Criminals Use Paid Search Ads to Harvest Bank Login Credentials
Federal prosecutors say a Russian web developer helped run a scheme that bought sponsored search ads to direct users to fake banking login pages, stealing credentials and draining accounts.
Authorities have extradited Sergei Anatolyevich Filimonov, a 36-year-old Russian web developer, after a grand jury indictment alleged he built and maintained the infrastructure for a widespread bank account takeover scheme. The operation bought sponsored search-engine results that mimicked legitimate bank ads, leading users who searched for their banks to fraudulent login pages. Victims entered their credentials, which were captured and later used to check balances and execute unauthorized wire transfers.
The Justice Department previously identified at least 19 U.S. victims and reported roughly $28 million in attempted losses and $14.6 million in actual losses. The scheme exploited the trust users place in top-ranked paid ads, a tactic the FBI describes as SEO poisoning. Officials advise using bookmarks, official apps, and careful URL checks to avoid such scams.
Why it matters
The scam shows how paid online ads can be weaponized to steal banking credentials, threatening millions of users.
In this story
