Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

U.S. Recovers $15.1 Million From 3ve Digital Advertising Fraud Scheme

By TheFinanceBase Team5 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

The U.S. government recovered $15,111,453.84 from Swiss bank accounts tied to the 3ve digital-advertising fraud scheme, the Justice Department announced on May 18, 2022. Switzerland transferred the funds under a final order of forfeiture. Prosecutors said businesses paid more than $29 million for ad activity that was not viewed by real people—but the announcement did not say the recovered money was distributed as refunds to advertisers or publishers.

How 3ve made fake advertising look real

3ve was a botnet-based advertising fraud operation. A botnet is a group of compromised computers that criminals can control remotely. According to prosecutors, 3ve operators accessed more than 1.7 million computers infected with the Kovter malware. The computers belonged to individuals and businesses whose owners did not know they were being used.

Hidden browser processes ran on those machines and loaded fabricated webpages made to resemble legitimate publisher sites. Those pages triggered digital ad auctions. Automated activity then generated billions of false ad views, or impressions. An impression records an opportunity for an ad to appear; it does not establish that a person saw or paid attention to it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The scheme falsified both sides of the advertising transaction: the supposed visitor was an infected computer running automated activity, and the supposed publisher page was fabricated or spoofed. Advertisers paid for impressions they believed reached human audiences. The DOJ said the operation spoofed more than 86,000 publisher domains and caused businesses to pay more than $29 million for ads not viewed by real users.

That does not mean 86,000 publisher websites were hacked. The figure refers to domains represented in the fraud; prosecutors described fabricated pages and domain spoofing, not compromise of every named publisher’s actual servers. Nor should false impressions be confused with fake clicks: the cited DOJ figures concern ad views.

The numbers measure different things

Figure What it describes
More than 1.7 million Computers prosecutors said defendants accessed; not necessarily every computer worldwide infected with Kovter.
More than 86,000 Publisher domains the scheme allegedly spoofed, not a count of publishers whose real sites were breached.
Billions Falsified ad views generated by the operation.
More than $29 million Business payments prosecutors attributed to ads not seen by real users.
$15,111,453.84 Proceeds recovered from Swiss accounts and transferred to the U.S. government under a forfeiture order.

The DOJ said more than 1,500 of the computers accessed were located at residences and businesses in the Eastern District of New York. The total computer figure is a count of machines, not people: a computer could belong to a household, company, or institution.

Who was charged in the 3ve case?

For the botnet-based operation prosecutors called “3ve.2 Template A,” or “Eve,” the DOJ identified Sergey Ovsyannikov and Yevgeniy Timchenko, citizens of Kazakhstan, and Aleksandr Isaev, a citizen of Russia. Ovsyannikov was arrested in Malaysia in October 2018 and extradited to the United States in March 2019. Timchenko was arrested in Estonia in November 2018 and extradited in February 2019. Both pleaded guilty in September 2019 and were later sentenced. The DOJ’s May 2022 announcement said Isaev remained at large at that time; that is a status reported in that announcement, not a claim about his present status.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The broader 2018 indictment involved eight defendants and covered more than one advertising-fraud operation. It included the separate Methbot scheme, which relied on computers in commercial datacenters rather than primarily on a botnet of infected personal and business computers. Prosecutors said Ovsyannikov provided technical assistance to Methbot operators, including help mimicking human behavior and evading fraud detection. They attributed more than $7 million in losses to Methbot. The relationship between the operations does not make them the same scheme.

How investigators disrupted the infrastructure

After Ovsyannikov’s arrest, U.S. authorities worked with private-sector partners to dismantle parts of the infrastructure. The FBI sinkholed 23 internet domains connected to the charged operation or Kovter and executed search warrants at 11 U.S. server providers, searching 89 servers linked to the operation or malware. In cybersecurity, sinkholing means taking control of or redirecting malicious domains so operators cannot use them normally and investigators can disrupt or observe communications.

The case also depended on cross-border cooperation. The investigation involved U.S. authorities, partners in the private sector, and Swiss authorities; the funds ultimately moved from Swiss accounts to the U.S. government through the forfeiture process. The DOJ separately said the FBI disruption also affected infrastructure associated with Boaxxe malware, which was not the same thing as proving that every compromised computer was part of 3ve.

What the $15.1 million recovery means

Forfeiture is the legal seizure and transfer of property connected to criminal conduct or its proceeds. In this case, Switzerland transferred $15,111,453.84 to the U.S. government following a Final Order of Forfeiture in United States v. Sergey Ovsyannikov et al. The DOJ described it at the time as the Eastern District of New York’s largest international cybercrime recovery.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That is not the same as a refund program. The DOJ announcement confirms the government recovered the funds; it does not say advertisers, publishers, or computer owners automatically received payments from them. The recovered amount was also not the full loss figure prosecutors cited: $15.1 million is the amount recovered from identified Swiss accounts, while alleged business losses exceeded $29 million.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why the case matters to advertisers and consumers

3ve showed how malware can be monetized without its operators needing to sell stolen files or demand a ransom. By turning infected computers into hidden participants in ad auctions, the scheme could charge advertisers for activity that had no genuine audience while diverting revenue from legitimate publishers. Owners of infected computers were another affected group: their machines and resources were used without their knowledge or consent.

For advertisers, the lesson is that an ad impression is a recorded event, not proof of a real person’s attention. For consumers and businesses, the case illustrates that a computer can be abused in the background even when its owner is unaware. The prosecution and forfeiture also demonstrate the importance of combining technical disruption, financial tracing, and international legal cooperation. They do not establish that ad fraud has been eliminated.

Timeline

  • December 2015: Prosecutors said the 3ve scheme began.
  • October 2018: Ovsyannikov was arrested in Malaysia.
  • November 2018: The broader indictment was unsealed in Brooklyn; Timchenko was arrested in Estonia.
  • February–March 2019: Timchenko and Ovsyannikov were extradited to the United States, respectively.
  • September 2019: Ovsyannikov and Timchenko pleaded guilty.
  • May 18, 2022: The DOJ announced the $15,111,453.84 transfer from Swiss accounts under a final forfeiture order.

Sources: DOJ forfeiture announcement (May 18, 2022); DOJ guilty-plea announcement (September 25, 2019); DOJ indictment announcement (November 27, 2018).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.