Fraud & Social Engineering

Cybersecurity news in this category

🇪🇸Sep 10

Trezor Warns of Email Provider Breach Used in Targeted Phishing Campaign Against Hardware Wallet Users

Trezor has disclosed that attackers compromised an external email provider and leveraged it to send phishing messages that appeared to originate from the company. The emails carried the subject line 'Critical Security Alert: STM32 Entropy Vulnerability' and falsely claimed a hardware flaw in STM32 microcontrollers that would reduce entropy and allow seed phrase reconstruction. No such CVE exists, and the campaign followed classic social-engineering patterns of urgency and brand impersonation aimed at stealing recovery phrases. Trezor has since disabled the malicious domain and continues investigating how the provider was accessed. Similar messages may have reached users of BitBox, suggesting possible compromise of shared service providers across the hardware wallet ecosystem. The incident underscores the difficulty of detecting phishing when it originates from legitimate third-party infrastructure.

Hispasec
🇷🇺Sep 8

Free Robux Lures Used in Phishing Campaign Targeting Children's Messenger Accounts

Scammers have launched a new wave of attacks aimed at children and teenagers by promising free in-game currency for Roblox, Brawl Stars, and Standoff 2. The scheme, uncovered by specialists from F6, uses short YouTube videos that direct victims to phishing sites disguised as reward platforms. One prominent site branded as NovaDrop tricks users into selecting a messenger and game before presenting a rigged roulette that awards a fake prize of 25,000 coins. To claim the reward, victims must enter a phone number and six-digit verification code, which actually authorizes the attackers in the chosen messenger. Once inside, the criminals can read conversations, view documents and media, access contacts, and send messages to the victim's friends while sometimes remaining undetected. The attackers are increasingly focused on hijacking existing accounts due to difficulties in purchasing new Russian profiles for their operations.

AntiMalware
🇷🇺Sep 6

Dynamic QR Codes Enable Personalized Redirects and Conceal Final Destinations

Dynamic QR codes printed on menus, receipts, and advertisements do not contain the final destination URL. Instead they point to an intermediary service that logs each scan and issues a redirect chosen at scan time. The redirect decision can depend on device model, language, IP address, country, and previous scans, allowing different users to receive entirely different pages. Owners can change the target after printing without replacing the physical code, creating risks when domains or accounts change hands. Each scan records time, device details, and approximate location, leaving a trail users did not consent to. Attackers exploit these properties with overlay stickers, QR codes inside documents that bypass email filters, and fake payment pages that request card details instead of processing a true QR payment.

Habr
🇷🇺Sep 3

Booking.com Security Overlooked Fake Downing Street Listing in Which? Fraud Test

Researchers from Which? successfully listed a fake apartment at 10 Downing Street on Booking.com to test the platform's fraud defenses. The listing included the exact address, photos of the UK Prime Minister's residence, and a description of a one-bedroom property near Parliament. Booking.com processed a payment for a week-long stay and failed to refund it even after more than six weeks. A fabricated positive review mentioning the official cat Larry was approved almost instantly. The platform also permitted a phishing link sent through its internal chat system asking for credit card details. The listing remained active from June 18 until its removal on August 27, prompting Which? to call for an Ofcom investigation into Booking.com's systemic security failures.

AntiMalware
🇵🇹Sep 2

Password Spraying Campaign Targets AWS Root Accounts in Over 150 Organizations

A password spraying campaign targeted AWS root accounts across more than 150 organizations between July 24 and August 23, 2026. Attackers performed repeated login attempts against identities holding maximum privileges in the cloud environment. The root account is created with every AWS account and grants full access to resources, configurations, billing, and sensitive administrative functions. Researchers observed a median of two attempts per organization, with some targets receiving up to eight attempts. No successful authentications linked to the campaign have been identified so far. The attacks leveraged distributed proxies across multiple countries and networks, including hosting infrastructure and residential proxies, while using user agents that mimicked older versions of Microsoft Edge and Firefox. Since June 2025, AWS has required MFA for root users, significantly raising the bar for account takeover even if a password is discovered.

BoletimSec
🇷🇺Sep 2

Unsolicited iPhone 15 Pro Max Delivery to Reddit User Sparks Fears of Targeted Cyber Attack

A Reddit user received an unexpected iPhone 15 Pro Max in a sealed box that was never ordered. Apple’s service identified the serial number as belonging to a device purchased or activated in December 2023, with its warranty already expired in 2024, creating a clear mismatch between the new-looking packaging and the device’s documented history. The included FedEx label contained a tracking number that does not exist in the carrier’s system. Discussion on the platform raised the possibility of a targeted attack, potentially a form of whaling, in which the phone could have been pre-modified to steal data or credentials once connected to a network or Apple ID. No concrete evidence confirms the package originated from an attacker, and alternative explanations such as a delivery error or order fraud remain possible. Experts recommend that recipients avoid powering on the device, inserting a SIM card, or entering any account credentials, and instead consider returning it to Apple for inspection or disposing of it as electronic waste.

AntiMalware
🇷🇺Sep 2

Scammers Embed Phishing Inside Telegram Mini Apps After August Update

Cybercriminals are increasingly abusing Telegram's Mini Apps and WebView features to deliver phishing attacks that mimic legitimate banking, payment, and cryptocurrency services. Following the platform update on August 25, attackers can now present fake interfaces for transfers, airdrops, and voting systems directly inside the messenger. Victims are tricked into entering confirmation codes, connecting wallets, or pasting commands into PowerShell under the guise of fixing errors or claiming bonuses. The attacks rely heavily on social engineering rather than automated malware, requiring users to actively authorize actions such as signing transactions or providing phone verification details. Fake voting schemes are used to harvest account credentials, while crypto-related lures prompt users to link wallets to malicious services. Experts emphasize that simply opening a Mini App does not lead to immediate theft, but authorizing or connecting assets does expose users to significant risk.

AntiMalware
🇷🇺Sep 2

Google Introduces Multi-Step Verification for Android APK Sideloading to Combat Fraud

Google has begun rolling out an enhanced installation flow for Android apps installed outside of Google Play. Users must first confirm that no one is coercing them to enable unknown sources, then reboot their device and wait 24 hours before the option becomes available. The new process includes explicit warnings about scammers who pressure victims into enabling sideloading, noting that legitimate organizations never require this setting. After the waiting period, users can grant the permission for seven days or indefinitely. The change does not affect ADB installations, preserving a workaround for advanced users. Google states the delay is intended to give people time to reconsider before enabling potentially risky settings. An Android Authority poll showed 88 percent of respondents expect further restrictions in the future.

AntiMalware
🇷🇺Aug 30

Why 'Be Vigilant' Is Not Enough: Dissecting Human Psychology During Social Engineering Attacks

A cybersecurity expert with years of SOC and pentest experience explains why traditional awareness training fails against social engineering. The article details how attackers exploit psychological levers such as authority, urgency, reciprocity, social proof, and emotion to bypass conscious decision-making. It emphasizes that people who fall for attacks are often the most helpful and diligent employees, not the careless ones. Instead of relying on willpower in stressful moments, organizations must implement procedures that enforce independent verification and protect the right to pause. The piece also highlights how a blame-free culture dramatically reduces incident impact by encouraging early reporting. Technical measures that reduce reliance on a single human decision are presented as effective supplements to policy.

Habr
🇷🇺Aug 28

Scammers Impersonate Gas Workers to Pressure Russians into Overpriced Repairs Before September 1 Deadline

Fraudsters have started visiting apartments and private homes in Russia, posing as employees of gas services or management companies. They claim to have discovered critical issues such as gas leaks, faulty valves, problematic meters, or dangerous chimneys during supposed August inspections. Residents are warned that gas will be disconnected by September 1 unless immediate and expensive repairs are paid for on the spot. In some cases, scammers demand prepayments for urgent work and then disappear with the money. Victims are often charged 5 to 10 times the market price for equipment replacement. The Moshelovka platform of the Narodny Front has reported these incidents and issued safety recommendations. Residents are advised to verify maintenance schedules in advance and never pay cash or transfer money to individuals without confirmation.

AntiMalware
🇷🇺Aug 26

VC.ru Blocks Lawyer's Account After Article Exposing In-Platform Phishing Scheme

A Russian lawyer specializing in IT law and cryptocurrency regulation published an article on VC.ru detailing a phishing operation that abused the platform's own articles. The scheme involved posting seemingly legitimate content that later had links altered to redirect users to fake services stealing crypto assets. Within an hour of publication, the author's four-year-old account was automatically blocked under rules prohibiting multiple accounts to evade bans, despite the author having no prior restrictions or secondary accounts. After formal complaints citing Russian data protection law 152-FZ and consumer protection statutes, the platform reversed the ban but initially reclassified the account as commercial, demanding a monthly fee of 56,000 rubles for indexing. The account status was later restored following further legal correspondence. The incident highlights platform moderation challenges when reporting security threats involving paid accounts on the same site.

Habr
🇷🇺Aug 26

Email Graph Analysis Detects Impersonated Suppliers When DKIM and SPF Pass

Security researchers have outlined a practical method to identify business email compromise attempts that bypass traditional authentication checks. The approach relies solely on metadata from mail server logs to build communication profiles between external and internal addresses. By tracking first contact, one-way traffic, dormant periods, unusual sending hours, and domain similarity, analysts can flag high-risk messages requesting payment changes. The technique works against mailbox takeover scenarios where attackers reuse legitimate threads and valid signatures. Implementation uses existing Postfix or Microsoft Exchange logs and requires no new infrastructure beyond daily exports. A simplified version focusing only on lookalike domain detection can be built in a single evening and still catches most supplier impersonation attempts.

Habr
🇷🇺Aug 26

Developer Releases PhishIntel Open-Source Tool for Phishing Site Analysis and Risk Scoring

A developer has published PhishIntel, a lightweight Python-based OSINT application designed to analyze domains and evaluate phishing risk. The tool performs extensive checks including domain structure analysis, DNS records, RDAP and WHOIS data, TLS certificates, HTTP redirects, page content, security headers, and JavaScript static analysis. It generates structured JSON reports containing risk scores with explanatory indicators. Optional integrations with VirusTotal, Google Safe Browsing, URLhaus, Nmap, Nuclei, ZAP, and Playwright enable reputation checks, dynamic browser analysis, and active scanning. The project aims to help identify suspicious sites used in schemes such as the recent fake fuel sales campaign that defrauded victims of at least 3.7 million rubles. The author invites feedback from security professionals to improve the codebase.

Habr
🇷🇺Aug 20

Russian Court Bans Advertising for Renting and Selling Third-Party Bank Cards

The Chertanovsky District Court of Moscow has ruled that information promoting the rental and sale of other people's bank cards is prohibited for distribution in Russia. The decision targets a website and two Telegram channels that offered users the chance to temporarily lend or permanently sell their cards to third parties. Such schemes are commonly used to recruit drops who help receive, transfer, and cash out stolen funds. The court found that these proposals violate the rights and legitimate interests of citizens. Owners of the resources could not be identified, and domain registrars were foreign companies. VTB had previously warned about these schemes in 2024, noting that card owners risk ending up on bank blacklists, losing access to financial services, and facing criminal charges. The Ministry of Internal Affairs has also highlighted that transferring bank cards and accounts to outsiders can lead to criminal liability, with fraudsters particularly targeting children and teenagers.

AntiMalware
🇷🇺Aug 20

Smart Engines Patents AI Method to Detect Holographic Security Features in Documents Using Visible Light Only

Smart Engines has developed and patented a new technique that identifies optically variable devices such as holograms on identity documents without requiring ultraviolet illumination. The approach relies on a standard document scanner equipped with six independently controlled LEDs that capture a sequence of six images under different lighting angles while the document and camera remain stationary. After dark-current correction and calibration against a white reference sheet, the system normalizes the images and computes per-pixel color-vector standard deviation to generate an OVD map. A simple thresholding and region-of-interest analysis then produces a binary verdict indicating whether a genuine holographic element is present. The method effectively distinguishes original documents from high-quality color prints, photocopies, and physical replicas that cannot reproduce the angle-dependent color shifts of real OVDs. All processing occurs with existing scanner hardware, demonstrating that algorithmic interpretation of controlled illumination can add a new authenticity signal without additional optics or spectral channels.

Habr
🇷🇺Aug 19

YooMoney's YuScan Automates E-commerce Risk Assessment Scanning Up to 1,000 Sites Per Hour

YooMoney has detailed the inner workings of its YuScan service, an automated auditing tool designed to help banks and payment providers identify websites that conceal prohibited or high-risk activities. Since 2020 the system has processed more than 550,000 merchant applications without resulting in any fines for servicing illegal operations. YuScan builds comprehensive site maps, executes JavaScript, and handles dynamic content using Playwright combined with Camoufox to evade modern anti-bot protections such as Cloudflare. The crawler is built on Scrapy with FastAPI and PostgreSQL, then applies ML models, embeddings, and LLMs to analyze text, images, reviews, and external signals including Roskomnadzor registries and WHOIS data. The automation has reduced manual review time dramatically, allowing half of compliant merchants to begin accepting payments within 24 hours. YooKassa now offers the service to other banks through NSPK, the operator of the Mir payment system.

Habr
🇷🇺Aug 14

Scammers Pose as Employers to Remotely Lock iPhones and Demand Ransom

Russian police have warned of a new social engineering scheme in which fraudsters impersonate potential employers to gain control of victims' Apple devices. The attackers instruct targets to sign out of their personal Apple accounts and authenticate using credentials supplied by the supposed employer. Once the device links to the fraudster's account, the scammers can remotely lock the iPhone or iPad and demand payment for unlocking it. Authorities emphasize that paying the ransom does not guarantee recovery of the device and may lead to further extortion demands. Victims are advised never to enter third-party Apple credentials on personal hardware and to contact Apple Support with proof of purchase if a device is already locked. The scheme exploits the Find My and Activation Lock features built into iOS devices.

AntiMalware
🇷🇺Aug 14

Scammers Target Remote Workers with Fake Compensation for Home Internet and Devices

Russian remote employees are being targeted by fraudsters impersonating employers, government agencies, and corporate IT departments. Attackers lure victims with promises of compensation for home internet costs and personal computers, directing them to fake sites for identity verification or SMS code submission. Instead of receiving payments, victims risk handing over account credentials or banking details to criminals. Another tactic involves urgent messages from supposed IT services demanding immediate access renewal or software updates via malicious links. The pressure of urgency aims to bypass caution, leading users to click links, enter passwords, or execute files before verifying the sender. Home networks present additional risks because users manage their own routers and connected devices, unlike secured office environments. Experts from Yandex recommend changing default router passwords, updating firmware, disabling quick device pairing, and isolating smart devices on a separate guest network.

AntiMalware
🇯🇵Aug 14

Phishing Reports Fall 42.6% in June While Abused URLs Rise 3.2%

The Phishing Countermeasures Council recorded 72,370 phishing reports in June 2026, a 42.6% drop from 126,061 reports the previous month. Despite the decline in reports, the number of malicious URLs increased to 42,241, up 3.2% from the prior month. More than 90% of the phishing emails received by the council's monitoring addresses used unique domains. The largest share of attacks targeted the EC sector at 42.7%, followed by credit and finance services at 27.4%. The council noted that this marks the second consecutive month of declining reports after a peak in April.

Security NEXT
🇷🇺Aug 12

WhatsApp Begins Limited Beta Testing of On-Device Scam Alert to Detect Fraud While Preserving End-to-End Encryption

WhatsApp has started limited beta testing of its Scam Alert feature, which uses an on-device machine learning model to analyze message patterns and linguistic indicators of fraud. The system runs entirely locally on the user's smartphone, ensuring that conversation content is never sent to WhatsApp or Meta. Users receive warnings about suspicious messages from unknown contacts and can choose to block, report, ignore, or mark the chat as trusted. To maintain transparency, each model release is logged in an immutable journal managed by Cloudflare with Ed25519 signatures and SHA-256 hashes. The company receives only anonymized statistics on detections and user actions. In parallel, Signal has introduced automatic key verification using a cryptographically verifiable log audited by Cloudflare and Trail of Bits.

AntiMalware
🇷🇺Aug 12

Google Chrome Blocks Over 7 Billion Unwanted Notifications Daily on Android

Google reported that its Chrome protection systems blocked more than 7 billion unwanted notifications every day on Android during the first quarter of 2026. Websites increasingly use browser notifications to deliver phishing attempts, fraudulent payment requests, and malware. Chrome applies a multi-layer "Swiss cheese" defense model where several overlapping filters compensate for each other's weaknesses. The browser automatically revokes notification permissions from sites that have not been visited recently or that trigger repeated security warnings, and it can also cancel associated subscriptions. For particularly noisy resources, Chrome enforces a hard limit of 1,000 messages per minute and returns HTTP 429 responses to excess traffic. Google also made permission prompts less intrusive on Android, which reduced background activity and improved battery life. Users can review and manage notification permissions through Safety Hub on both desktop and mobile versions of Chrome.

AntiMalware
🇷🇺Aug 11

Mail.ru Blocks Phishing Wave Using Password-Protected RAR Archives

Mail.ru's antispam team has stopped a new phishing campaign that relies on password-protected RAR archives. These messages accounted for 13% of all blocked emails over the past month. The attackers impersonate business correspondents by sending contracts, signature requests, and tax-related notifications during the reporting season. Each email contains the archive password in plain text, allowing the recipient to open a malicious executable hidden inside. The malware is designed to steal credentials, grant remote access, or exfiltrate personal and corporate data. Mail.ru's filtering system uses more than 30 machine-learning models and antispam checks to detect such threats. Users are advised to verify senders carefully and avoid launching files from unexpected attachments even when a password is supplied.

AntiMalware
🇷🇺Aug 11

Kaspersky Adds Call Filtering to Kaspersky Secure Mobility Management for Android Devices

Kaspersky has introduced call control capabilities into the expanded version of Kaspersky Secure Mobility Management. The new feature allows corporate Android devices running Kaspersky Endpoint Security for Android to check incoming call numbers against both local offline databases and global online reputation sources. Depending on company policy, the system can display warnings to employees or automatically block suspicious calls. Administrators gain the ability to define rules by call category, maintain black and white lists, and apply different policies to specific employee groups. The update targets risks from telephone fraud and social engineering attempts that aim to extract confidential corporate information or funds. It also helps reduce unwanted spam calls that disrupt staff who handle high volumes of incoming communications. Kaspersky Secure Mobility Management provides full lifecycle control over corporate mobile devices, applications, data, and security policies.

AntiMalware
🇷🇺Aug 7

Behavioral Anti-Fraud: How Systems Analyze User Actions Beyond Device and Browser Fingerprints

Anti-fraud systems are shifting from static device and browser fingerprinting toward continuous behavioral analysis powered by machine learning. The article explains why matching User-Agent strings with Canvas or font rendering is no longer sufficient, as bot developers can easily synchronize these static signals. Modern defenses now record dozens of micro-events during a session, including keystroke timing, mouse trajectories, scroll speed, and focus changes, to build a dynamic Trust Score. These models are trained on large clusters of real-user behavior and flag sessions whose patterns fall outside legitimate clusters even when fingerprints appear realistic. The text details dwell time, flight time, error-correction patterns, natural hand tremor, and acceleration curves governed by Fitts’s law as key biometric markers. It also covers browser-level signals such as Event.isTrusted, CDP artifacts, and navigator.webdriver flags that reveal automation frameworks. The discussion extends to mobile sensors and concludes that perfectly error-free, mathematically smooth input is itself a strong indicator of synthetic activity.

Habr
🇵🇹Aug 7

Free Online Panel Examines Rising Omnichannel Scams and Multichannel Fraud Tactics

The Brazilian human risk management firm Eskive is hosting its third free online panel on August 18 at 11 a.m. to address the growing threat of omnichannel cyber fraud. Experts will discuss how attackers combine multiple channels such as email, SMS, and other vectors to create more convincing social-engineering narratives that bypass traditional single-channel defenses. The event will feature CEO Priscila Meyer as moderator along with cyber threat intelligence specialist Thiago Bordini and Santa Catarina Civil Police investigator Elias Edenis. Participants will gain practical insights from real client simulations, live Q&A sessions, and interactive quizzes designed to improve organizational preparedness. The panel aims to highlight why users accustomed to recognizing basic phishing or smishing attempts remain vulnerable when fraudsters deploy coordinated, multi-channel campaigns.

BoletimSec
🇵🇹Aug 6

OpenAI Disables Coordinated ChatGPT Network Used for Financial Scams and Identity Forgery

OpenAI has deactivated a coordinated network of ChatGPT accounts that supported financial fraud, romance scams, and identity forgery operations. Criminals leveraged the AI to generate fake personas, translate conversations, and craft targeted messages aimed at victims across multiple schemes. The investigation originated from reports of suspicious activity observed on WhatsApp. Scammers used the tool to produce forged documents including stock confirmations, legal notices, passports, and fake financial interfaces to increase credibility. Operations typically began on social media or messaging apps, building emotional trust or urgency before requesting deposits, activation fees, or nonexistent fines. Indicators of possible human trafficking and forced labor were also uncovered through job advertisements and internal discussions about worker control in Poipet. OpenAI has blocked the accounts and shared operational indicators with law enforcement and technology companies.

BoletimSec
🇷🇺Aug 4

Positive Technologies Uncovers Disinformation Factory Linking 45 Domains and 74 Telegram Channels

Researchers at Positive Technologies have exposed an integrated disinformation operation that combined fake government emails with a network of pseudo-news websites and synchronized social media channels. The campaign began with emails sent from lookalike domains such as minpromtorg.digital and gosuslugi.digital, requesting employee lists and salary data to prepare targeted phishing attacks. Parallel to the email activity, operators maintained at least 45 domains including rulenta.live and crime24.live that mixed genuine stories with fabricated content and cited nonexistent sources. These sites were amplified through dozens of Telegram channels and accounts on VKontakte, Odnoklassniki, YouTube, Instagram, and TikTok, creating a self-reinforcing loop where fabricated claims were quoted back as credible reporting. Investigators noted a possible infrastructure overlap with the cybercriminal group Rare Werewolf, although direct attribution remains unconfirmed. The operation demonstrates a complete information pipeline from initial reconnaissance via email to wide distribution of disinformation across multiple platforms.

AntiMalware
🇷🇺Aug 3

Russian Interior Ministry Advises Citizens Against Posting Personal Dossiers on Social Media

The Russian Ministry of Internal Affairs has issued a public warning urging citizens to reduce the amount of personal information shared on social networks. Details such as places of study and work, home addresses, and family information should remain outside public profiles to avoid attracting the attention of fraudsters and recruiters. According to materials cited by RIA Novosti, such digital self-portraits allow malicious actors to study potential victims, identify vulnerabilities, and craft personalized communication scenarios. The ministry also recommends avoiding public discussions of personal views and refraining from answering questions from strangers. Users are advised to verify profile ownership before engaging and to block suspicious accounts while reporting them to platform moderators. This marks the second such advisory from the ministry within recent months, following an October 2025 reminder about the risks of exposing full names, birth dates, and other identifiable data.

AntiMalware
🇵🇹Jul 31

Cordial Spider Deploys Work Panel Platform for Tech Support Scams Against Corporate Identities

A criminal platform called Work Panel is turning fake technical support calls into structured operations aimed at taking over corporate accounts. The service combines target research, page cloning, telephony, and credential capture within a single control panel. It is linked to the group tracked as O-UNC-045, also known as Cordial Spider. Campaigns target users of multiple identity providers and combine telephone social engineering with fake authentication pages. Operators research names, job titles, corporate emails, phone numbers, and professional profiles before calling to impersonate help-desk staff. While one operator keeps the victim on the line, a manager monitors the phishing session in real time. Captured credentials are sent only to operation managers via Telegram, reducing internal theft risks among the criminals themselves.

BoletimSec
🇷🇺Jul 31

Scammers Deploy Fake Russian Defense Ministry Websites to Harvest Data from Relatives of Fallen Soldiers

Russian threat intelligence firm F6 has uncovered a phishing campaign that used counterfeit Ministry of Defense portals to target relatives of participants in the special military operation. The attackers registered lookalike domains and populated them with official logos, coats of arms, and navigation menus copied from the legitimate mil.ru site, leaving only the registration form under their control. Victims were invited to register for state awards ceremonies and asked to supply full name, phone number, passport details, SNILS, and INN; an additional “Add guest” button collected the same information for accompanying persons. The stolen data can be used to reset access to government services, apply for microloans, or launch follow-on social-engineering attacks against military families. F6 analysts noted that the fraudulent pages were likely generated with a large language model, evidenced by an unhandled JSON error that appeared only after data submission. Although the discovered domains have been blocked inside Russia, the low technical barrier means new clones can be stood up quickly.

AntiMalware
🇷🇺Jul 30

Russia to Launch Unified Payment Card Registry in 2026 to Combat Dropper Fraud Schemes

Starting September 1, 2026, Russia will introduce a single nationwide system for recording all payment cards issued by domestic banks. The registry will include every card regardless of the payment system used, covering existing Visa and Mastercard products as well as expired cards that banks continue to service. The measure is designed to give banks visibility into the total number of cards held by any individual across multiple institutions, thereby disrupting dropper schemes that rely on multiple accounts for laundering stolen funds. No immediate mass closure of cards will occur; instead, the first year will focus on data collection and preparation. From September 1, 2027, a hard limit of 20 cards per person will apply to new issuances only, while existing cards above the limit will remain operational. The policy grants individuals time to decide which cards they truly need before the issuance restriction takes effect.

AntiMalware
🇷🇺Jul 28

Scammers Launch Fake Cyberpolice Russia Telegram Bot to Steal Accounts and Sell Fake Subscriptions

Fraudsters have created a counterfeit Telegram bot impersonating Russia's Cyberpolice, complete with official insignia and a convincing backstory. The bot promotes a paid subscription service for protection against cyber threats, essentially selling users defense against the scammers themselves. In a second attack vector, the bot requests a six-digit confirmation code, which grants attackers full access to the victim's Telegram account. Cyberpolice Russia has publicly stated that its units do not provide any paid services for threat notifications or protection. The legitimate bot operates under the exact handle cyberpolicerus_bot, and users are advised to verify the name character by character because scammers frequently alter letters or add symbols. Victims are reminded never to share six-digit Telegram codes with anyone, including entities claiming to represent law enforcement.

AntiMalware
🇷🇺Jul 27

Beeline Subscribers Targeted in Mass SIM Hijacking via Remote eSIM Issuance

Beeline customers have encountered widespread attempts to hijack mobile numbers through unauthorized remote issuance of eSIM cards. Attackers required only a single careless confirmation from the user to complete the takeover, bypassing traditional SMS or push notifications. The scheme presented a system-level prompt on the smartphone screen requesting login to the operator's personal account, after which a virtual SIM was issued and the physical card blocked. One victim was Kommersant FM editor-in-chief Vladislav Viktorov. Specialist Alexander Baulin suggested possible infrastructure compromise at the operator, though Beeline denied this and described the incident as a coordinated attack on remote SIM issuance mechanisms. The company stated it repelled the assault, with only isolated successful hijackings occurring, and is assisting affected users. Similar attacks have impacted the entire telecom market since the start of the year, enabling fraudsters to access banking apps, government services, and other accounts tied to the number.

AntiMalware
🇷🇺Jul 27

Yandex Rolls Out Universal Anti-Fraud Platform to Block Bots and Manipulation Schemes

Yandex has begun deploying its Universal Anti-Fraud system, a single AI-driven platform designed to detect bots, ticket scalping, and other forms of digital fraud across multiple services. The new solution can be integrated into a service within two to four days, replacing the previous months-long process of building separate defenses for each product. Dozens of Yandex services, including Eda, Afisha, Puteshestviya, and applications powered by Alice, are already connected to the platform. In Afisha the system identifies bots that mass-book tickets for popular events to create artificial scarcity, while in Eda it flags repeated fraudulent complaints aimed at obtaining compensation. The platform combines neural networks, analytical methods, and more than one hundred attack-pattern rules, analyzing traffic in real time and applying service-specific parameters. A key advantage is centralized updating: once a new fraud scheme is identified, protections are distributed instantly to all connected products.

AntiMalware
🇷🇺Jul 24

Protecting C-Suite Leaders: Defending Executives Against Targeted Cyberattacks

According to PT EdTechLab data, 12% of registered data leaks in Russia originate from attacks on top management. Executives often combine maximum privileges with lax cyber hygiene and public visibility, creating high-value targets. The article outlines three primary attack scenarios: targeted whaling phishing with deepfakes, compromise of personal devices used for both work and private tasks, and account takeover via weak passwords or SIM swapping. Detailed recommendations include mandatory multi-factor authentication, separate corporate devices or MDM solutions, EDR coverage, strict password policies, and network segmentation. The piece stresses that technical measures must be paired with direct communication using business impact language to secure executive buy-in and set an example for the wider organization.

Habr
🇯🇵Jul 24

IPA Reports Record High Fake Warning Scam Consultations in Q2 2026

The Information Processing Promotion Agency (IPA) recorded 3,832 personal security consultations in the second quarter of 2026, marking an 8.5 percent increase from the previous quarter. Fake warning scams, which display fabricated malware alerts to frighten users into contacting fraudsters, rose sharply to 1,428 cases, a 23.7 percent jump and the highest figure in two years. These scams carry risks of financial loss and device compromise through fake support services. Consultations dipped temporarily after arrests in May 2025 but have now exceeded levels seen before those arrests. Phishing reports also increased slightly to 146 cases, including schemes impersonating the National Tax Agency. The trend of rising fake warning incidents has continued for three consecutive quarters, underscoring the need for ongoing public vigilance.

Security NEXT
🇷🇺Jul 23

macOS Users Encounter Phishing and Scams More Often Than Windows Users but Adopt Fewer Protections, Kaspersky Study Reveals

A new study from Kaspersky Lab shows that macOS users report higher rates of phishing encounters and various scams compared to Windows users, yet they are less likely to implement basic security measures. Over the past year, 12 percent of macOS users faced phishing attempts versus 9 percent of Windows users, while 16 percent encountered investment fraud schemes compared to 13 percent. Privacy violations and personal data theft were also reported more frequently by Mac owners at 11 percent and 12 percent respectively, against 8 percent and 7 percent for Windows. Security habits differ notably, with only 51 percent of macOS users avoiding suspicious links and emails versus 62 percent of Windows users, and just 35 percent installing additional protection tools compared to 42 percent. Password practices and multi-factor authentication usage follow the same pattern, with Mac users trailing in creating unique or complex passwords and enabling 2FA. Kaspersky notes that while macOS built-in defenses handle many threats effectively, they offer limited protection against social engineering and platform-specific attacks, underscoring that the Apple brand does not serve as automatic security.

AntiMalware
🇷🇺Jul 23

Scammers Impersonate Russian Post to Lure Victims into Fake Telegram Bots

Fraudsters have developed a new scheme targeting Russian citizens by impersonating Russian Post over the phone. They claim that a registered letter or parcel requires additional address details and direct victims to a counterfeit Telegram bot. The bot then requests personal information, bank card data, or SMS verification codes. State Duma deputy Anton Nemkin highlighted how the criminals exploit trust in the well-known postal service and create urgency around expected deliveries. Victims are advised to avoid any links or contacts provided by callers and instead verify information directly through official Russian Post channels. The scheme relies on automatic reactions from people who may be expecting packages, making them more likely to follow instructions without suspicion. No actual parcel exists, but the risk of account takeover or financial loss remains very real.

AntiMalware
🇷🇺Jul 22

From Free Game Cheats to Arson: Cybercriminals Recruit Children for Espionage and Violent Crimes

Cybercriminals are increasingly targeting children not only to steal money from parents but also to turn them into unwitting accomplices in dangerous criminal activities. During school holidays, teenagers spend more time in games and messengers where scammers offer free in-game currency, mods, cheats, and pirated game versions to build trust. Once access is gained, fraudsters extract SMS codes, bank card details, or device control, escalating to threats and blackmail when initial tactics fail. Kaspersky Lab recorded over 19 million attempts to distribute malware disguised as popular games between April 2024 and April 2025, installing spyware and RAT trojans that monitor chats, keystrokes, cameras, and microphones. In severe cases, children are manipulated into believing they assist law enforcement, leading to real-world crimes such as photographing apartments, handing over keys, setting fires, or attacking people. Specific incidents include a 12-year-old boy from Leningrad Oblast forced to assault a police officer and a 13-year-old from Podolsk ordered to ignite a gas pump at a filling station. Izvestia reporting highlights that parents should watch for signs like hidden screens or strange tasks and teach children that no stranger can demand codes, money, or secret missions.

AntiMalware
🇷🇺Jul 20

Google Quietly Rolls Out Android Developer Verifier App to Curb APK Sideloading Fraud

Android users are discovering a new system application called Android Developer Verifier with the package identifier com.google.android.verifier that Google installs automatically through system updates without any separate consent prompt. The service prepares devices for upcoming restrictions on installing APK files from unknown sources by checking whether an app is registered to a verified developer who has passed identity verification and supplied legal information to Google. This verification does not guarantee an application is safe but allows Google to associate it with a specific individual or company, helping combat social-engineering scams in which fraudsters pressure victims into disabling protections and installing malicious APKs. To install software from an unverified developer, users will need to enable developer mode, confirm they are not under duress, reboot the device, wait 24 hours, and re-authenticate with PIN or biometrics. The new requirements begin on 30 September in Brazil, Indonesia, Singapore, and Thailand, with worldwide expansion planned for 2027 and later. While the app can currently be removed, it is unclear whether future updates will restore it, and advanced users retain the option to sideload via ADB, which bypasses the new checks entirely.

AntiMalware
🇷🇺Jul 20

Protecting Your Credit History: How to Check for Unauthorized Microloans and Set Up Self-Bans in Russia

Russians often discover fraudulent loans taken out in their name only when banks reject their applications, revealing unknown debts in their credit reports. The article explains how to obtain a list of credit bureaus via Gosuslugi or the Central Bank of Russia, download free reports twice a year from each BKI, and thoroughly review contracts, applications, and creditor inquiries rather than focusing solely on credit scores. It details the new self-ban mechanism available from March 2025 on Gosuslugi and September 2025 via MFC, which blocks remote lending while allowing exceptions for mortgages and education loans. Practical advice covers pre-travel preparations, immediate actions after losing documents or phones, and the step-by-step process of disputing fraudulent entries with creditors, police, and the Central Bank. The guide also includes a table of common red flags and a checklist of ongoing security habits to prevent identity theft and financial fraud.

Securitylab
🇷🇺Jul 19

Aurorium Anti-Detect Browser Uses AI Fingerprinting Linked to Real Hardware and User Profiles to Evade Modern Anti-Fraud Systems

Aurorium is an anti-detect browser that differentiates itself from competitors by embedding spoofing directly into the browser kernel rather than relying on JavaScript patches. The product generates fingerprints using AI that analyzes the operator’s actual device hardware and matches it to a realistic social profile including age, income, occupation, and geography. Network routing is handled at the kernel level so that WebRTC and DNS traffic is forced through proxies without disabling features that anti-fraud systems flag. The company also published a detailed Cure53 security audit that identified and subsequently fixed four critical vulnerabilities. Team-oriented features include built-in CRM, task management, multi-team support, and a mobile application. The review highlights that Aurorium’s approach reduces the common mismatch between generated fingerprints and the supposed user’s real-world context that often triggers detection.

Securitylab
🇨🇳Jul 18

CACTER Upgrades PhishSim Anti-Phishing Simulation System to Help Enterprises Reduce Phishing Risks in Four Easy Steps

CACTER has released an updated version of its PhishSim anti-phishing drill system designed to replace traditional theoretical training with realistic, immersive phishing simulations. The platform can replicate common attack vectors including fake links, malicious attachments, and disguised QR codes while impersonating legitimate senders and official domains to mimic both APT and spear-phishing campaigns. Organizations using the system have reportedly lowered their average employee click rate from 23.88% to 4.16% through regular, customized exercises. Key features include a continuously updated template library tailored to specific industries and business scenarios, automated visual reports that rank departments and classify employee risk levels, and actionable remediation recommendations. The entire workflow is completed in just four steps—selecting templates, grouping employees, launching drills, and reviewing reports—allowing companies to run ongoing training without dedicated security specialists. The solution emphasizes measurable results and a closed-loop process of simulation, analysis, and improvement to strengthen email security posture.

嘶吼
🇷🇺Jul 18

Dutch Police Arrest Leader of 700-Person Investment Scam Network That Stole Over €100 Million Monthly

Dutch authorities have arrested the suspected leader of a massive international investment fraud operation that employed more than 700 people across roughly 20 offices in multiple countries. The 46-year-old Israeli-Polish citizen, described as a known hacker, was detained in Poland while traveling from Dubai and later extradited to the Netherlands. The group posed as financial consultants, using fake trading platforms to convince victims to invest increasingly large sums, primarily in cryptocurrency, while never actually placing the funds. Victims in the Netherlands alone reported nearly €25 million in losses across 550 complaints, with many losing over €10,000 and suffering severe consequences including inability to buy food and suicidal thoughts. Additional arrests occurred in Belgium, Cyprus, and Greece, while Europol assisted in disrupting the network's infrastructure and identifying further suspects.

securitylab_n
🇷🇺Jul 16

Interpol Dismantles €140 Million BEC Fraud Network Impersonating Executives Across Spain, Portugal and Panama

Police have dismantled an international criminal network that used Business Email Compromise (BEC) techniques to steal €140 million through investment fraud and the substitution of corporate correspondence. The operation, conducted simultaneously in Spain, Portugal, and Panama with support from Interpol and Europol, resulted in the arrest of four suspected organizers. Investigators found the group controlled more than 800 bank accounts and 120 corporate accounts while relying on 67 intermediaries to move funds. The scheme involved impersonating company executives or sending fake invoices to trick employees into transferring money to accounts controlled by the criminals. Rapid layering of transfers across multiple countries obscured the money trail, with at least €94 million confirmed to have passed through the network. Authorities froze €3 million and seized 15 computers plus over 170 smartphones during raids on six premises in Barcelona, Girona, Tarragona, and Porto.

securitylab_n
🇷🇺Jul 15

Microsoft Permanently Locks Hacked Account After Security Changes, Erasing 25 Years of OneDrive Data and Purchases

A streamer named Joshua Kane lost access to his Microsoft account containing 25 years of digital files, family photos, and purchased content after it was compromised by an attacker who altered security settings. Microsoft confirmed the account belonged to him and had been breached but refused to restore access, citing internal policies that prevent manual recovery once security information is changed by an unauthorized party. The company stated that OneDrive content cannot be extracted due to its encryption architecture and privacy protections, leaving the data permanently inaccessible even to Microsoft engineers. Kane was advised to create a new account and repurchase games and services, while the incident quickly gained over two million views on social media and prompted other users to share similar experiences. The case underscores the risks of insufficient account protection and the permanent consequences of account takeovers when two-factor authentication and backup strategies are not properly implemented.

AntiMalware
🇷🇺Jul 14

Phishers Launch Dark Web Platform to Spoof Real Corporate Email Addresses from Major Companies

A new phishing platform has emerged on the dark web that enables attackers to send mass emails appearing to originate from legitimate corporate addresses of well-known organizations. The tool relies on advanced email spoofing techniques, making the sender’s domain and company name look authentic to recipients. According to research from BI.ZONE Threat Intelligence reported by Izvestia, the service is actively advertised on underground forums as a ready-to-use solution for large-scale campaigns. It also automatically scrapes official websites to replicate logos, branding, and email styling, significantly increasing the credibility of the fraudulent messages. Victims may receive messages disguised as invoices, security alerts, contractor proposals, or urgent data confirmation requests. Traditional advice to verify the sender address is now insufficient, as the displayed domain genuinely belongs to the targeted company. Security experts warn that users must now scrutinize links, unexpected requests, and any demands to download files or provide credentials.

AntiMalware
🇷🇺Jul 13

Looking for Gasoline? Hand Over Your Account: Scammers Launch Fake Gas Station Card Phishing Sites Targeting Fuel Shortages

Cybercriminals have created more than 60 phishing websites that impersonate gas station locator services, game platforms, marketplaces, and video hosting sites to exploit fuel shortages and user demand for bonuses. The primary scheme involves promising users real-time information on available gasoline, electronic fuel coupons, or free in-game rewards in exchange for providing a phone number and confirming it with an SMS code. Once the code is entered, attackers gain full access to the victim's messenger account, allowing them to read conversations, download media and documents, view contacts, and send messages on the victim's behalf. The fraudulent sites often appear highly convincing, prompting users to select fuel type and region before redirecting them to a fake verification form instead of displaying actual station data. F6 specialists identified that over half of the sites mimic marketplace brands, 19% pose as social platforms, and the remainder target gas station maps, games like Brawl Stars, video services, and classifieds boards using domains such as .site, .click, .shop, .lol, and .xyz. The same campaign also targets children by offering free Brawl Stars loot boxes and virtual currency. F6 has already submitted the malicious domains for blocking, though new phishing pages continue to emerge regularly.

AntiMalware
🇷🇺Jul 12

Interpol’s Operation First Light 2026: 5,811 Arrests, $293 Million Seized in Global Crackdown on Social Engineering Fraud

Law enforcement agencies from 97 countries and territories conducted Interpol’s Operation First Light 2026 between 15 January and 30 April 2026, resulting in 5,811 arrests and the seizure of $293 million in illicit assets. The operation targeted social engineering scams—including business email compromise, fake investment schemes, romance fraud, and blackmail—and the associated money laundering networks that have turned personal trust into a multi-million-dollar criminal enterprise. Over 152,000 cases were examined, more than 31,000 bank accounts were frozen, and nearly 24,000 crimes were solved, leading to the identification of 15,600 suspects and 142,000 victims worldwide. One of the most striking discoveries was a fully equipped fake Brazilian police station built in Eswatini, where 82 people were arrested and 240 electronic devices seized. In Thailand, investigators traced over $122.5 million in romance-scam proceeds through a single 20-year-old suspect’s cryptocurrency wallets, while coordinated efforts in Singapore, Oman, and Macau prevented multimillion-dollar losses in real time.

securitylab_n
🇷🇺Jul 12

GC Solar and SEG-T Launch Development of AI-Powered Security Email Gateway SEG-T to Counter Advanced Phishing Campaigns

GC Solar and co-founder of Secure-T Khariton Nikishkin have initiated the development of SEG-T, a new Security Email Gateway solution designed to protect corporate email systems using multi-agent AI. The project responds to the growing sophistication of phishing attacks that leverage ready-made toolkits, infrastructure, anti-bot mechanisms, and AI-generated content to create convincing messages at scale. Unlike traditional filters, SEG-T will analyze both technical indicators and semantic elements such as tone, manipulation tactics, attempts to build trust, instill fear, or create urgency. The system will block suspicious attachments including links, archives, PDFs, executables, and SVGs while focusing primarily on social engineering rather than relying on a built-in sandbox. SEG-T is planned for deployment across cloud, on-premises, and Kubernetes environments with rapid 15-minute setup times and will integrate with Solar webProxy and Solar Dozor for enhanced traffic inspection and data loss prevention. GC Solar holds a 49% stake in the project following its earlier acquisition of a controlling interest in Secure-T.

AntiMalware
🇷🇺Jul 12

Scammers Impersonate Neighbors to Lure Residents into Fake Bomb Shelter Chat Groups for Data Theft

Fraudsters have launched a new social engineering scheme that exploits public anxiety by impersonating neighbors and inviting victims to join Telegram chats supposedly dedicated to organizing bomb shelters in residential buildings. The callers claim an urgent residents’ meeting is taking place and insist that the target must share personal details and join the group chat to be included on the attendance list. In reality, decisions about creating official bomb shelters are governed by strict state regulations and cannot be made through informal neighbor votes, making the entire premise a clear red flag. Once the victim engages, scammers quickly pivot from the supposed shelter topic to requesting names, phone numbers, and other sensitive information. Victims who continue the conversation may later receive follow-up calls from fraudsters posing as government officials who claim the victim’s data has been compromised, pressuring them into transferring money or taking other harmful actions. The scheme is easily identified by callers who refuse in-person meetings, push for immediate chat enrollment, and avoid any verifiable details about the building or meeting. Security experts recommend ending such calls immediately and never sharing personal information with unknown individuals over the phone.

AntiMalware