YooMoney's YuScan Automates E-commerce Risk Assessment Scanning Up to 1,000 Sites Per Hour
YooMoney has published a detailed technical overview of YuScan, its internal service for automated risk assessment of e-commerce websites. The tool helps banks and payment organizations detect merchants that attempt to mask prohibited or high-risk activities behind seemingly legitimate storefronts.
Since its launch in 2020, YuScan has analyzed more than 550,000 merchant applications. During this period YooKassa has not received any regulatory fines related to servicing prohibited business activities.
The service is intended for organizations that process over 10,000 pages daily, work with acquiring, marketplaces, KYC/AML checks, or must comply with Russian Federal Law 152-FZ. Manual analysis of such volumes quickly becomes a bottleneck, so YuScan was developed to perform deep, automated audits at scale.
From URL to Report in Minutes
YuScan starts from a merchant’s homepage and recursively crawls the entire site structure. It behaves like a real browser by executing JavaScript, waiting for dynamic elements, and scrolling through pages. This approach reveals content that would remain hidden under simple HTTP requests.
Asynchronous processing allows the system to handle up to 1,000 sites per hour. For modern sites that rely heavily on JavaScript, the crawler uses the Playwright library. When standard automation is blocked by advanced anti-bot systems such as Cloudflare, YuScan switches to Camoufox, which modifies browser behavior at the C/C++ level to produce cleaner fingerprints and avoid detection.
Technology Stack and Architecture
The service is written in Python. The API layer is built with FastAPI, data is stored in PostgreSQL, and the crawling core is based on the open-source Scrapy framework. Playwright handles browser automation while custom scaling and risk-scoring logic sit on top of Scrapy’s queue and pipeline system.
After data collection, multiple analysis stages begin. Text, images, reviews, external links, and registration details are examined. Images are converted into vector embeddings and compared against sensitive categories such as alcohol, tobacco, and online gambling. Large language models evaluate context to reduce false positives.
External Signals and Final Scoring
YuScan also checks whether a domain appears in Roskomnadzor registries, reviews third-party feedback, analyzes WHOIS records, and looks for signs of cloned or fraudulent sites. Extracted company details (INN, KPP, OGRN, contacts, and legal documents) help distinguish real businesses from temporary or opaque operations.
Since the introduction of automated checks, merchant onboarding times have improved significantly: simple cases are completed in under three hours, half of all companies begin processing payments within one day, and seven out of ten finish the process within two days.
Related articles
Fake GTA and Ghost Casino Apps Flood Google Play Early Access with Scam Promises
Unscrupulous developers are exploiting Google Play's Early Access program to distribute applications that make false promises of earnings through fake games and casino experiences. These apps lack public ratings and reviews, preventing disappointed users from warning others before installation. Bitdefender reports that the scheme is heavily promoted via advertisements on TikTok, Facebook, and other social networks, often featuring deepfakes of actors, athletes, and celebrities to build credibility. Users are lured with offers of PayPal payments, cryptocurrency, gift cards, and casino jackpots, but the apps deliberately slow progress near withdrawal thresholds. After installation, the software displays generous virtual winnings that never translate into real payouts. The campaign relies on aggressive advertising and misleading interfaces to maximize installations before users realize the fraud.
BI.ZONE Mail Security 3.0 Enhances Detection of Password-Protected Archives and Spam Variants
BI.ZONE has released Mail Security 3.0, introducing new mechanisms to detect email threats and improved tools for administrators. The updated system now assigns additional risk scores to password-protected archives when their contents cannot be unpacked, without automatically classifying the archive itself as malicious. It also compares message texts to identify near-identical emails used in spam campaigns where attackers slightly alter wording to evade filters. Administrators can now incorporate SPF and DKIM verification results into delivery rules to better distinguish legitimate senders from impersonators. According to BI.ZONE statistics, phishing accounted for 90 percent of illegitimate email traffic in the first half of 2026. Additional protections include CAPTCHA challenges after repeated failed login attempts on administrative accounts. The release also adds bulk management of rules, improved logging with a side panel for message details, a new Events section, and Syslog export to external SIEM systems.
F6 and MAX Neutralize Over 2,550 External Phishing and Scam Resources in Two-Month Operation
F6 and the MAX messenger have jointly blocked more than 2,550 malicious external websites used for phishing, scams, and other forms of online fraud. The effort relied on the F6 Digital Risk Protection platform, which continuously scans for fake authentication pages and fraudulent resources targeting users. Monitoring took place during July and August 2026, after which experts from both organizations arranged for the sites to be taken down. The action focused exclusively on external resources and did not involve any malicious content hosted inside the MAX messenger itself. F6 Digital Risk Protection head Stanislav Goncharov noted that regular takedowns can reduce attacker activity over time, yet users must still verify website addresses manually before entering credentials or payment data.
Trezor Warns of Email Provider Breach Used in Targeted Phishing Campaign Against Hardware Wallet Users
Trezor has disclosed that attackers compromised an external email provider and leveraged it to send phishing messages that appeared to originate from the company. The emails carried the subject line 'Critical Security Alert: STM32 Entropy Vulnerability' and falsely claimed a hardware flaw in STM32 microcontrollers that would reduce entropy and allow seed phrase reconstruction. No such CVE exists, and the campaign followed classic social-engineering patterns of urgency and brand impersonation aimed at stealing recovery phrases. Trezor has since disabled the malicious domain and continues investigating how the provider was accessed. Similar messages may have reached users of BitBox, suggesting possible compromise of shared service providers across the hardware wallet ecosystem. The incident underscores the difficulty of detecting phishing when it originates from legitimate third-party infrastructure.