Searching for a bank online may seem like a safe way to reach its website. Federal investigators now warn that scammers used paid search ads to exploit exactly that habit. The U.S. Department of Justice says fraudulent bank links on Google and Bing helped criminals collect login details and use them to access real financial accounts.
The case highlights a simple online risk: a search result can look legitimate without actually leading to the bank.
How the Scheme Worked
Federal prosecutors allege that the group paid for sponsored search placements that appeared when people searched for their banks. Instead of taking users to legitimate financial websites, the ads reportedly sent them to fake domains designed to closely resemble federally insured institutions.
Victims entered usernames, passwords, and other authentication details on those pages. According to prosecutors, criminals then used the stolen information to access genuine bank accounts, check balances, and send unauthorized wire transfers.

Freepik | Federal investigators warn that paid search ads on Google and Bing are leading users to fraudulent bank websites.
The scheme did not depend on obviously suspicious emails or text messages. A person could simply search for a familiar bank and click a prominent result.
The FBI refers to this type of tactic as “SEO poisoning.” Criminals can manipulate search visibility or purchase lookalike ads to place phishing websites where users expect to find legitimate services.
DOJ Case Details
The DOJ announced on Sept. 8 that U.S. authorities had extradited Sergei Anatolyevich Filimonov, a 36-year-old Russian national and web developer, from the Republic of Georgia. Prosecutors accuse him of helping develop and maintain infrastructure connected to the operation.
The indictment alleges that Filimonov supported databases containing more than 5,000 stolen credentials and software designed to collect sensitive authentication information.
A federal grand jury indicted Filimonov on Nov. 4, 2025. The September announcement did not identify a specific search engine. However, a DOJ announcement in December 2025 concerning the same operation said fraudulent ads had appeared on Google and Bing.
By December 2025, investigators had identified at least 19 U.S. victims. The DOJ reported approximately $28 million in attempted losses, including about $14.6 million in actual losses.
Why These Ads Can Fool Users

Gemini | Fake bank sites mimic real designs, so check for subtle domain errors rather than relying on visuals or sponsored tags.
Fake banking pages can closely copy the design of real websites. That makes visual checks less reliable, especially when someone is trying to log in quickly.
The web address offers a better clue. A small change in the domain can signal that the page is not genuine. A “Sponsored” label also does not mean the website has been personally verified by the bank.
The FBI has also reported a wider account takeover problem. Since January 2025, its Internet Crime Complaint Center has recorded more than 5,100 complaints connected to account takeover fraud, with reported losses above $262 million.
Once scammers move stolen money into accounts they control, recovery can become much harder.
Safer Ways to Access a Bank
The FBI recommends avoiding search results and paid ads when accessing financial accounts. Instead, use the bank’s official mobile app or a bookmark created after confirming the correct website.
Other safeguards can reduce the risk:
1. Check the complete web address before signing in.
2. Use multifactor authentication.
3. Enable alerts for logins, transfers, and withdrawals.
4. Review bank statements for unusual activity.
5. Pay attention if a password manager suddenly refuses to fill in saved credentials.
If banking information has already been entered on a suspicious website, contact the bank through a trusted phone number and change the exposed password immediately. Unauthorized transfers should also be reported to the Internet Crime Complaint Center as soon as possible.
The DOJ case shows how ordinary search habits can become part of a phishing scheme. Searching for a bank is convenient, but it is not the safest route to a financial login. Using a verified app or trusted bookmark removes the search-ad step and makes it harder for a fake banking page to intercept sensitive information.