Spoofed Bank Domains Used for Account Takeovers

CyberScoop · Medium sophistication
Last updated September 9, 2026

U.S. authorities extradited a Russian national accused of running a bank-account takeover scheme that used lookalike bank domains and paid search ads to trick victims into logging in to fake banking sites. The crew allegedly harvested thousands of banking credentials and then attempted large unauthorized transfers from victim accounts.

How the Attack Worked

This scheme relied on a simple but effective combination: lookalike bank domains paired with paid search advertising. Attackers registered spoofed domains resembling real bank websites, then purchased sponsored links so those domains appeared prominently when victims searched for their bank's login page. Victims who clicked the sponsored result landed on a fraudulent login page designed to closely mimic the real bank site.

Once a victim entered their username and password, the fraudulent site reportedly prompted them for additional details, framed as necessary to bypass security controls. This extra step likely helped attackers work around multi-factor authentication or other protections banks had in place. Prosecutors allege the group collected more than 5,000 victim bank login credentials this way, then attempted unauthorized transfers totaling millions of dollars from two banks.

Why It Succeeded

The attack succeeded because it exploited trust in search engines rather than trust in email or phone calls. Employees with online banking access, including finance, accounting, treasury, and executive staff, may not scrutinize a sponsored search result the way they would an unsolicited email. A slightly altered domain name is easy to miss when the page layout and branding look convincing.

What to Watch For

  • A bank login page domain that differs slightly from the real, known bank domain
  • Arriving at a login page via a sponsored ad rather than a bookmark or typed URL
  • Any request for extra information beyond a normal login, especially if framed as required to bypass a security check

Building Resistance

Organizations should train employees with banking access to reach bank portals only through trusted bookmarks or manually typed URLs, treating sponsored search results with skepticism. Staff should learn to verify the exact domain before entering credentials, since lookalike domains are the core of this technique. Finally, any unusual request for additional information during login should trigger a pause and verification through a known, trusted channel rather than immediate compliance.

Key findings

  • Attackers allegedly spoofed bank domains and used sponsored links to drive victims to fraudulent login pages.
  • The group allegedly collected more than 5,000 victim bank login credentials.
  • Victims were prompted for extra information to bypass security controls.
  • Prosecutors allege attempted and unauthorized transfers totaling millions of dollars from two banks.

Who’s being targeted

  • Commonly targeted roles: Finance, Accounting/AP, Treasury, Executive assistants (who may handle payments), Employees with online banking access.
  • Affected industries: Banking, Finance, Businesses with employees who have access to corporate bank accounts.
  • Attack channels: website.
  • Impersonated: Victim’s bank (via a spoofed banking website).

Red flags to watch for

  • Login page domain is slightly different from the real bank domain
  • User arrived via a sponsored link/ad rather than a known bookmark or typed URL
  • Site asks for “additional details” beyond normal login to bypass security controls
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers get victims to fake bank login pages?

They allegedly registered spoofed domains that resembled real bank websites and purchased sponsored search links so the fake pages appeared near the top of search results.

What happened after credentials were stolen?

Prosecutors allege the group collected more than 5,000 victim bank login credentials and then attempted large unauthorized transfers totaling millions of dollars from two banks.

Why did victims give up more than just their password?

The fraudulent sites reportedly prompted victims for additional details, framed as needed to bypass security controls, which helped attackers get past extra authentication steps.

How can employees avoid this type of attack?

Access bank portals only through trusted bookmarks or typed URLs, be cautious of sponsored search results, and verify the exact domain before entering any login credentials.

Read the video transcript

You Google your bank, click the top result, log in… and someone else just got your banking password. That’s the scam U.S. prosecutors just described: spoofed bank domains plus paid search ads, harvesting thousands of real bank logins and trying to move millions out. The trap: you arrive from a sponsored link, the domain is just a little off, and the site suddenly wants extra details to 'get past security', that’s how they bypass protections. One move: never reach your bank through ads. Use a bookmark or type the exact address, and if a site asks for unusual extra info, close it and start over from your trusted link.

Similar attacks

Cybercrime as a Service Fuels New Scam Waves

Cybercrime as a Service Fuels New Scam Waves

A threat landscape report describes how criminals now buy or rent phishing, fraud, malware, and hidden infrastructure “as a service,” making scams faster to launch and harder to stop. The article highlights practical, repeatable social-engineering workflows such as fake CAPTCHA pages that trick…

July 31, 2026
BigBear 2.0 PhaaS Steals 5,100+ M365 Logins

BigBear 2.0 PhaaS Steals 5,100+ M365 Logins

Researchers say the “BigBear 2.0” phishing-as-a-service operation stole over 5,100 Microsoft 365 credential records across 461 organizations by capturing passwords and session cookies. The campaign used an adversary-in-the-middle setup to bypass MFA and maintain access, with stolen data sent to…

September 8, 2026
Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026
Russian Clusters Hijack Accounts via OAuth & WhatsApp

Russian Clusters Hijack Accounts via OAuth & WhatsApp

Google says multiple suspected Russia-linked espionage clusters targeted academics, government, and defense-related personnel by abusing legitimate sign-in features instead of using obvious fake login pages. The campaigns used realistic lures (file sharing, conference invites, and “secure WhatsApp”…

August 20, 2026
Real-Time Smishing Tool Steals 2FA Codes Live

Real-Time Smishing Tool Steals 2FA Codes Live

Cisco Talos reported a real-time phishing framework called “JWR” that guides victims through fake checkout and login pages while attackers watch keystrokes live. It is being delivered through SMS messages that impersonate toll and postal authorities, and it can capture payment details, identity…

August 13, 2026
Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026