Federal prosecutors have uncovered a sophisticated scheme in which criminals purchase paid search advertisements that look like legitimate bank results. When users click the ads, they are taken to counterfeit login pages that capture banking credentials and enable unauthorized wire transfers.
How the scam works
According to the Justice Department, the group—led by Russian web developer Sergei Anatolyevich Filimonov—created spoofed domains that closely resemble the websites of federally insured financial institutions. The conspirators then bought sponsored search‑engine links that appear near the top of results when a consumer types a bank’s name.
A click on one of these ads redirects the victim to a fraudulent login page. Once the user enters a username and password, the attackers harvest the data, log into the real account, check balances, and initiate wire transfers. The indictment alleges that the operation maintained databases containing more than 5,000 stolen credentials and software designed to capture authentication data.
Scope of the problem
The DOJ announced on Sept. 8 that the group’s activities have already affected at least 19 victims across the United States, with roughly $28 million in attempted losses and about $14.6 million in actual losses reported through Dec. 2025. The FBI’s Internet Crime Complaint Center has logged over 5,100 complaints of account‑takeover fraud since Jan. 2025, with total reported losses exceeding $262 million.
Official response
Microsoft, which operates the Bing search platform, said it has policies and detection mechanisms to remove ads that violate its rules and that it uses violations to improve its systems. The company also encourages users to report suspicious ads through its “Report a Concern” form. Google was contacted for comment but did not respond before the deadline.
Protecting yourself
The FBI recommends using bookmarks or the bank’s official mobile app instead of searching for a bank in a web browser. Before entering credentials, users should verify the URL for misspellings or subtle changes that indicate a fake site. Enabling two‑factor authentication adds a layer of security, but it does not protect against phishing pages that capture the one‑time code.
Additional safeguards include:
- Saving the bank’s verified website as a bookmark and using that link each time.
- Inspecting the domain name carefully for any variations.
- Using a trusted password manager that can flag mismatched URLs.
- Keeping antivirus software up to date to warn of known phishing sites.
- Setting up account alerts for withdrawals and new logins, and reviewing activity promptly.
While online banking remains convenient, changing the way you reach your bank’s login page can dramatically reduce the risk of falling victim to these paid‑search scams.
Original reporting: Fox News (HLL/CB) — read the source article.