U.S. authorities extradited a Russian national accused of running a bank-account takeover scheme that used lookalike bank domains and paid search ads to trick victims into logging in to fake banking sites. The crew allegedly harvested thousands of banking credentials and then attempted large unauthorized transfers from victim accounts.
How the Attack Worked
This scheme relied on a simple but effective combination: lookalike bank domains paired with paid search advertising. Attackers registered spoofed domains resembling real bank websites, then purchased sponsored links so those domains appeared prominently when victims searched for their bank's login page. Victims who clicked the sponsored result landed on a fraudulent login page designed to closely mimic the real bank site.
Once a victim entered their username and password, the fraudulent site reportedly prompted them for additional details, framed as necessary to bypass security controls. This extra step likely helped attackers work around multi-factor authentication or other protections banks had in place. Prosecutors allege the group collected more than 5,000 victim bank login credentials this way, then attempted unauthorized transfers totaling millions of dollars from two banks.
Why It Succeeded
The attack succeeded because it exploited trust in search engines rather than trust in email or phone calls. Employees with online banking access, including finance, accounting, treasury, and executive staff, may not scrutinize a sponsored search result the way they would an unsolicited email. A slightly altered domain name is easy to miss when the page layout and branding look convincing.
What to Watch For
- A bank login page domain that differs slightly from the real, known bank domain
- Arriving at a login page via a sponsored ad rather than a bookmark or typed URL
- Any request for extra information beyond a normal login, especially if framed as required to bypass a security check
Building Resistance
Organizations should train employees with banking access to reach bank portals only through trusted bookmarks or manually typed URLs, treating sponsored search results with skepticism. Staff should learn to verify the exact domain before entering credentials, since lookalike domains are the core of this technique. Finally, any unusual request for additional information during login should trigger a pause and verification through a known, trusted channel rather than immediate compliance.
Key findings
- Attackers allegedly spoofed bank domains and used sponsored links to drive victims to fraudulent login pages.
- The group allegedly collected more than 5,000 victim bank login credentials.
- Victims were prompted for extra information to bypass security controls.
- Prosecutors allege attempted and unauthorized transfers totaling millions of dollars from two banks.
Who’s being targeted
- Commonly targeted roles: Finance, Accounting/AP, Treasury, Executive assistants (who may handle payments), Employees with online banking access.
- Affected industries: Banking, Finance, Businesses with employees who have access to corporate bank accounts.
- Attack channels: website.
- Impersonated: Victim’s bank (via a spoofed banking website).
Red flags to watch for
- Login page domain is slightly different from the real bank domain
- User arrived via a sponsored link/ad rather than a known bookmark or typed URL
- Site asks for “additional details” beyond normal login to bypass security controls
Frequently asked questions
How did attackers get victims to fake bank login pages?
They allegedly registered spoofed domains that resembled real bank websites and purchased sponsored search links so the fake pages appeared near the top of search results.
What happened after credentials were stolen?
Prosecutors allege the group collected more than 5,000 victim bank login credentials and then attempted large unauthorized transfers totaling millions of dollars from two banks.
Why did victims give up more than just their password?
The fraudulent sites reportedly prompted victims for additional details, framed as needed to bypass security controls, which helped attackers get past extra authentication steps.
How can employees avoid this type of attack?
Access bank portals only through trusted bookmarks or typed URLs, be cautious of sponsored search results, and verify the exact domain before entering any login credentials.
Read the video transcript
You Google your bank, click the top result, log in… and someone else just got your banking password. That’s the scam U.S. prosecutors just described: spoofed bank domains plus paid search ads, harvesting thousands of real bank logins and trying to move millions out. The trap: you arrive from a sponsored link, the domain is just a little off, and the site suddenly wants extra details to 'get past security', that’s how they bypass protections. One move: never reach your bank through ads. Use a bookmark or type the exact address, and if a site asks for unusual extra info, close it and start over from your trusted link.