By MFJ Staff | Sources: DOJ Office of Public Affairs, USAO Northern District of Georgia, and PYMNTS
Key takeaway: Extraditions show law enforcement can reach phishing operations abroad, but lookalike domains bought into paid search results keep working until merchants and banks actively monitor for spoofed brand mentions in ad placements.
A Russian web developer has been extradited to the US on charges tied to a bank account takeover fraud scheme that allegedly harvested more than 5,000 stolen banking credentials, as the FBI reports over $262 million in account takeover losses since January 2025.
Sergei Anatolyevich Filimonov, 36, was extradited from the Republic of Georgia and arraigned September 4 in the Northern District of Georgia, the Justice Department announced, on an indictment a federal grand jury returned in November 2025.
Prosecutors say Filimonov built spoofed domains mimicking legitimate financial institutions and bought sponsored search placements to route online banking customers to fraudulent login pages, storing more than 5,000 compromised credentials on his backend infrastructure. He faces conspiracy and substantive counts of bank fraud, wire fraud, access-device fraud, and aggravated identity theft, carrying a mandatory minimum of two years and a maximum of 175 years if convicted on all counts. PYMNTS, citing court filings, reports the scheme is tied to roughly $14.6 million stolen from at least 19 victims, including two companies.
“This investigation and indictment underscore our commitment to disrupting large-scale cyber theft,” said Theodore S. Hertzberg, US Attorney for the Northern District of Georgia. FBI Atlanta Special Agent in Charge Marlo Graham added that Filimonov “allegedly used spoofed domains and fraudulent login pages to target unsuspecting online banking customers, stealing millions from victims,” crediting the case to partnerships with Estonian and Georgian law enforcement.
Why it matters: The spoofed-domain-plus-paid-search playbook used here targets bank logins today, but it’s the same template phishing kits use against merchant checkout and account pages. The FBI’s Internet Crime Complaint Center has logged over 5,100 account takeover complaints and $262 million-plus in reported losses since January 2025 alone.
Sources: justice.gov — DOJ Office of Public Affairs; justice.gov — USAO Northern District of Georgia; PYMNTS












