More than 5,000 victim login credentials: that is the number prosecutors say an alleged transnational crew collected in a bank-account takeover operation that U.S. authorities say resulted in multi‑million‑dollar attempted transfers and confirmed losses.
The arrest, extradition and charges
Authorities extradited a 36‑year‑old Russian national, Sergei Anatolyevich Filimonov, from the Republic of Georgia and charged him in the Northern District of Georgia, the Justice Department said. Filimonov is accused, along with unnamed co‑conspirators, of running an extensive operation beginning in November 2023 to spoof bank domains, harvest customer credentials and use those credentials to steal money from accounts with large balances.
Federal prosecutors charged Filimonov with conspiracy to commit bank and wire fraud, access device fraud conspiracy, multiple counts of bank and wire fraud, possession of unauthorized access devices and aggravated identity theft. He pleaded not guilty on Sept. 4 and remains detained in the Northern District of Georgia. If convicted on all counts he faces up to 175 years in prison, the indictment states.
Spoofed domains, sponsored links and credential storage
According to court records cited by prosecutors, Filimonov and co‑conspirators registered and maintained spoofed domains that imitated legitimate banks. They allegedly purchased sponsored links that directed unsuspecting customers to those fraudulent pages and harvested the credentials entered there. The indictment also says the group built infrastructure to store harvested credentials and trick victims into providing additional details to bypass security controls.
The documents identify a methodical effort to convert credential theft into account access, rather than a single opportunistic phishing incident: spoofed bank sites to capture logins, sponsored links to channel victims, data repositories to collect credentials, and active social‑engineering steps to defeat secondary protections.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleFinancial toll: targeted transfers, attempted losses and confirmed losses
Prosecutors say the alleged crew caused and attempted specific large transfers: nearly $5.58 million from one unnamed bank in June 2024 and $735,000 from another bank in November 2024. Both banks have local branches in the Northern District of Georgia and maintain headquarters in North Carolina, according to the indictment.
Officials previously seized a domain the co‑conspirators allegedly used to store credentials in December 2025. At that time, the FBI reported identifying at least 19 U.S. victims linked to the domain and placed total attempted losses at about $28 million, including confirmed losses of about $14.6 million.
Geographic and corporate links cited in the indictment
The indictment states the alleged operation collected credentials that included those assigned to employees with access to a company headquartered in Atlanta and another business with offices in Cumming, Ga. Prosecutors tie the targeted banks to the Northern District of Georgia by noting both institutions maintain local branches there while their headquarters are in North Carolina.
Those geographic details underscore the cross‑jurisdictional footprint prosecutors attribute to the scheme: international actors allegedly targeting U.S. customers and companies, with transfers routed through banks that operate in multiple states.
What this means for banks, security teams, and customers
- Banks and financial institutions: the indictment’s emphasis on spoofed domains, sponsored links and credential repositories highlights the kind of coordinated abuse banks will watch for when investigating large, unusual transfers tied to credential theft.
- Security teams and technologists: the case centers on infrastructure used to harvest and store thousands of credentials and on steps to defeat security controls, signaling the need to monitor for fraudulent domains and for channels converting phishing into account access.
- Employees and retail customers: prosecutors say credentials tied to employees at an Atlanta‑headquartered company and at a business in Cumming were among those collected, illustrating how both consumer and corporate accounts were targeted and why account holders should be alert to deceptive bank domains and sponsored search results.
The federal case now proceeds in the Northern District of Georgia with Filimonov detained after a Sept. 4 not‑guilty plea; prosecutors portray an operation that began in November 2023, amassed more than 5,000 credentials, and produced both targeted attempted transfers and broader attempted losses measured in the tens of millions. How prosecutors trace the alleged co‑conspirators and whether additional victims or defendants emerge will be among the concrete next steps set by the indictment and the criminal process.




