Sponsored-Link Bank Phishing: How a Google Ad Above the Real Login Took $14.6 Million
By Sethu Satheesh · 12 Sept 2026 · 17 min read
Threat Actor: Sergei Anatolyevich Filimonov (charged, presumed innocent) and a co-defendant whose name is redacted; "others known and unknown to the Grand Jury" · Target: Online-banking customers of FDIC-insured US banks who reached the bank by search; at least 19 identified victims including two companies in the Northern District of Georgia
Source: www.courtlistener.com
Executive Summary
On 4 September 2026 Sergei Anatolyevich Filimonov, 36, a Russian web developer, appeared before a magistrate judge in Atlanta after extradition from the Republic of Georgia, pleaded not guilty to eleven counts, and was ordered detained as a flight risk. A federal grand jury in the Northern District of Georgia had indicted him under seal on 4 November 2025, alongside a co-defendant whose name is redacted from every public filing. The indictment alleges that from November 2023 to October 2025 the conspirators ran a bank account takeover operation built on one idea: when a customer types their bank's name into Google or Bing, the first result is a paid advertisement, and anyone can buy one. Their advertisements imitated the banks' own, sent the customer to a cloned login page on a look-alike domain, captured the username, password, security-question answers and two-factor codes the customer typed, and passed them to operators who logged into the real bank and wired the money out. Nothing below is proven; an indictment alleges.
The scale is in two sets of numbers that the September coverage has run together. The Justice Department's December 2025 announcement of the seizure of the backend domain, web3adspanels[.]org, said the FBI had identified "at least 19 victims throughout the United States, including two companies in the Northern District of Georgia," with "attempted losses of approximately $28 million dollars and actual losses of approximately $14.6 million dollars." The indictment pleads the two Georgia companies specifically. On 6 June 2024 the conspirators are alleged to have phished the banking credentials of an employee of an Atlanta company and induced them to hand over "additional information to bypass account security measures"; the next day they "caused and attempted to cause the unauthorized transfer of more than $5,000,000" from two of its accounts, with Count Three putting the figure at $5,579,800. One wire that went through, $299,600, landed in an account belonging to Aston Eric, LLC, a company registered with the Georgia Secretary of State on 4 April 2024, two months before the theft, at the same bank as the second victim. On 15 November 2024 the same method took an employee of a company in Cumming, Georgia; approximately $735,000 was attempted from its accounts.
The tradecraft around the phishing page is what makes the case worth studying. The indictment alleges the conspirators "sent hundreds of unsolicited emails to the email address associated with the victim's login credentials and bank account" to bury the bank's transaction alerts, and that they induced victims to transmit "two-factor authentication text message codes," which means the cloned page was relaying in real time. Filimonov's alleged role was the infrastructure: he "developed, tested, and maintained" the fraudulent bank websites and, with others, the "interactive database of stolen login credentials, accessible to members of the conspiracy" that held more than 5,000 sets. That database was web3adspanels[.]org, registered on 20 October 2023, five weeks before the conspiracy's alleged start, and according to the Justice Department still serving as a backend "as recently as November 2025," which is after the indictment was returned and after 6 October 2025, the date on which the indictment says the defendants possessed the credentials "outside of the United States."
The investigation ran through three countries. Estonian police "preserved and collected data from servers hosting the phishing pages and the stolen login credentials," which places the hosting in Estonia; Georgian police arrested and surrendered Filimonov; the FBI's Tbilisi legal attaché coordinated. He is defendant number two on the docket. Who defendant number one is, where they are, and whether the $14.6 million was recovered, the record does not say.
Verification of Claims
-
Claim: Filimonov was extradited from Georgia and pleaded not guilty on 4 September 2026. → Verified → DOJ N.D. Ga. release, 8 September; docket 1:25-cr-00491, minute entry of 4 September: initial appearance, arraignment, "PLEA of NOT GUILTY … as to Counts 1r–11r," detention granted, Russian interpreter.
-
Claim: The scheme caused $14.6 million in losses to almost 20 victims. → Verified as the FBI's December 2025 figure → DOJ OPA release, 22 December 2025: "at least 19 victims … attempted losses of approximately $28 million dollars and actual losses of approximately $14.6 million dollars." The September 2026 release says only "millions." The indictment pleads two victims and $6,314,800 attempted.
-
Claim: The conspirators bought sponsored search links impersonating banks. → Verified as alleged → Indictment ¶¶7, 16(b), 18; December 2025 release: advertisements "through search engines, including Google and Bing," that "imitated the sponsored search engine advertisements used by legitimate banking entities."
-
Claim: More than 5,000 login credentials were stolen. → Verified as alleged → Indictment ¶22: "collected and attempted to collect more than 5,000 victim login credentials"; Count Seven: "approximately 5,000." Both are the government's count from the seized database.
-
Claim: Filimonov built the phishing sites and the credential database. → Verified as alleged → Indictment ¶20: "developed, tested, and maintained … the fraudulent websites"; ¶21: with others, "created, developed, and maintained online infrastructure to store victim login credentials." Denied by plea.
-
Claim: The mule account was a Georgia LLC formed two months before the theft. → Verified as alleged → Indictment ¶10: "Aston Eric, LLC was a company registered with the Georgia Secretary of State on or about April 4, 2024"; Count Five: $299,600 wired on 7 June 2024 to its account ending x0077 at BANK-2.
-
Claim: The backend domain was still active after the indictment. → Verified → Indictment returned 4 November 2025. December 2025 release: the domain "continued to host a backend server … as recently as November 2025." The registry record shows creation on 20 October 2023 and current nameservers
ns1/ns2.fbi.seized.gov. -
Claim: Filimonov stole $15 million. → False as phrased → The Daily Hodl's "$15,000,000" rounds the FBI's $14.6 million estimate of losses across the whole conspiracy. No figure is attributed to Filimonov personally, the indictment pleads a money judgment "representing the amount of proceeds obtained" without stating one, and he has been convicted of nothing.
-
Claim: He faces up to 175 years. → Verified as a statutory sum → DOJ: "a minimum of two years and a maximum penalty of 175 years." The two years is the mandatory consecutive term for aggravated identity theft; 175 is the arithmetic sum of maximums across eleven counts and bears no relation to a likely sentence.
-
Claim: Filimonov was arrested in October 2025. → Assessed, not confirmed → No arrest date is published. Counts Seven and Eight allege possession of the credentials and the capture software "on or about October 6, 2025, outside of the United States," by defendants "who will be first brought to the Northern District of Georgia," the standard venue formula for conduct at the time of a foreign arrest. The Record and CyberScoop give no date.
Timeline
| Date | Actor | Event | Source |
|---|---|---|---|
| 20 October 2023 | Conspirators | web3adspanels[.]org registered through Tucows. |
Registry record |
| November 2023 | Conspirators | Conspiracy begins, per indictment. | Indictment ¶1 |
| 4 April 2024 | Unknown | Aston Eric, LLC registered with the Georgia Secretary of State; account x0077 opened at BANK-2. | Indictment ¶10 |
| 6 June 2024 | Conspirators | Phish BANK-1 credentials of C.W., employee of COMPANY-1 (Atlanta), "through software code"; induce C.W. to transmit additional security information. | Indictment ¶29 |
| 7 June 2024 | Conspirators | Access COMPANY-1 accounts x1681 and x0489; attempt transfers totalling $5,579,800; wire $299,600 to Aston Eric, LLC. | Indictment ¶30, Counts 3, 5, 9, 10 |
| 15 November 2024 | Conspirators | Phish BANK-2 credentials of S.C., employee of COMPANY-2 (Cumming, Ga.); attempt ~$735,000 from accounts x7343 and x8643. | Indictment ¶¶31–32, Counts 4, 11 |
| 22 November 2024 | S.C. | Electronic transmission of S.C.'s credentials to a server outside the United States. | Count 6 |
| 6 October 2025 | Defendants | Alleged possession of ~5,000 credentials and capture software "outside of the United States." | Counts 7–8 |
| 4 November 2025 | Grand jury, N.D. Ga. | Sealed indictment; arrest warrant issued. | Docket |
| November 2025 | Conspirators | Backend on web3adspanels[.]org still active, per FBI. |
DOJ, 22 Dec 2025 |
| 25 November 2025 | FBI IC3 | PSA I-112525: 5,100+ ATO complaints since January, $262M+ losses. | IC3 |
| 22 December 2025 | DOJ | Announces seizure of web3adspanels[.]org; 19 victims, $28M attempted, $14.6M actual; Estonian police preserved server data. |
DOJ OPA |
| 3–4 September 2026 | N.D. Ga.; Filimonov | Extradited; redacted indictment filed; initial appearance, not-guilty plea, detention ordered; federal defender appointed. | Docket |
| 8 September 2026 | DOJ | Announces extradition. | DOJ N.D. Ga. |
| 9 September 2026 | Magistrate Judge Sommerfeld | Pretrial motions due 23 September; pretrial conference 28 September. | Docket, Doc. 18 |
Attack Anatomy
Loading diagram...
Stage 1: buying the top of the page
The indictment defines the mechanism in one paragraph: "A 'sponsored link' was a paid advertisement displayed by a search engine. Sponsored links can be purchased and appear when search engine users search for specific keywords." The conspirators bought them for bank names so that "their spoofed domains would appear in search results when victims sought to access the banking website of their financial institution by searching for their financial institution." The December 2025 release adds that the advertisements ran on Google and Bing and "imitated the sponsored search engine advertisements used by legitimate banking entities." Neither document says whether the advertisements were purchased under stolen accounts, through intermediaries, or directly; a co-conspirator "purchased online infrastructure … including websites, servers, and website traffic filtering tools," the last of which is the standard method for showing the phishing page only to real visitors and a harmless page to Google's reviewers.
Stage 2: the clone
The spoofed domains "linked to webpages that appeared indistinguishable from the actual login pages of the financial institutions they sought to imitate." Filimonov is alleged to have developed and tested them. The page captured the login and, per ¶16(d), induced customers "to transmit other account security information, including answers to security questions or two-factor authentication text message codes." An SMS code is useful for about a minute, so the page was relaying to an operator, or to automation, that was logging into the real bank as the victim typed. The indictment's phrase for both Georgia victims is "through software code" and "induced … to transmit additional information to bypass account security measures."
Stage 3: the panel
Credentials went to "an interactive database of stolen login credentials, accessible to members of the conspiracy," which also tracked "information about the compromised financial accounts to which the login credentials provided access." That is web3adspanels[.]org, described by the FBI as "a backend web panel to store and manipulate illegally harvested bank login credentials," holding more than 5,000 sets when seized. The name reads as an advertising-panel product; the registration predates the alleged conspiracy by five weeks. Estonian police preserved data from "servers hosting the phishing pages and the stolen login credentials," which places at least part of the hosting there.
Stage 4: the wire, and the noise
Operators "used stolen login credentials to log into banking websites … review account balances … and cause funds to be wired from the victims' accounts." The one wire the indictment itemises, $299,600 on 7 June 2024, went to Aston Eric, LLC: a Georgia entity two months old, banked at the same institution as the second victim. A domestic LLC with a domestic account is the receiving end that makes a same-day wire from a Georgia business look ordinary. Whether Aston Eric's registrant was a conspirator, a recruited mule, or a stolen identity is not alleged.
Concealment was by volume: "hundreds of unsolicited emails" to the victim's address, so that the bank's confirmation of a $299,600 wire arrived in the middle of a flood. Email bombing is documented in ransomware initial access; here it is the finishing move of a wire fraud.
Yield
The itemised attempts total $6,314,800 against two victims; the FBI's aggregate is $28 million attempted and $14.6 million actual across 19. The gap between attempted and actual is the banks' fraud controls working roughly half the time.
Accused
- Sergei Anatolyevich Filimonov, 36, Russian national, "web developer," "located outside of the United States" during the conspiracy. Defendant (2) on the docket. Extradited from Georgia; detained as a flight risk (order of Magistrate Judge Salinas, 4 September 2026); represented by the Federal Defender Program (Keenen Twymon). Not-guilty plea entered. Presumed innocent.
- Co-defendant, defendant (1), name redacted throughout the public indictment and omitted from both DOJ releases. Alleged to have registered the spoofed domains "using aliases" and purchased the infrastructure. Status unknown.
- Charges: Count 1, §1349 bank and wire fraud conspiracy; Count 2, §1029(b)(2) access device fraud conspiracy; Counts 3–4, §1344 bank fraud; Counts 5–6, §1343 wire fraud; Count 7, §1029(a)(3) possession of 15+ unauthorised access devices; Count 8, §1029(a)(4) possession of device-making equipment (the capture software); Count 9, §1029(a)(5); Counts 10–11, §1028A aggravated identity theft. Each conspiracy count carries the §3559(g)(1) enhancement for false domain registration. Forfeiture: money judgment.
- Court: N.D. Ga., 1:25-cr-00491-WMR-LRS, Judge William M. Ray II; prosecuted by AUSA Jessica C. Morris and CCIPS Senior Counsel Brian Mund.
- MITRE ATT&CK techniques (verified on attack.mitre.org, 12 September 2026):
- T1583.008 Acquire Infrastructure: Malvertising
- T1583.001 Acquire Infrastructure: Domains (spoofed bank domains)
- T1566.002 Phishing: Spearphishing Link
- T1557 Adversary-in-the-Middle (relayed login)
- T1111 Multi-Factor Authentication Interception (SMS codes)
- T1078 Valid Accounts
- T1657 Financial Theft
Technical Indicators
# From the indictment and DOJ releases. Historical; the backend is seized.
backend_panel:
domain: web3adspanels[.]org
registered: 2023-10-20 (Tucows)
seized: announced 2025-12-22; nameservers now ns1/ns2.fbi.seized[.]gov
active_until: "as recently as November 2025" (FBI)
contents: ">5,000 bank login credentials; account tracking"
phishing_hosting: servers in Estonia (data preserved by Estonian police)
spoofed_domains: not published; "similar to the domains of BANK-1, BANK-2, and other financial institutions"
delivery: paid search advertisements on Google and Bing imitating bank ads
capture: login, security-question answers, SMS 2FA codes; relayed
concealment: email bombing of victim inbox ("hundreds of unsolicited emails")
mule_entity:
name: Aston Eric, LLC
registered: Georgia Secretary of State, 2024-04-04
account: BANK-2 x0077
itemised_attempts:
- 2024-06-07: COMPANY-1, BANK-1, $5,579,800 attempted; $299,600 wired
- 2024-11-15: COMPANY-2, BANK-2, ~$735,000 attempted
ip_addresses: []
file_hashes: []Legal and Regulatory Response
Charges and posture. Eleven counts; detention ordered on the government's motion citing flight risk. Pretrial motions due 23 September 2026; pretrial conference 28 September. The government's estimated trial length is "short," which signals a documentary case built on the seized panel.
Seizure. The domain was seized under a warrant supported by an FBI affidavit, announced 22 December 2025, "approximately one month after" the IC3 PSA of 25 November. The affidavit is not public.
International. Estonia preserved server data and is credited in both releases through its Prosecutor General and Police and Border Guard Board; Georgia's Prosecutor General and Central Criminal Police handled the arrest and extradition; the FBI's Tbilisi legal attaché coordinated. Russia does not extradite its nationals; the arrest occurred because Filimonov was in Georgia.
Victim guidance. The FBI's advice in both releases is the same: navigate to banks by bookmark, not by search. The IC3 PSA reports 5,100 account-takeover complaints and $262 million in losses since January 2025, which makes this one operation, at $14.6 million, about 5.6% of reported national losses for the year.
Platforms. Neither Google nor Microsoft is named in the indictment beyond the December release's reference to advertisements on "Google and Bing." Neither has commented. No allegation is made against them.
Banks. BANK-1 and BANK-2 are described as FDIC-insured with headquarters in North Carolina and branches in the Northern District of Georgia. Neither is named. The $28 million attempted against $14.6 million actual implies roughly half of attempted transfers were stopped or reversed.
Impact Assessment
- Identified victims — Reported. At least 19 (FBI, December 2025); two pleaded in the indictment.
- Attempted losses — Reported. ~$28 million (FBI); $6,314,800 itemised.
- Actual losses — Reported. ~$14.6 million (FBI). Not itemised; not attributed to any defendant.
- Credentials stolen — Alleged. More than 5,000.
- Duration — Alleged. November 2023 – October 2025; backend active into November 2025.
- Recovery — Unknown. No restitution or clawback figure published.
- Co-defendant — Unknown.
- Conviction — None.
Lessons and Defensive Recommendations
For anyone who banks online
- Never reach your bank through a search result. The first result is an advertisement, an advertisement can be bought by anyone, and the page it leads to can be a pixel-perfect copy. Bookmark the login page or type the address.
- A login page that asks for your SMS code and then for a second one, or for security-question answers you did not expect, is relaying you to the real bank. Stop.
- A sudden flood of junk email is a signal, not a nuisance. It is used to hide the one message that matters. Check your accounts directly when it happens.
For banks and payment operators
- Monitor paid search for your own brand terms and file trademark complaints against impersonating advertisements; the platforms' processes exist and are slow, which is why they must be continuous.
- A new-payee wire of six figures from a business account, minutes after a login from a new device, on the day after a credential reset, is the pattern in Count Three. The half of attempts that were stopped show the controls exist; the half that succeeded show the thresholds.
- Domestic LLCs formed weeks earlier with a first large inbound wire are mule accounts. Aston Eric, LLC was two months old.
For search platforms
- The indictment is a description of a product feature working as designed: keyword purchase, ad copy that matches the brand, and traffic filtering to defeat review. Impersonation of a financial institution in a sponsored link should be an enforceable category with pre-publication verification, not a post-hoc complaint.
For defenders and researchers
- The paid-search lure is the same channel as the "Continue with" lure and the fake-recruiter lure: a legitimate feature of a legitimate platform, used at scale. Detection at the platform is the only detection that scales.
Sources
- United States v. Filimonov, N.D. Ga. 1:25-cr-00491-WMR-LRS. Redacted indictment, Document 12, returned 4 November 2025, filed 3 September 2026; Government's Motion for Detention (Doc. 16) and Order (Doc. 17), 4 September 2026; Pretrial Scheduling Order (Doc. 18), 9 September 2026. Via CourtListener.
- US Department of Justice, USAO Northern District of Georgia. "Russian National Extradited to United States for Bank Account Takeover Fraud Scheme Causing Millions of Dollars in Losses". 8 September 2026.
- US Department of Justice, Office of Public Affairs. "Justice Department Announces Seizure of Stolen-Password Database Used in Bank Account Takeover Fraud". 22 December 2025.
- FBI Internet Crime Complaint Center. "Account Takeover Fraud via Impersonation of Financial Institution Support", Alert I-112525-PSA. 25 November 2025.
- The Record. "Russian suspect in bank account takeovers is extradited to US". 8 September 2026.
- CyberScoop. "Russian national extradited to US for alleged involvement in bank-account takeover scheme". September 2026.
- BleepingComputer. "FBI seizes domain storing bank credentials stolen from U.S. victims". December 2025.
- The Hacker News. "U.S. DoJ Seizes Fraud Domain Behind $14.6 Million Bank Account Takeover Scheme". December 2025.
- Atlanta News First. "Russian web developer extradited in international bank fraud case, pleads not guilty in Atlanta". 8 September 2026.
- MITRE ATT&CK. T1583.008 Malvertising; T1111; T1557. Accessed 12 September 2026.
Related Research
A Russian national extradited from Cyprus faces trial over a 2016–17 campaign that used 225 fake accounts on a Santa Clara freelance platform to send Excel macros dropping the TeamViewer-abusing TVRAT. The unsealed indictment gives numbers the press release rounded away.
For 17 days in August 2026 an attacker registered Lenovo IDs on other people's email addresses and signed straight into their Dropbox accounts. Lenovo's verification was the flaw; Dropbox's willingness to trust it without a password was the breach.
India's cybercrime agency identified a wave of fraudsters using Google Firebase to host phishing pages and collect stolen banking credentials from millions of users.