Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fraudsters Clone Russian Company Sites to Steal Payments

Fraudsters Clone Russian Company Sites to Steal Payments

Posted on July 29, 2026 By CWS

Cybersecurity experts have exposed an extensive fraud operation that has been cloning websites of major Russian firms to misappropriate funds from global businesses for over nine years. This sophisticated scheme has targeted international enterprises, utilizing counterfeit sites of Russian corporations across various sectors such as petrochemicals, metallurgy, and banking.

Details of the Fraud Scheme

According to the cybersecurity firm F6, the operation, which dates back to 2017, involves setting up fake websites that closely mimic the legitimate sites of Russian companies. These fraudulent sites target international customers by presenting content in multiple languages, including English, French, Arabic, and Russian. The fraudulent domains often resemble the genuine ones, misleading clients into making advance payments for non-existent goods.

Research shows that the scam primarily focuses on the Commonwealth of Independent States (CIS) countries, exploiting the business-to-business (B2B) sector. The fraudsters initiate contact through cold calls and phishing emails, directing victims to bogus websites where deceptive business documents with false banking details are shared.

Modus Operandi and Impact

The scheme deceives potential customers into engaging with these fake platforms, with altered contact information guiding them to the attackers. Sometimes, unsuspecting sales personnel are hired to conduct cold calls, eventually transferring negotiations to the fraudsters posing as senior managers. This tactic has led to significant financial losses for victims, including an Azerbaijani firm that lost $150,000 in April 2025.

F6’s investigation has identified nearly 100 counterfeit domains, revealing connections to earlier fraud activities. These domains share common DNS records and IP addresses, suggesting a coordinated effort. The campaign’s infrastructure is mainly linked to IP addresses 212.127.73[.]235 and 167.86.100[.]68.

Preventive Measures and Future Outlook

To combat this pervasive threat, businesses are advised to independently verify the authenticity of business partners and their contact information. Checking domain registration details and confirming payment instructions through reliable sources can mitigate such risks. Additionally, companies should be vigilant about verifying the legitimacy of subsidiaries and business documents.

The sophistication of these fraudulent activities, including the replication of fraud warnings, highlights the need for heightened cybersecurity measures. As the campaign continues to evolve, utilizing domains like .com, .org, and .net, vigilance remains crucial for companies engaged in international trade.

Overall, understanding the scale and ingenuity of these fraud schemes can help businesses protect themselves from substantial financial and reputational damage. Staying informed and conducting thorough due diligence are key steps in safeguarding against such cyber threats.

The Hacker News Tags:B2B sector, brandjacking, Cybercrime, Cybersecurity, DNS records, due diligence, fake domains, fake websites, Fraud, international trade, online scams, payment fraud, Phishing, protect your business, Russian companies

Post navigation

Previous Post: Houston College Data Breach Exposes 832k Student Records
Next Post: VMware ESXi Security Flaws Patched by Broadcom

Related Posts

Gitea Patches Critical RCE Vulnerability in Git Hooks Gitea Patches Critical RCE Vulnerability in Git Hooks The Hacker News
Golden Chickens Unveils New Malware Threats Golden Chickens Unveils New Malware Threats The Hacker News
GitLab RCE Exploit Allows Command Execution as Git GitLab RCE Exploit Allows Command Execution as Git The Hacker News
OpenSSL Vulnerability Causes Memory Freeze with Minimal Data OpenSSL Vulnerability Causes Memory Freeze with Minimal Data The Hacker News
Malicious Ruby and Go Modules Target CI Environments Malicious Ruby and Go Modules Target CI Environments The Hacker News
Active Attacks Exploit Gladinet’s Hard-Coded Keys for Unauthorized Access and Code Execution Active Attacks Exploit Gladinet’s Hard-Coded Keys for Unauthorized Access and Code Execution The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Web3 Developers Targeted by Fake Recruiters
  • VMware ESXi Security Flaws Patched by Broadcom
  • Fraudsters Clone Russian Company Sites to Steal Payments
  • Houston College Data Breach Exposes 832k Student Records
  • Mate Security Secures $35M to Enhance AI-Powered SOC

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Web3 Developers Targeted by Fake Recruiters
  • VMware ESXi Security Flaws Patched by Broadcom
  • Fraudsters Clone Russian Company Sites to Steal Payments
  • Houston College Data Breach Exposes 832k Student Records
  • Mate Security Secures $35M to Enhance AI-Powered SOC

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark