Cybersecurity vendor F6 has detailed a large-scale fraud campaign that has been active for over nine years. The operation involves creating replica websites of prominent Russian companies, including those in fertilizer manufacturing, petrochemicals, metallurgy, logistics, and banking. These fake sites are used to defraud international businesses by soliciting advance payments for goods that are never delivered.
The threat actors copy content from legitimate company websites and often use lookalike domain names. These fraudulent sites are available in multiple languages, including English, French, Arabic, and Russian, to target a broad international customer base. The scheme primarily focuses on business-to-business (B2B) transactions within Commonwealth of Independent States (CIS) countries.
Attackers initiate contact through cold calls, phishing email campaigns, and fraudulent corporate websites. They distribute business documents containing banking details of fake "subsidiary" companies. In some cases, unsuspecting sales representatives are hired to make initial cold calls, then customers are passed to "senior managers" who are actually the fraudsters.
Once negotiations reach the final stage, fraudsters send commercial offers, contracts, and invoices with bogus bank details, diverting payments to their accounts. An Azerbaijani company reportedly lost $150,000 in April 2025 due to such a fraudulent transaction. F6's investigation has identified nearly 100 counterfeit domains impersonating companies, with some infrastructure linked to earlier campaigns dating back to 2017.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Cybersecurity researchers have uncovered a nine-year fraud campaign that uses cloned websites of major Russian companies to steal advance payments from international firms. The scheme targets B2B organizations, primarily in CIS countries, by tricking them into making payments to fraudulent bank accounts for non-existent goods.