire transfers. Investigators say Filimonov helped develop databases that held more than 5,000 stolen credentials and created software to harvest sensitive authentication data. A federal grand jury indicted him on Nov. 4, 2025; U.S. authorities later extradited him from the Republic of Georgia.
Scope and Impact
In a December 2025 statement about the case, the DOJ said fraudulent ads had appeared on both Google and Bing. By that month, investigators had identified at least 19 U.S. victims, with roughly $28 million in attempted losses and about $14.6 million in actual losses. Since January 2025, the FBI’s Internet Crime Complaint Center (IC3) has recorded more than 5,100 account-takeover complaints with reported losses exceeding $262 million.
Why This Scam Worked
The scheme is particularly deceptive because many usual red flags are absent. Instead of receiving a suspicious email or text, victims simply searched for their bank, saw a prominent sponsored result, and clicked. The tactic — which the FBI calls "SEO poisoning" — relies on criminals buying lookalike ads that funnel users to phishing sites that closely mimic real bank pages. Even careful users can miss subtle URL differences or fake security prompts before entering a username, password, or one-time passcode.
How To Protect Yourself
- Don't use search results for banking logins. Open your bank's verified mobile app or use a bookmark you created after confirming the correct website.
- Check the full URL. Verify the web address, not just how the page looks.
- Use a password manager. If it normally autofills credentials but doesn't on a page, treat that as a warning sign.
- Enable multifactor authentication (MFA). Use app-based or hardware MFA where possible.
- Set account alerts and monitor statements. Enable notifications for logins and withdrawals and review activity regularly.
- If exposed, act fast. Contact your bank using a trusted phone number, change the affected password immediately, and report fraud to the IC3.
Tip: Rely on official apps or bookmarks for financial logins and pause to confirm the address before entering credentials — a few extra seconds can prevent major losses.
This case underscores how ordinary browsing habits can be weaponized. Breaking the habit of using search results to reach financial sites is one of the simplest and most effective defenses.
Related Incidents
Law-enforcement and industry reports show similar large-scale threats: claims that an AI-driven scam built thousands of fake sites and millions of domains, a U.K. crypto ad that preceded device takeovers and large losses, and an FBI-led operation that dismantled a pig-butchering network with hundreds of arrests and large seizures.
Help us improve.

























