express gazette logo
The Express Gazette
Sunday, September 20, 2026

Scammers Use Fake Google Ads to Steal Bank Logins, DOJ Says

Federal prosecutors allege criminals bought sponsored search ads that mimic legitimate banks, leading users to fraudulent login pages and costing victims millions.

US Politics 2 hours ago
Scammers Use Fake Google Ads to Steal Bank Logins, DOJ Says

Federal investigators have uncovered a scheme where scammers purchased sponsored Google ads designed to impersonate banks, tricking users into revealing their login credentials and draining their accounts. The Justice Department announced on September 8 that a Russian web developer accused of aiding this operation has been extradited to the United States.

Prosecutors allege that the group operated by buying sponsored search engine links that appeared when users searched for their bank. These ads directed customers to fake login pages. Once victims entered their usernames and passwords, the attackers captured the information, which they then used to access real bank accounts, check balances, and initiate unauthorized wire transfers.

This tactic, referred to as "SEO poisoning" by the FBI, exploits the common practice of clicking on the first search result that appears to be legitimate. The FBI warns that these fraudulent ads can lead to URLs that closely resemble the real bank addresses. In a previous announcement concerning the same operation in December 2025, investigators specifically noted that the criminal group delivered fraudulent advertisements through search engines including Google and Bing.

The earlier investigation reported approximately $28 million in attempted losses and about $14.6 million in actual losses tied to at least 19 victims across the United States by December 2025. The indictment against Sergei Anatolyevich Filimonov, 36, alleges he developed and maintained infrastructure for the operation, including databases storing over 5,000 stolen login credentials and software for capturing sensitive data.

Since January 2025, the FBI's Internet Crime Complaint Center has received more than 5,100 complaints related to account takeover fraud, with reported losses exceeding $262 million. Criminals employ various methods to gain account access, including phishing sites accessed via fake search ads and social engineering to obtain one-time passcodes used in multifactor authentication.

To protect against such scams, experts advise users to avoid clicking sponsored search results for banking logins. Instead, they recommend using a bank's official mobile app or a pre-saved bookmark. It is crucial to inspect the web address carefully before entering any sensitive information and to verify the destination of any "sponsored" link. Enabling multifactor authentication is also recommended, though users should be aware that it may not protect them if they inadvertently submit credentials on a fake login page.

Other protective measures include using a password manager, which can flag unfamiliar login pages, installing strong antivirus software, and setting up financial account alerts for unusual activity. In the event that login information is compromised, contacting the financial institution immediately and changing passwords across all affected accounts is advised. Reporting fraudulent wire transfers to IC3.gov can also improve the chances of recovery.


Sources