AntiMalwareJuly 12, 2026🇷🇺Translated from Russian

Scammers Impersonate Neighbors to Lure Residents into Fake Bomb Shelter Chat Groups for Data Theft

Scammers have developed a new social-engineering tactic that capitalizes on heightened public concern over safety by pretending to be neighbors and inviting people to join chat groups about equipping residential buildings with bomb shelters.

According to reports from the Telegram channel “Lapsa Media” and the author channel “Bez obmana” run by Alexander Yelshevsky, the fraudsters call residents and claim that an urgent meeting of building occupants is being organized to discuss the creation of a bomb shelter. The caller introduces himself as a neighbor, stresses the importance of the gathering, and urges the recipient to be added to a common chat so they can participate.

How the Scam Unfolds

Instead of discussing the supposed shelter, the conversation quickly shifts to requests for personal data. Victims are asked to provide their name, phone number, or other identifying information under the pretext of being added to the attendance list. The scammers further claim that without joining the chat and appearing on the list, the person will be unable to attend the meeting.

The fundamental flaw in the story is that residents cannot simply vote to establish a bomb shelter. Such facilities must be created in accordance with official state requirements and safety regulations. Therefore, any claim of an urgent neighbor meeting that cannot be accessed without handing over personal information to a stranger over the phone is itself a strong indicator of fraud.

Second Stage of the Scheme

If the target continues the conversation, a follow-up stage often occurs. The victim may later receive calls from individuals posing as government officials who state that the victim’s data has fallen into the hands of criminals. These callers then pressure the person to transfer money or perform other actions under the guise of protecting their information or resolving the issue.

Recognizing and Avoiding the Scam

  • The caller avoids any suggestion of an in-person meeting and insists on continuing the discussion exclusively by phone.
  • The conversation rapidly moves away from the supposed shelter topic toward requests for personal data.
  • The caller pressures the victim to join an unknown chat immediately.

Security experts advise ending such calls at once. Personal information should never be shared with strangers over the phone. If the caller is genuinely a neighbor, any legitimate issue can be discussed face-to-face within the building.

Related articles

AntiMalwareFraud & Social Engineering

Russian Court Bans Advertising for Renting and Selling Third-Party Bank Cards

The Chertanovsky District Court of Moscow has ruled that information promoting the rental and sale of other people's bank cards is prohibited for distribution in Russia. The decision targets a website and two Telegram channels that offered users the chance to temporarily lend or permanently sell their cards to third parties. Such schemes are commonly used to recruit drops who help receive, transfer, and cash out stolen funds. The court found that these proposals violate the rights and legitimate interests of citizens. Owners of the resources could not be identified, and domain registrars were foreign companies. VTB had previously warned about these schemes in 2024, noting that card owners risk ending up on bank blacklists, losing access to financial services, and facing criminal charges. The Ministry of Internal Affairs has also highlighted that transferring bank cards and accounts to outsiders can lead to criminal liability, with fraudsters particularly targeting children and teenagers.

HabrFraud & Social Engineering

Smart Engines Patents AI Method to Detect Holographic Security Features in Documents Using Visible Light Only

Smart Engines has developed and patented a new technique that identifies optically variable devices such as holograms on identity documents without requiring ultraviolet illumination. The approach relies on a standard document scanner equipped with six independently controlled LEDs that capture a sequence of six images under different lighting angles while the document and camera remain stationary. After dark-current correction and calibration against a white reference sheet, the system normalizes the images and computes per-pixel color-vector standard deviation to generate an OVD map. A simple thresholding and region-of-interest analysis then produces a binary verdict indicating whether a genuine holographic element is present. The method effectively distinguishes original documents from high-quality color prints, photocopies, and physical replicas that cannot reproduce the angle-dependent color shifts of real OVDs. All processing occurs with existing scanner hardware, demonstrating that algorithmic interpretation of controlled illumination can add a new authenticity signal without additional optics or spectral channels.

HabrFraud & Social Engineering

YooMoney's YuScan Automates E-commerce Risk Assessment Scanning Up to 1,000 Sites Per Hour

YooMoney has detailed the inner workings of its YuScan service, an automated auditing tool designed to help banks and payment providers identify websites that conceal prohibited or high-risk activities. Since 2020 the system has processed more than 550,000 merchant applications without resulting in any fines for servicing illegal operations. YuScan builds comprehensive site maps, executes JavaScript, and handles dynamic content using Playwright combined with Camoufox to evade modern anti-bot protections such as Cloudflare. The crawler is built on Scrapy with FastAPI and PostgreSQL, then applies ML models, embeddings, and LLMs to analyze text, images, reviews, and external signals including Roskomnadzor registries and WHOIS data. The automation has reduced manual review time dramatically, allowing half of compliant merchants to begin accepting payments within 24 hours. YooKassa now offers the service to other banks through NSPK, the operator of the Mir payment system.

AntiMalwareFraud & Social Engineering

Scammers Pose as Employers to Remotely Lock iPhones and Demand Ransom

Russian police have warned of a new social engineering scheme in which fraudsters impersonate potential employers to gain control of victims' Apple devices. The attackers instruct targets to sign out of their personal Apple accounts and authenticate using credentials supplied by the supposed employer. Once the device links to the fraudster's account, the scammers can remotely lock the iPhone or iPad and demand payment for unlocking it. Authorities emphasize that paying the ransom does not guarantee recovery of the device and may lead to further extortion demands. Victims are advised never to enter third-party Apple credentials on personal hardware and to contact Apple Support with proof of purchase if a device is already locked. The scheme exploits the Find My and Activation Lock features built into iOS devices.