ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Cybercrime

FBI Seizes ‘Web Panel’ Behind $14.6 Million Bank Account Takeover Scheme

Paul by Paul
December 27, 2025
in Cybercrime
Reading Time: 3 mins read
web3adspanels
Share on FacebookShare on Twitter

Authorities shut down web3adspanels.org, a backend database that stored thousands of stolen U.S. bank credentials harvested through fake search engine ads.

You might also like

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Tennessee Man Pleads Guilty to Posting Stolen SCOTUS Docs on Instagram

Dutch Police Arrest Alleged AVCheck Operator in ‘Operation Endgame’ Breakthrough

Federal authorities have seized the domain web3adspanels.org, disrupting a massive cybercrime infrastructure used to steal millions from American bank accounts. According to the Department of Justice, the site functioned as a “web panel”—a backend control center where criminals stored and managed thousands of stolen login credentials.

The seizure, announced in late December 2025, halts an operation that successfully stole at least $14.6 million from U.S. victims and attempted to transfer nearly $28 million in total.

Key Facts at a Glance

  • Domain Seized: web3adspanels.org
  • The Scam: Criminals used fake search ads to mimic banks, leading victims to phishing sites.
  • Financial Impact: $14.6 million stolen; $28 million attempted.
  • Victims: At least 19 identified U.S. victims, including businesses, though the database held credentials for thousands more.
  • International Aid: Estonian law enforcement helped preserve server data to aid the investigation.

How the Phishing Scam Worked

The fraudsters relied on a technique known as “search engine phishing.” The group purchased advertisements on major search engines like Google and Bing, designing them to look exactly like legitimate customer support or login links for major financial institutions.

When users searched for their bank and clicked these sponsored ads, they were redirected to look-alike phishing websites. Once the victims entered their usernames and passwords, the site secretly captured the data. The criminals then used these stolen credentials to perform Account Takeovers (ATO), logging into the real banking portals to initiate wire transfers and drain funds into cryptocurrency wallets.

The Role of the Seized Domain

While the phishing sites collected the data, web3adspanels.org served as the central storage locker. Investigators discovered that the domain hosted a database containing thousands of stolen login sets. Criminals accessed this panel to view victims’ passwords and coordinate the theft of funds.

The infrastructure remained active as recently as November 2025. Visitors to the site now see a seizure banner indicating that the domain is under the control of the FBI and the U.S. Attorney’s Office for the Northern District of Georgia.

A Surge in Banking Fraud

This takedown occurs during a record-breaking year for digital banking fraud. The FBI’s Internet Crime Complaint Center (IC3) reports that since January 2025, there have been over 5,100 complaints regarding account takeovers, with total losses exceeding $262 million.

This operation highlights a specific trend where scammers impersonate bank support teams or use “spoofed” search results to bypass security measures like Multi-Factor Authentication (MFA).

How to Protect Yourself

Law enforcement warns that search engine results are no longer a safe way to find your bank’s login page. To avoid falling victim to similar schemes:

  • Stop Clicking Ads: Deeply verify “Sponsored” links in search results before clicking. Or use AdBlock!
  • Use Bookmarks: Only access your bank via a saved bookmark or by typing the URL directly into your browser.
  • Enable Alerts: Set up transaction alerts to notify you immediately of suspicious activity.
  • Report Fraud: If you suspect your account has been compromised, contact your bank immediately and file a complaint at ic3.gov.
Previous Post

Gravy Analytics Breached: A Massive Data Leak Exposes Millions of Location Traces

Next Post

Rainbow Six Siege Hacked: Players Gifted Billions of Credits as Ubisoft Forces Servers Offline

Paul

Paul

Editor and chief at ZeroSecurity. Expertise includes programming, malware analysis, and penetration testing. If you would like to write for ZeroSecurity, please click "Contact us" at the bottom of the page.

Recommended For You

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

February 6, 2026
Tennessee Man Pleads Guilty to Posting Stolen SCOTUS Docs on Instagram

Tennessee Man Pleads Guilty to Posting Stolen SCOTUS Docs on Instagram

January 19, 2026

Dutch Police Arrest Alleged AVCheck Operator in ‘Operation Endgame’ Breakthrough

January 16, 2026

Bigfork Man Sentenced to 46 Months After FBI Traces 1,100 IP Addresses in Cyberstalking Case

January 15, 2026

Europol Dismantles Black Axe Cell in Spain, Arrests 34 for €5.9M Fraud

January 11, 2026

Phishing 2.0: How AI is Turning Cyber Attacks into a Science

January 7, 2025 - Updated on January 9, 2025

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.