Russian National Extradited to United States for Bank Account Takeover Fraud Scheme Causing Millions of Dollars in Losses


Sergei Anatolyevich Filimonov, 36, a Russian national and web developer who was allegedly involved in a transnational cyber‑fraud conspiracy responsible for large‑scale bank account takeover activity, was arraigned Friday in the Northern District of Georgia after being extradited from the Republic of Georgia. Filimonov was indicted by a federal grand jury on Nov. 4, 2025, for charges relating to a credential‑harvesting and bank‑fraud operation that targeted victims across the United States.

According to court documents, Filimonov and his co‑conspirators executed a sophisticated scheme involving spoofed domains that mimicked the websites of federally insured financial institutions. The conspirators purchased sponsored search‑engine links to divert unsuspecting banking customers to fraudulent login pages, where victims entered their credentials. The conspirators used the stolen credentials to access bank accounts, review account balances, and initiate unauthorized wire transfers to steal bank account funds.

Read more…
Source:  U.S. Department of Justice


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Biden warns of US ‘cyber’ response after Ukraine says computers wiped during attack

    January 20, 2022

    US President Joe Biden responded forcefully to reports of a wide-ranging cyberattack on Ukrainian government systems Wednesday afternoon, telling reporters that the US would respond with its own cyberattacks if Russia continues to target Ukraine’s digital infrastructure. “The question is if it’s something significantly short of an…invasion or major military forces coming across,” Biden said in ...

  • Biden signs cybersecurity memorandum for Defense Department, intelligence agencies

    January 19, 2022

    US President Joe Biden signed a memorandum on Tuesday concerning the cybersecurity of the Defense Department and the country’s intelligence agencies, sketching out exactly how an executive order he signed in May 2021 will be implemented. “This NSM requires that, at minimum, National Security Systems employ the same network cybersecurity measures as those required of federal ...

  • Former DHS official charged with stealing govt employees’ PII

    January 14, 2022

    A former Department of Homeland Security acting inspector general pleaded guilty today to stealing confidential and proprietary software and sensitive databases from the US government containing employees’ personal identifying information (PII). 61-year-old Charles Kumar Edwards coordinated the scheme while working for DHS-OIG (Department of Homeland Security, Office of Inspector General) as an employee and acting IG ...

  • Cyberattack shuts down Albuquerque schools; county copes with ransomware incident

    January 13, 2022

    School officials in Albuquerque, New Mexico have cancelled classes for Thursday and Friday due to a cyberattack. The shutdown took place just days after a ransomware attack hit government services across Bernalillo County. In a statement posted to the Albuquerque Public Schools (APS) website, officials said schools will remain closed “as the district continues to investigate ...

  • Iranian intel cyber suite of malware uses open source tools

    January 12, 2022

    FORT MEADE, Md. – To better enable defense against malicious cyber actors, U.S. Cyber Command’s Cyber National Mission Force has identified and disclosed multiple open-source tools that Iranian intelligence actors are using in networks around the world. These actors, known as MuddyWater in industry, are part of groups conducting Iranian intelligence activities, and have been seen ...

  • Maryland officials confirm ransomware attack shut down Department of Health

    January 12, 2022

    Maryland officials confirmed on Wednesday that state’s Department of Health is dealing with a devastating ransomware attack, which has left hospitals struggling amid a surge of COVID-19 cases. In a statement released on Wednesday, Maryland Chief Information Security Officer Chip Stewart said the attack began on December 4 and crippled their systems. “We have paid no extortion ...