The U.S. Department of Justice announced the seizure of the domain web3adspanels[.]org, which was used as a backend control panel for a sophisticated bank account takeover fraud operation targeting Americans. The criminal group behind the scheme purchased fraudulent advertisements on major search engines such as Google and Bing, which closely mimicked legitimate banking ads. Unsuspecting users who clicked these ads were redirected to counterfeit bank websites, where their login credentials were harvested using malicious code. The attackers then used these credentials to access real bank accounts and steal funds, resulting in at least $14.6 million in confirmed losses and $28 million in attempted thefts from 19 identified victims, including two companies in Georgia.
The seized domain stored thousands of stolen credentials and supported the fraud operation as recently as November 2025. The FBI’s Internet Crime Complaint Center (IC3) has received over 5,100 complaints related to similar bank account takeover schemes since January 2025, with reported losses exceeding $262 million. The takedown of the domain is part of a broader law enforcement effort to disrupt the infrastructure enabling these attacks and prevent further exploitation of stolen credentials.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
On or before December 23, 2025, the U.S. Department of Justice, FBI, and Estonian authorities seized the domain and associated database for web3adspanels.org, which served as a control panel for the bank account takeover scheme. Estonian law enforcement also preserved and collected data from servers hosting the phishing pages.
The seized domain was active as recently as November 2025 and hosted thousands of stolen credentials used in the fraud operation. Its continued operation showed the scheme was still functioning shortly before the takedown.
Investigators linked the operation to at least 19 known victims, including two companies in Georgia, with about $28 million in attempted losses and $14.6 million in confirmed losses. The stolen credentials were stored in a backend system associated with web3adspanels.org.
During 2025, a criminal group used fraudulent advertisements on search engines such as Google and Bing to redirect victims to counterfeit banking websites. Victims' login credentials were harvested and then used to access real bank accounts and steal funds.
Since January 2025, the FBI's Internet Crime Complaint Center has received more than 5,100 complaints tied to similar bank account takeover schemes, with reported losses exceeding $262 million. This broader trend provides context for the web3adspanels.org operation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcethehackernews.com
Open sourcetherecord.media
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.