SEO Poisoning Drained $14.6 Million From Bank Accounts
A Russian web developer has been extradited to the United States over an operation that used SEO poisoning to steal bank logins, and the numbers give a rare look at what this tactic is worth to the people running it. Federal investigators recorded about $14.6 million in confirmed losses and roughly $28 million attempted, from just 19 identified victims.
The method was not sophisticated. The group registered domains that mimicked federally insured banks, then bought sponsored search results so those fake sites appeared when customers searched for their own bank. Victims clicked, typed their credentials into a convincing login page, and the attackers used them to sign in, check balances and initiate wire transfers.

What the Justice Department actually said about the SEO poisoning case
Sergei Anatolyevich Filimonov, 36, was indicted by a federal grand jury on 4 November 2025, extradited from the Republic of Georgia, and appeared before a federal magistrate in Atlanta on 4 September 2026, where he pleaded not guilty. He faces a minimum of two years and a maximum of 175 years if convicted on all counts. He remains in US Marshals custody.
The indictment alleges he built and maintained the infrastructure: databases holding more than 5,000 stolen login credentials, and software designed to capture and transmit authentication data. Prosecutors say the scheme ran from November 2023 through October 2025, which is 23 months of live operation.
An indictment is an allegation. The government still has to prove it.
The ad platforms were named in the earlier action. When the Justice Department seized the group's backend domain, web3adspanels.org, in December 2025, the affidavit stated plainly that the group delivered fraudulent advertisements through search engines including Google and Bing, and that those ads imitated the sponsored search advertisements used by legitimate banking entities.
That domain was still supporting the operation as recently as November 2025.
Why SEO poisoning works better than email phishing
The FBI uses the term SEO poisoning for this in its account takeover guidance, and the reason it works is the part worth understanding.
Ordinary phishing has to interrupt you. An email arrives, a text arrives, and some part of you is suspicious because you did not ask for it.
This inverts that. The victim starts the interaction. They want to check a balance, they search for their bank, and a result appears where results are supposed to appear. Nothing arrived uninvited. The usual warning signal never fires.
Paid placement does the rest. A sponsored result sits above the organic one, which means the fake can outrank the real bank on a search for the real bank's name.
The scale beyond this one case
Since January 2025 the FBI's Internet Crime Complaint Center has received more than 5,100 complaints about bank account takeover fraud, with reported losses above $262 million.
This one SEO poisoning operation, with 19 identified victims, accounts for about 5.6% of that figure on confirmed losses alone. Which tells you both that the case is significant and that it is one of many.
What this means if you buy ads
Most coverage of this story is written for bank customers. There is a second audience, and it is anyone who buys advertising.
Verification is going to get heavier, and this is why. Every SEO poisoning enforcement action pushes platforms to demand more proof of who an advertiser is. Advertiser identity verification, business documentation and domain ownership checks all exist because of cases like this one. Expect more of it, not less, particularly in finance.
Finance is the vertical under the most scrutiny. If you run finance offers, you are advertising in the same category as the people this case is about. That is not fair, but it is the environment. Landing page review in finance is stricter than anywhere else, and the reason is sitting in an Atlanta courtroom.
Domain age and reputation matter more than advertisers think. SEO poisoning depends on freshly registered lookalike domains. Platforms know that, so a new domain in a sensitive vertical starts from a position of suspicion. If you are launching a finance offer on a domain registered last week, expect friction that has nothing to do with your intentions.
Impersonation is the line that ends accounts permanently. Policy breaches around claims or disclosures usually produce a rejection or a suspension you can appeal. Impersonating another business is treated differently by every platform, and reasonably so given what is in this indictment.
For the advertiser being impersonated
If you are a brand rather than a buyer, the practical step is monitoring. Search your own brand name, including common misspellings, and look at who is bidding on it. Platforms have brand protection and trademark complaint routes, but they are reactive, so somebody has to notice first.
The Justice Department also credited Estonian law enforcement with preserving data from the servers hosting the phishing pages, and Georgian authorities with the apprehension. These cases take years and cross several jurisdictions. Waiting for enforcement is not a strategy.
Agency ad accounts, without the wait.
Buy and top up Google, Meta, native, and more from one dashboard.
Get started
No comments yet. Be the first to comment.
Comments are open to registered AdScaleLab clients.
Sign in to comment