DOJ Warns Fake Google and Bing Bank Ads Helped Scammers Steal $14.6 Million From US Victims
Prosecutors allege criminals used sponsored search links to steal banking credentials and make unauthorised wire transfers from at least 19 US victims

The US Department of Justice has warned that fraudulent bank advertisements appearing on Google and Bing were used in an alleged account takeover scheme that resulted in approximately $14.6 million (£11.0 million) in actual losses among at least 19 identified US victims.
Prosecutors say the scheme used sponsored search links to direct banking customers to fake login pages designed to capture credentials before those details were allegedly used to access real accounts and make unauthorised wire transfers.
The latest development came after the DOJ announced on 8 September that Sergei Anatolyevich Filimonov, a 36-year-old Russian national and web developer, had been extradited from the Republic of Georgia to the US.
Prosecutors allege that Filimonov helped develop and maintain infrastructure used by the operation. He pleaded not guilty to the charges on 4 September, according to the US Attorney's Office for the Northern District of Georgia.
Fake Google and Bing Ads Targeted Bank Customers
The alleged scheme relied on a deceptively ordinary online habit. Customers searching for their bank could encounter a sponsored result that appeared to lead to the institution's genuine website. Instead, prosecutors say the links redirected users to fraudulent pages designed to resemble legitimate banking websites.
The DOJ's September announcement described the links as sponsored search-engine advertisements. An earlier DOJ announcement concerning the same investigation specifically identified Google and Bing.
The fraudulent pages were allegedly designed to collect banking credentials, including information that could later be used to access victims' accounts.
Prosecutors allege that the stolen credentials were then used to log into genuine bank accounts, check balances and initiate unauthorised wire transfers.
The indictment accuses Filimonov of helping create and maintain online infrastructure for the operation. That allegedly included interactive databases containing more than 5,000 stolen login credentials and software designed to capture and transmit sensitive authentication information.
A federal grand jury returned the indictment against Filimonov on 4 November 2025. The allegations against him have not been proven in court.
The financial figures give a sense of the scale prosecutors say they uncovered. By December 2025, the DOJ had identified at least 19 victims, with approximately $28 million (£21 million) in attempted losses and $14.6 million (£11.0 million) in actual losses.
The $14.6 million (£11.0 million) figure therefore refers to losses identified in connection with those victims, rather than suggesting that every person targeted by the wider operation lost money.
DOJ Warns Search Ads Can Hide Phishing Sites
The danger lies partly in how little the interaction may resemble a conventional scam. There may be no suspicious email or alarming text message. Instead, a customer can search for a familiar bank, see a prominent advertisement and click it without realising the destination is fraudulent.
The FBI has described similar account takeover schemes as 'SEO poisoning'. Its guidance says criminals can use search-engine advertising to make fraudulent websites appear prominently to people looking for legitimate businesses or financial institutions.
The FBI recommends avoiding search advertisements when accessing banking services and using a verified bookmark or the bank's official app instead. Users are also advised to check the full web address carefully before entering sensitive information.
A sponsored label should not be treated as proof that a website has been independently vetted. A fraudulent domain can be designed to look remarkably similar to the genuine address, while the page itself may reproduce familiar branding and login screens.
The wider threat is considerably larger than the particular investigation involving Filimonov.
In a November 2025 alert, the FBI said its Internet Crime Complaint Center had received more than 5,100 complaints involving account takeover fraud since January that year, with reported losses exceeding $262 million (£197.3 million). Those figures cover account takeover fraud more broadly and are not limited to the Google and Bing advertising scheme.
Once money has been transferred into accounts controlled by criminals, the FBI warns that recovering it can become difficult. That makes the first few seconds of an online banking session important.
FBI Cautions Customers
For customers, the FBI's advice is relatively straightforward. Rather than searching for a bank and clicking an advertisement, use an official banking application or a verified bookmark.
Check the complete web address before entering credentials, enable multifactor authentication where available and monitor account activity for unexpected transactions.
Anyone who believes they have entered banking information into a fraudulent website should contact their bank through a trusted phone number, change the exposed password and report suspected fraudulent transfers to the FBI's Internet Crime Complaint Center.
The case against Filimonov remains ongoing, with prosecutors' allegations still to be tested in court.
© Copyright IBTimes 2026. All rights reserved.

























