Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fraudsters Clone Russian Company Sites to Steal Payments

Fraudsters Clone Russian Company Sites to Steal Payments

Posted on July 29, 2026 By CWS

Cybersecurity experts have exposed an extensive fraud operation that has been cloning websites of major Russian firms to misappropriate funds from global businesses for over nine years. This sophisticated scheme has targeted international enterprises, utilizing counterfeit sites of Russian corporations across various sectors such as petrochemicals, metallurgy, and banking.

Details of the Fraud Scheme

According to the cybersecurity firm F6, the operation, which dates back to 2017, involves setting up fake websites that closely mimic the legitimate sites of Russian companies. These fraudulent sites target international customers by presenting content in multiple languages, including English, French, Arabic, and Russian. The fraudulent domains often resemble the genuine ones, misleading clients into making advance payments for non-existent goods.

Research shows that the scam primarily focuses on the Commonwealth of Independent States (CIS) countries, exploiting the business-to-business (B2B) sector. The fraudsters initiate contact through cold calls and phishing emails, directing victims to bogus websites where deceptive business documents with false banking details are shared.

Modus Operandi and Impact

The scheme deceives potential customers into engaging with these fake platforms, with altered contact information guiding them to the attackers. Sometimes, unsuspecting sales personnel are hired to conduct cold calls, eventually transferring negotiations to the fraudsters posing as senior managers. This tactic has led to significant financial losses for victims, including an Azerbaijani firm that lost $150,000 in April 2025.

F6’s investigation has identified nearly 100 counterfeit domains, revealing connections to earlier fraud activities. These domains share common DNS records and IP addresses, suggesting a coordinated effort. The campaign’s infrastructure is mainly linked to IP addresses 212.127.73[.]235 and 167.86.100[.]68.

Preventive Measures and Future Outlook

To combat this pervasive threat, businesses are advised to independently verify the authenticity of business partners and their contact information. Checking domain registration details and confirming payment instructions through reliable sources can mitigate such risks. Additionally, companies should be vigilant about verifying the legitimacy of subsidiaries and business documents.

The sophistication of these fraudulent activities, including the replication of fraud warnings, highlights the need for heightened cybersecurity measures. As the campaign continues to evolve, utilizing domains like .com, .org, and .net, vigilance remains crucial for companies engaged in international trade.

Overall, understanding the scale and ingenuity of these fraud schemes can help businesses protect themselves from substantial financial and reputational damage. Staying informed and conducting thorough due diligence are key steps in safeguarding against such cyber threats.

The Hacker News Tags:B2B sector, brandjacking, Cybercrime, Cybersecurity, DNS records, due diligence, fake domains, fake websites, Fraud, international trade, online scams, payment fraud, Phishing, protect your business, Russian companies

Post navigation

Previous Post: Houston College Data Breach Exposes 832k Student Records
Next Post: VMware ESXi Security Flaws Patched by Broadcom

Related Posts

Critical Lanscope Endpoint Manager Bug Exploited in Ongoing Cyberattacks, CISA Confirms Critical Lanscope Endpoint Manager Bug Exploited in Ongoing Cyberattacks, CISA Confirms The Hacker News
What Should We Learn From How Attackers Leveraged AI in 2025? What Should We Learn From How Attackers Leveraged AI in 2025? The Hacker News
Fortinet FortiGate Under Active Attack Through SAML SSO Authentication Bypass Fortinet FortiGate Under Active Attack Through SAML SSO Authentication Bypass The Hacker News
Google Launches New Maps Feature to Help Businesses Report Review-Based Extortion Attempts Google Launches New Maps Feature to Help Businesses Report Review-Based Extortion Attempts The Hacker News
Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomware Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomware The Hacker News
Why AI Projects Often Falter Post-Demo Why AI Projects Often Falter Post-Demo The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Highlights Critical Security Flaws in Artifactory and RouterOS
  • VLC Media Player Security Flaws Pose Serious Risks
  • Enhancing Security: Tackling Cloud Supply-Chain Threats
  • AI-Driven Cyber Threats Demand Swift Security Upgrades
  • BlueMoon Exploit Kit Targets Chrome and Windows Zero-Days

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Highlights Critical Security Flaws in Artifactory and RouterOS
  • VLC Media Player Security Flaws Pose Serious Risks
  • Enhancing Security: Tackling Cloud Supply-Chain Threats
  • AI-Driven Cyber Threats Demand Swift Security Upgrades
  • BlueMoon Exploit Kit Targets Chrome and Windows Zero-Days

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark