Indonesian Political, Business & Finance News

Beware of Silent Scam Modus Operandi That Drains Bank Accounts

| Source: CNBC Translated from Indonesian | Technology
Beware of Silent Scam Modus Operandi That Drains Bank Accounts
Image: CNBC

Jakarta, CNBC Indonesia - Cybersecurity researchers have revealed a fraud modus operandi that silently drains victims’ bank accounts. The perpetrators create fake websites resembling well-known companies to deceive customers and divert payments to accounts they have prepared.

Russian cybersecurity firm F6 uncovered a large-scale fraud campaign that has been ongoing since 2017. The perpetrators created clone sites of various Russian companies, ranging from fertiliser producers, petrochemical firms, metallurgical plants, logistics operators, to banks.

F6 stated that most of the content on these fake sites was copied directly from the companies’ official websites. Some also used domain names very similar to the originals.

“Most of the content on these fraudulent sites is copied from the companies’ official websites. Some also use very similar domain names. These fake sites are available in English, French, Arabic, and Russian to target international customers and steal advance payments for goods that never actually existed,” F6 said, as quoted by The Hacker News on Thursday (30/7/2026).

Analysis shows that this fraud scheme primarily targets organisations in Commonwealth of Independent States (CIS) countries, particularly in the business-to-business (B2B) and international trade sectors.

The perpetrators initiate contact with potential victims through phone calls, phishing emails, and fake company websites. They then send business documents containing bank account details belonging to fictitious subsidiary companies.

This modus operandi works by directing potential customers to clone sites that appear to be official websites. On these sites, the contact information has been altered so that all victim communications are connected directly to the perpetrators.

In some cases, the perpetrators even recruit salespeople who are unaware of the fraud to make initial calls to potential customers. When negotiations reach the final stage, the victim is directed to someone claimed to be a “senior manager”.

After that, all communication is handled directly by the perpetrators. They send business proposals, contracts, and invoices with fake bank account details so that the victim’s payment funds go to accounts controlled by the fraud syndicate.

One victim, a company from Azerbaijan, is estimated to have suffered losses of up to US$150,000 in April 2025 as a result of the fraudulent transaction.

F6’s investigation found nearly 100 fake domains impersonating official companies. Researchers also found links between this fraud infrastructure and similar campaigns that have been ongoing since 2017.

“Most of this infrastructure uses the same DNS records, IP addresses, and registration data. This indicates that these sites are part of a single coordinated campaign,” said Elena Shamshina, technical lead of F6’s Threat Intelligence Department.

F6 also revealed a similar case that occurred in 2017. At that time, a chemical company in Russia received numerous phone calls from farmers complaining about delayed deliveries of fertiliser they had paid for in advance.

The farmers claimed to have contracts with signatures believed to be from company representatives. However, the company confirmed that these contracts were never issued.

The investigation later found that the perpetrators had created a fake website almost identical to the company’s official site. The only differences were the bank account details and company contacts.

“The perpetrators also created very convincing business proposals using the company’s official letterhead. Although the documents appeared genuine, the payment information had been replaced with accounts controlled by the perpetrators. As a result, customers transferred money for goods that never actually existed,” F6 added.

F6 assesses that this campaign is international in nature. Whereas previously the perpetrators mostly used .ru domains, they now also utilise .com, .org, and .net domains. The sites are available in Russian, English, Arabic, and French.

In addition to fake sites, F6 found various fictitious business documents resembling commercial proposals, contracts, and invoices complete with fake company email addresses and manipulated bank account details.

“Analysis of these documents shows that the perpetrators prepared a complete package of business documentation to support the fake transactions and increase the victim’s trust,” said Vera Kolenikova, senior specialist at F6’s Cybercrime Investigation Department.

F6 warned that this fraud not only causes financial losses for victims but also damages the reputation of the companies whose brands are misused.

“Victims lose money, while the companies whose brands are misused suffer reputational damage. For companies engaged in international import and export, one of the most effective security measures is to independently verify contact information and payment details before transferring funds,” the firm stressed.

View JSON | Print