Scammers are buying Google ads to steal bank logins

You need to check your bank account, so you open Google, type in your bank’s name and click the first result that looks right. Most of us have done some version of that without thinking twice.

Now federal investigators say criminals turned that everyday habit into a way to steal bank logins and drain accounts. The Justice Department announced on Sept. 8 that a Russian web developer accused of helping run a large bank account takeover operation had been extradited to the United States. Prosecutors say the group bought sponsored search engine links that sent banking customers to fake login pages. Victims then entered their credentials, believing they had reached their bank.

That should get the attention of anyone who banks online. Here’s how the scam works, why those sponsored results can look so convincing and what you can do to avoid handing your bank login to a criminal.

ASKED SIRI TO CALL YOUR BANK? A SCAM COULD COST THOUSANDS

NEW! 🩺 Free CyberGuy LIVE class: Get Better Healthcare With AI Saturday, September 26 at 11 a.m. ET / 8 a.m. PT

Kurt “CyberGuy” Knutsson will show you five practical ways AI can help you organize your health history, remember important appointment details, understand complicated medical information, research prescriptions and prepare smarter questions for your doctor. No technical experience is needed.

Save your free spot at CyberGuyLive.com

According to federal prosecutors, the alleged operation used spoofed domains that mimicked websites belonging to federally insured financial institutions. The conspirators then bought sponsored search engine links. Those links could appear when someone searched for their bank.

A click sent the customer to a fraudulent login page. Once victims entered their credentials, the attackers could capture that information. Prosecutors say the group then used the stolen credentials to access real bank accounts, check balances and initiate unauthorized wire transfers.

The indictment also alleges that Sergei Anatolyevich Filimonov developed and maintained infrastructure supporting the operation. That included databases storing more than 5,000 stolen login credentials and software designed to capture sensitive authentication data.

The newest Sept. 8 Justice Department announcement says the conspirators purchased sponsored search-engine links. It does not name a particular search engine. However, the DOJ previously described the same bank account takeover operation when it seized the group’s backend domain in December 2025. In that announcement, investigators specifically said the criminal group delivered fraudulent advertisements through search engines including Google and Bing. The ads imitated sponsored search ads used by legitimate banks.

Victims who clicked those ads were redirected to fake banking websites controlled by the criminals, according to the DOJ. That earlier investigation had identified at least 19 victims across the United States by December 2025. The DOJ reported approximately $28 million in attempted losses and about $14.6 million in actual losses tied to those victims.

Microsoft told CyberGuy that it has policies and detection mechanisms designed to help prevent misleading advertising. The company said that when it becomes aware of ads that violate its policies, it takes action to remove them and uses what it learns to strengthen its detection capabilities. Microsoft also encourages users to report suspicious ads through its “Report a Concern” form. We also reached out to Google for comment but did not hear back before our deadline.

FAKE PATIENT PORTAL SCAM CAN STEAL YOUR LOGIN AND INFECT YOUR PC

The trap works because a paid search result can appear in a place many of us naturally look first. You search for your bank. A result appears near the top. The wording looks familiar, so you click before studying the address. Most search ads are legitimate.

Still, the FBI warns that criminals can buy ads that imitate real businesses and direct users to convincing phishing sites. The FBI refers to this tactic as SEO poisoning in its account takeover guidance. That changes how I would approach something as sensitive as online banking. In fact, the FBI specifically recommends using bookmarks or favorites to reach login pages rather than clicking search results or advertisements.

This problem stretches far beyond one alleged criminal operation. Since January 2025, the FBI’s Internet Crime Complaint Center has received more than 5,100 complaints reporting account takeover fraud. Reported losses have exceeded $262 million.

Criminals use several ways to get inside accounts. Fraudulent banking websites remain one of them. The FBI says victims can encounter a phishing site after clicking a fake search advertisement. Attackers may also try to obtain a one-time passcode if an account uses multifactor authentication.

Once criminals gain access, they may move money to accounts they control. That can make recovery difficult, especially when funds move quickly.

The latest development centers on Sergei Anatolyevich Filimonov, 36, a Russian national and web developer. A federal grand jury indicted Filimonov on Nov. 4, 2025. Authorities later extradited him from the Republic of Georgia.

You do not need to stop banking online. However, changing how you reach your bank’s login page can lower your risk.

SHOULD YOU USE A SEPARATE COMPUTER FOR ONLINE BANKING?

If you already have your bank’s verified app installed, open it directly rather than searching for your bank in a browser. That removes the search-result step where this particular scam tries to catch you.

Visit your bank’s verified website and save it as a bookmark or favorite. The FBI specifically recommends bookmarks or favorites for financial login pages instead of relying on search results or advertisements.

Take a second to inspect the domain before you enter banking credentials. A fake site may use a misspelled address or another small change designed to look legitimate. The FBI warns that fraudulent search ads can lead to URLs that closely resemble the real address. Microsoft also advises users to carefully review website URLs before entering credentials or other personal information online.

A “Sponsored” label means someone paid to place the advertisement. So when money or sensitive information is involved, verify the destination yourself before you sign in.

Enable two-factor or multifactor authentication if your financial institution offers it. However, do not let that give you a false sense of security. The FBI warns that MFA may not protect you after you land on a fraudulent login page. Criminals can also use social engineering to try to obtain your one-time code. Never give a one-time passcode to someone who contacts you unexpectedly.

YOUR BANK MAY STOP TEXTING YOU SIX-DIGIT CODES

A trusted password manager can help because it associates your saved login with a particular website. If your password manager normally fills your banking credentials but suddenly does not, stop before typing them manually. Check the address first. We’ve previously explained how password managers can provide another clue when you land on a spoofed login page.

Strong antivirus software can add another layer of protection if you click a malicious search result. It may warn you about known phishing sites, block dangerous downloads and stop other threats before they reach your device. However, no security software can protect you if you willingly enter your banking credentials on a convincing fake site, so always check the web address first. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com

Set up alerts for activity such as withdrawals and new logins if your bank offers them. Then review unexpected activity immediately. The FBI recommends regularly monitoring financial accounts for unauthorized transactions.

Identity theft protection can help monitor for signs that your personal information is being misused. Some services can alert you to suspicious activity involving your credit, financial accounts or personal information and provide recovery assistance if fraud occurs. This will not stop a fake bank ad, but it can give you another way to spot trouble after your information has been exposed. See my tips and best picks on Best Identity Theft Protection at Cyberguy.com

If you think you entered your credentials on a fake banking page, contact your financial institution immediately using a number you trust. Then reset the exposed credentials. If you reused the same password on another account, change it there as well. The FBI also recommends reporting fraudulent wire transfers to the Internet Crime Complaint Center at IC3.gov. Acting quickly may improve the chances of stopping or reversing a transfer.

What gets me about this scam is how normal the first step feels. You want to check your balance, so you search for your bank and choose a result that appears legitimate. There may be no strange email waiting in your inbox. You did not respond to an unexpected text. You started the search yourself. That can make the trap much harder to recognize. For banking, I would skip search results altogether. Use your bank’s official app or a bookmark you have already verified. Then take a moment to look at the address before entering anything sensitive. A few extra seconds can be a lot easier than trying to recover money after it has left your account.

Have you ever clicked a sponsored search result because you assumed Google had already verified the company behind it? Would this warning change how you log in to your bank? Let us know by writing to us at CyberGuy.com

Sign up for my FREE CyberGuy Report

Copyright 2026 CyberGuy.com. All rights reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Post