Scammers are buying Google ads to steal bank logins
The US Justice Department announced in September that a Russian web developer had been extradited for his role in a sophisticated bank account takeover operation. Criminal groups purchased sponsored search advertisements on Google and Bing that appeared when customers searched for their banks, directing them to fraudulent login pages that mimicked legitimate banking websites. Once victims entered their credentials, believing they had accessed their genuine bank accounts, the criminals captured this information and used it to access real accounts, check balances and initiate unauthorised wire transfers. This scam exploits the everyday habit most people have of searching for their bank online and clicking the first result without careful verification.
The alleged operation, led by Sergei Anatolyevich Filimonov, used spoofed domains to mimic federally insured financial institutions and maintained databases containing over 5,000 stolen login credentials. By December 2025, investigators had identified at least 19 victims across the United States, with approximately £28 million in attempted losses and around £14.6 million in actual losses linked to those cases. Both Google and Bing confirmed the fraudulent advertisements had appeared on their platforms, prompting Microsoft to reaffirm its policies against misleading advertising and its commitment to removing violating ads. The effectiveness of the scam lies in how paid search results appear in places users naturally look first, making deceptive advertisements difficult to distinguish from legitimate sponsored links.
- Russian developer extradited for running bank login scam via fake sponsored search ads
- Criminal group stole over 5,000 credentials and caused £14.6 million in confirmed losses
- Scam exploits users' habit of clicking first search result when looking up their bank