• Tech Tech

DOJ says sponsored bank links on Google and Bing helped scammers steal $14.6 million

The FBI recommends using bookmarks or favorites for your financial logins instead of ads or search results.

A person typing on a laptop.

Photo Credit: iStock

Typing your bank's name into Google and clicking the first result may feel like the quickest way to log in — but federal investigators say that common habit became the entry point for a scheme that stole credentials and drained real accounts. 

The warning took on new urgency Sept. 8, when the Department of Justice announced the extradition of Sergei Anatolyevich Filimonov, a 36-year-old Russian national and web developer accused of helping support the operation's infrastructure, Fox News reported.

Here's what to know

Federal prosecutors allege the group paid for sponsored search links so their ads would appear when customers searched for their banks.

Prosecutors say the credentials entered on those fake pages were later used to log in to real bank accounts, review balances, and send unauthorized wire transfers. 

Rather than reaching a legitimate website, victims were reportedly redirected to spoofed domains built to resemble pages for federally insured financial institutions.

The indictment alleged that Filimonov helped develop and maintain databases containing more than 5,000 stolen credentials, along with software designed to capture sensitive authentication data. 

A federal grand jury indicted him on Nov. 4, 2025, and U.S. authorities extradited him from the Republic of Georgia.

The Sept. 8 announcement did not name a specific search engine, but in a December 2025 announcement about the same operation, the DOJ said that fraudulent ads had appeared on Google and Bing. 

By December 2025, the DOJ had identified at least 19 U.S. victims, with about $28 million in attempted losses and roughly $14.6 million in actual losses.

More background

What makes the scam especially tricky is that the usual red flags may be absent. 

Instead of an obviously fake email or a suspicious text message, a customer may simply search for a bank, see a prominent result, and click.

The FBI advised against relying on paid search placements for sensitive tasks. 

The bureau called the tactic "SEO poisoning" and warned that criminals can purchase lookalike ads that send users to phishing sites.

Because these pages closely mimic real bank websites, even careful consumers can miss a slightly altered web address before entering a username, password, or one-time passcode.

Since January 2025, the FBI's Internet Crime Complaint Center has logged more than 5,100 complaints linked to account takeover fraud, with reported losses exceeding $262 million. 

Once funds are transferred to accounts controlled by scammers, recovering that money can become much more difficult.

What can be done?

The safest solution is also one of the simplest: Do not use search results to log in to your bank.

Open your bank's verified app directly or use a bookmark you created after confirming the correct website. The FBI recommends using bookmarks or favorites for your financial logins instead of ads or search results.

It also helps to slow down before entering any information. 

Check the full web address, not just the look of the page, and do not assume a "Sponsored" label means the destination has been vetted.

A password manager can also serve as a warning sign. If it normally fills in your banking login but suddenly stays blank, you may be on the wrong site.

Turn on multifactor authentication, enable account alerts for logins and withdrawals, and regularly review statements for unexpected activity.

If you already entered your credentials on a suspicious page, contact your bank using a trusted phone number, change the exposed password immediately, and report fraudulent transfers to the Internet Crime Complaint Center as quickly as possible.

In a scam built around ordinary online behavior, breaking the habit of searching for your bank may be among the most effective defenses.

Where can I learn more?

These articles look at scam crackdowns, fake site networks, and ad-driven crypto theft.

• Google alleged an AI scam ring built 9,000 fake sites and 1 million domains.

• In the U.K., a crypto ad preceded device takeovers that drained £250,000 from a woman in her 70s.

• An FBI-led operation shattered a pig-butchering network with 276 arrests and $701 million seized.

Get TCD's free newsletters for easy tips, smart advice, and a chance to earn $5,000 toward home upgrades. To see more stories like this one, change your Google preferences here.

Cool Divider