← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Fraud campaign active since 2017, cloning Russian company websites.
  • Targets international B2B customers for advance payments.
  • Uses lookalike domains, cold calls, and phishing emails.
  • Nearly 100 counterfeit domains identified by F6 researchers.
  • Victims are directed to fake bank details for payments.

Long-Running Fraud Campaign Uncovered

Cybersecurity vendor F6 has detailed a large-scale fraud campaign that has been active for over nine years. The operation involves creating replica websites of prominent Russian companies, including those in fertilizer manufacturing, petrochemicals, metallurgy, logistics, and banking. These fake sites are used to defraud international businesses by soliciting advance payments for goods that are never delivered.

Modus Operandi

The threat actors copy content from legitimate company websites and often use lookalike domain names. These fraudulent sites are available in multiple languages, including English, French, Arabic, and Russian, to target a broad international customer base. The scheme primarily focuses on business-to-business (B2B) transactions within Commonwealth of Independent States (CIS) countries.

Attackers initiate contact through cold calls, phishing email campaigns, and fraudulent corporate websites. They distribute business documents containing banking details of fake "subsidiary" companies. In some cases, unsuspecting sales representatives are hired to make initial cold calls, then customers are passed to "senior managers" who are actually the fraudsters.

Financial Impact and Scope

Once negotiations reach the final stage, fraudsters send commercial offers, contracts, and invoices with bogus bank details, diverting payments to their accounts. An Azerbaijani company reportedly lost $150,000 in April 2025 due to such a fraudulent transaction. F6's investigation has identified nearly 100 counterfeit domains impersonating companies, with some infrastructure linked to earlier campaigns dating back to 2017.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Cybersecurity researchers have uncovered a nine-year fraud campaign that uses cloned websites of major Russian companies to steal advance payments from international firms. The scheme targets B2B organizations, primarily in CIS countries, by tricking them into making payments to fraudulent bank accounts for non-existent goods.