Russian national and web developer Sergei Anatolyevich Filimonov, 36, was extradited from the Republic of Georgia to the United States on allegations that he helped operate a bank-account takeover and wire-fraud scheme. Prosecutors allege that from November 2023 through October 2025, Filimonov and co-conspirators purchased sponsored-search advertisements, impersonated bank domains, and deployed fraudulent banking login pages to steal customer credentials and facilitate unauthorized wire transfers.
The alleged operation maintained infrastructure to retain stolen credentials and gather information used to bypass bank security controls. U.S. authorities linked a December 2025 seizure of web3adspanels.org and its stolen-password database to at least 19 U.S. victims, about $28 million in attempted losses, and roughly $14.6 million in confirmed losses; alleged transfers involving two banks in June and November 2024 totaled nearly $6.315 million. Filimonov pleaded not guilty in the Northern District of Georgia on September 4 and remains in custody.

See the reporting duties and controls this puts on the clock.
7 events from the most recent confirmed update back to the earliest known activity.
Filimonov pleaded not guilty in federal court in Atlanta and remained detained in the Northern District of Georgia.
U.S. authorities seized web3adspanels.org, a domain allegedly used to store credentials harvested through spoofed banking sites. Authorities said it contained credentials for thousands of victims; the FBI linked it to at least 19 U.S. victims, roughly $28 million in attempted losses, and about $14.6 million in confirmed losses.
A federal grand jury indicted Filimonov on charges including conspiracy to commit bank and wire fraud, access-device-fraud conspiracy, bank fraud, wire fraud, access-device fraud, and aggravated identity theft.
Prosecutors allege the group caused or attempted an unauthorized transfer of $735,000 from another unnamed bank.
Prosecutors allege the group caused or attempted an unauthorized transfer of nearly $5.58 million from an unnamed bank.
Prosecutors allege that Sergei Anatolyevich Filimonov and co-conspirators began using spoofed banking domains, sponsored search advertisements, and fraudulent login pages to steal online-banking credentials. The group allegedly built infrastructure to retain credentials and obtain information to bypass bank security controls.
U.S. authorities extradited the 36-year-old Russian web developer from the Republic of Georgia to face charges over the alleged bank-account takeover and wire-fraud scheme.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See what this changes for your reporting obligations and which controls it puts on the clock.
8 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcedatabreaches.net
Open sourcedecipher.sc
Open sourcecyberscoop.com
Open sourcetherecord.media
Open sourcejustice.gov
Open sourcejustice.gov
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.