DOJ Extradites Russian Web Developer in $15 Million Bank Account Takeover Scheme

Department of Justice

A Russian national who was allegedly involved in large-scale bank account takeover activity was arraignedFriday (Sept. 4) in the Northern District of Georgia after being extradited from the Republic of Georgia, the U.S. Justice Department said in a Monday (Sept. 8) press release.

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    Subscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    Sergei Anatolyevich Filimonov, 36, is a web developer who was indicted by a federal grand jury in November 2025 for charges relating to a credential-harvesting and bank-fraud operation that targeted victims in the United States, according to the release.

    Citing court documents, the Justice Department said in the release that Filimonov and his co-conspirators created spoofed domains that mimicked the websites of federally insured financial institutions, purchased sponsored search-engine links to divert unsuspecting bank customers to those domains, stole victims’ credentials when the victims entered them in fraudulent login pages, and then used the stolen credentials to access bank accounts and initiate unauthorized wire transfers to steal the accounts’ funds.

    We’d love to be your preferred source for news.

    Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!

    The indictment also alleges that Filimonov developed and maintained online infrastructure supporting the operation, and that he and his co-conspirators attempted to steal millions of dollars from victim accounts, according to the release.

    Filimonov faces multiple charges and, if convicted, faces a penalty of between two years and 175 years in prison, per the release.

    The Justice Department in December 2025 seized a domain that operated as a back-end server storing thousands of stolen credentials harvested from fraudulent banking sites, according to the release.

    When announcing that move in a December press release, the Justice Department said the fraud ring that operated the web domain and database had compromised the bank accounts of at least 19 victims, including two companies, and had stolen about $14.6 million.

    The FBI’s Internet Crime Complaint Center (IC3) said in November 2025 that it had received more than 5,100 reports of account takeover fraud since January 2025 and that these reports included losses totaling over $262 million.

    In account takeover fraud, cybercriminals impersonate a financial institution’s support staff or website to trick victims into giving them information that enables the criminals to access and take over online financial institution, payroll or health savings accounts, IC3 said.