Russian Developer Extradited Over Google Ads Scheme That Stole Bank Logins
Federal prosecutors say a Russian web developer helped run a bank account takeover operation that used sponsored search ads to send customers to fake login pages, capturing credentials from thousands of victims.
A Russian web developer accused of helping run a large-scale bank account takeover operation has been extradited to the United States, where federal prosecutors say the group bought sponsored search engine links that sent banking customers to fake login pages and allowed criminals to drain real accounts.
The Justice Department announced the extradition on Sept. 8, identifying the defendant as Sergei Anatolyevich Filimonov, 36, a Russian national and web developer. A federal grand jury indicted him on Nov. 4, 2025, and authorities later extradited him from the Republic of Georgia. Prosecutors allege he developed and maintained infrastructure supporting the operation, including databases storing more than 5,000 stolen login credentials and software designed to capture sensitive authentication data.
According to federal prosecutors, the scheme relied on spoofed domains that mimicked websites belonging to federally insured financial institutions. The conspirators then purchased sponsored search engine links that could appear when someone searched for their bank. A click sent the customer to a fraudulent login page, where victims entered their credentials believing they had reached their bank. Prosecutors say the group then used the stolen credentials to access real bank accounts, check balances and initiate unauthorized wire transfers.
The newest Justice Department announcement says the conspirators purchased sponsored search-engine links but does not name a particular search engine. However, the department previously described the same bank account takeover operation when it seized the group's backend domain in December 2025. In that announcement, investigators specifically said the criminal group delivered fraudulent advertisements through search engines including Google and Bing. The ads imitated sponsored search ads used by legitimate banks, and victims who clicked them were redirected to fake banking websites controlled by the criminals.
That earlier investigation had identified at least 19 victims across the United States by December 2025. The Justice Department reported approximately $28 million in attempted losses and about $14.6 million in actual losses tied to those victims.
The trap works because a paid search result can appear in a place many people naturally look first. A user searches for their bank, a result appears near the top, and the wording looks familiar enough that the click happens before the address is studied. Most search ads are legitimate, but the FBI warns that criminals can buy ads that imitate real businesses and direct users to convincing phishing sites. The bureau refers to this tactic as SEO poisoning in its account takeover guidance.
The problem extends far beyond one alleged criminal operation. Since January 2025, the FBI's Internet Crime Complaint Center has received more than 5,100 complaints reporting account takeover fraud, with reported losses exceeding $262 million. Criminals use several methods to get inside accounts, and fraudulent banking websites remain one of them. The FBI says victims can encounter a phishing site after clicking a fake search advertisement. Attackers may also try to obtain a one-time passcode if an account uses multifactor authentication. Once criminals gain access, they may move money to accounts they control, which can make recovery difficult, especially when funds move quickly.
Microsoft told CyberGuy that it has policies and detection mechanisms designed to help prevent misleading advertising. The company said that when it becomes aware of ads that violate its policies, it takes action to remove them and uses what it learns to strengthen its detection capabilities. Microsoft also encourages users to report suspicious ads through its «Report a Concern» form. Google did not respond to a request for comment before the deadline.
Consumers do not need to stop banking online, but changing how they reach a bank's login page can lower the risk. The FBI specifically recommends using bookmarks or favorites to reach login pages rather than clicking search results or advertisements. If a bank's verified app is already installed, opening it directly removes the search-result step where this particular scam tries to catch people. Visiting a bank's verified website and saving it as a bookmark offers another layer of protection, as does taking a moment to inspect the address before entering any credentials.



