Skip to content
July 24, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Cybercriminals
  • Search Engine “Malvertising” Ring Disrupted: DOJ Seizes Backend of $14.6 Million Bank Fraud Scheme
  • Cybercriminals

Search Engine “Malvertising” Ring Disrupted: DOJ Seizes Backend of $14.6 Million Bank Fraud Scheme

Do Son December 24, 2025 3 minutes read
0
Malvertising ATO
Add Daily CyberSecurity as a preferred source on Google

A sprawling cybercrime operation that weaponized trusted search engines to drain millions from American bank accounts has been dismantled by federal authorities. The Department of Justice (DOJ) announced the seizure of a critical command-and-control domain used to harvest and manage thousands of stolen banking credentials.

The operation targets a sophisticated “account takeover” scheme that leveraged the trust users place in platforms like Google and Bing to intercept sensitive financial data.

Unlike traditional phishing attacks that arrive via email, this group brought the trap directly to the victim’s search results. According to court documents, the criminals purchased advertising space on major search engines to display fake ads that mimicked legitimate banking portals.

“The criminal group perpetrating the bank account takeover fraud delivered fraudulent advertisements through search engines, including Google and Bing,” the press release states.

When users searched for their bank and clicked on what appeared to be a “sponsored” link to their financial institution, they were quietly redirected to high-fidelity replica sites. Once the victim entered their username and password, the trap was sprung.

“The criminals harvested those credentials through a malicious software program embedded in the fake website,” the DOJ explained. “The criminals then used those bank credentials on the corresponding legitimate bank websites to access victims’ bank accounts and drain their funds.”

The seizure focused on web3adspanels.org, a domain that served as the operational backbone for the fraudsters.

“The domain, web3adspanels.org, was used by those involved in the scheme as a backend web panel to store and manipulate illegally harvested bank login credentials,” the announcement clarified.

This backend interface allowed the attackers to organize their loot—thousands of stolen login sets—and systematically empty accounts. The scale of the theft was massive. The FBI identified at least 19 specific victims, including two companies in Georgia, resulting in “attempted losses of approximately $28 million dollars and actual losses of approximately $14.6 million dollars.”

Crucially, this was an active threat. “Based on the FBI’s investigation, the seized domain continued to host a backend server used in furtherance of the bank account takeover fraud as recently as November 2025.”

This seizure comes amidst a historic surge in account takeover (ATO) fraud. The FBI’s Internet Crime Complaint Center (IC3) has been inundated with reports, signaling a shift in cybercriminal tactics toward direct financial manipulation.

“Since January 2025, the FBI Internet Crime Complaint Center (IC3) received more than 5,100 complaints reporting bank account takeover fraud, with reported losses exceeding $262 million.”

To defend against these “malvertising” threats, the DOJ offers simple but effective advice: stop clicking ads to log in. The public is encouraged to use “‘Bookmarks’ or ‘Favorites’ for navigating to login websites” rather than relying on search engine results, which can be easily spoofed by the highest bidder.

Related Posts:

  • HTTP Client Tools Weaponized in Account Takeover Attacks
  • Atos Responds to Space Bears Ransomware Allegations
  • Microsoft announces that Bing will block cryptocurrency ads
  • Windows 11’s New “Speed Test” Feature: A Gimmick or a Genuine Upgrade?

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.


We respect your inbox. Unsubscribe anytime.

Related coverage

  • Hackers Hijack Industrial Cellular Routers to Launch Widespread Smishing Campaigns Across Europe
  • New RFQ Scams Hit Businesses: Fraudsters Steal Goods via Net Financing & Fake Procurement
  • SaaS-Style Cybercrime: Attackers Weaponize Langflow RCE and NATS Messaging for Ultra-Scalable C2
  • New Offensive OT Framework Targeting Energy Infrastructure Emerges on Dark Web
  • DOJ Dismantles North Korean IT Job Scam: Stolen Identities & Laundering Funded DPRK Weapons
Track all actively exploited CVEs →

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Account Takeover ATO Bing Ads DOJ fbi Financial Crime Google Ads Malvertising Northern District of Georgia Search Engine Fraud web3adspanels.org

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-0770CVSS 9.8
    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2021-27137CVSS 8.1
    An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2026-6875CVSS 9.5
    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability...
    Admin intel📅 Updated: Jul 18, 2026
  • CVE-2026-39808CVSS 9.8
    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox...
    CISA KEV📅 Added to KEV: Jul 16, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-48021CVSS 9.1
    In epa4all, prior to version 2026-05-20, an attacker who can intercept the...
  • CVE-2026-59940CVSS 9.8
    ## Summary A type confusion issue in `seroval.fromJSON()` allowed attacker-controlled JSON input...
  • CVE-2026-58630CVSS 10.0
    Improper access control in Azure App Service allows an unauthorized attacker to...
  • CVE-2026-57106CVSS 10.0
    Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to...
  • CVE-2026-56163CVSS 10.0
    Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an...
  • CVE-2026-15704CVSS 9.8
    In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled...
  • CVE-2026-62825CVSS 10.0
    Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate...
  • CVE-2026-58275CVSS 10.0
    Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges...
  • CVE-2026-56191CVSS 10.0
    Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform...
  • CVE-2026-56165CVSS 9.8
    Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.