A Russian man has been extradited to the United States over a scheme that stole online banking logins and used them to take money from victims’ accounts. U.S. prosecutors say Sergei Filimonov and others bought sponsored search ads and used spoofed domains and fake bank login pages to harvest credentials from November 2023 through October 2025, then accessed accounts and initiated unauthorized wire transfers. Authorities previously seized the domain web3adspanels.org and said it held credentials for thousands of victims, with at least 19 identified victims, about $28 million in attempted losses, and roughly $14.6 million in confirmed losses.
Why it matters: This matters to bank customers and fraud defenders because it shows how search ads and lookalike login pages can directly lead to account takeovers and stolen funds. Users should be cautious with sponsored links when signing in to financial accounts, and banks should harden phishing detection and monitor for fraudulent domains and unusual wire activity.
2026.09.08
100% relevant
This article establishes a trackable story because it provides a specific defendant, extradition, timeline, attack method, seized infrastructure, and quantified losses for a distinct bank account takeover campaign.
← Back to all stories