AntiMalwareJuly 12, 2026🇷🇺Translated from Russian

Scammers Impersonate Neighbors to Lure Residents into Fake Bomb Shelter Chat Groups for Data Theft

Scammers have developed a new social-engineering tactic that capitalizes on heightened public concern over safety by pretending to be neighbors and inviting people to join chat groups about equipping residential buildings with bomb shelters.

According to reports from the Telegram channel “Lapsa Media” and the author channel “Bez obmana” run by Alexander Yelshevsky, the fraudsters call residents and claim that an urgent meeting of building occupants is being organized to discuss the creation of a bomb shelter. The caller introduces himself as a neighbor, stresses the importance of the gathering, and urges the recipient to be added to a common chat so they can participate.

How the Scam Unfolds

Instead of discussing the supposed shelter, the conversation quickly shifts to requests for personal data. Victims are asked to provide their name, phone number, or other identifying information under the pretext of being added to the attendance list. The scammers further claim that without joining the chat and appearing on the list, the person will be unable to attend the meeting.

The fundamental flaw in the story is that residents cannot simply vote to establish a bomb shelter. Such facilities must be created in accordance with official state requirements and safety regulations. Therefore, any claim of an urgent neighbor meeting that cannot be accessed without handing over personal information to a stranger over the phone is itself a strong indicator of fraud.

Second Stage of the Scheme

If the target continues the conversation, a follow-up stage often occurs. The victim may later receive calls from individuals posing as government officials who state that the victim’s data has fallen into the hands of criminals. These callers then pressure the person to transfer money or perform other actions under the guise of protecting their information or resolving the issue.

Recognizing and Avoiding the Scam

  • The caller avoids any suggestion of an in-person meeting and insists on continuing the discussion exclusively by phone.
  • The conversation rapidly moves away from the supposed shelter topic toward requests for personal data.
  • The caller pressures the victim to join an unknown chat immediately.

Security experts advise ending such calls at once. Personal information should never be shared with strangers over the phone. If the caller is genuinely a neighbor, any legitimate issue can be discussed face-to-face within the building.

Related articles

AntiMalwareFraud & Social Engineering

BI.ZONE Mail Security 3.0 Enhances Detection of Password-Protected Archives and Spam Variants

BI.ZONE has released Mail Security 3.0, introducing new mechanisms to detect email threats and improved tools for administrators. The updated system now assigns additional risk scores to password-protected archives when their contents cannot be unpacked, without automatically classifying the archive itself as malicious. It also compares message texts to identify near-identical emails used in spam campaigns where attackers slightly alter wording to evade filters. Administrators can now incorporate SPF and DKIM verification results into delivery rules to better distinguish legitimate senders from impersonators. According to BI.ZONE statistics, phishing accounted for 90 percent of illegitimate email traffic in the first half of 2026. Additional protections include CAPTCHA challenges after repeated failed login attempts on administrative accounts. The release also adds bulk management of rules, improved logging with a side panel for message details, a new Events section, and Syslog export to external SIEM systems.

AntiMalwareFraud & Social Engineering

F6 and MAX Neutralize Over 2,550 External Phishing and Scam Resources in Two-Month Operation

F6 and the MAX messenger have jointly blocked more than 2,550 malicious external websites used for phishing, scams, and other forms of online fraud. The effort relied on the F6 Digital Risk Protection platform, which continuously scans for fake authentication pages and fraudulent resources targeting users. Monitoring took place during July and August 2026, after which experts from both organizations arranged for the sites to be taken down. The action focused exclusively on external resources and did not involve any malicious content hosted inside the MAX messenger itself. F6 Digital Risk Protection head Stanislav Goncharov noted that regular takedowns can reduce attacker activity over time, yet users must still verify website addresses manually before entering credentials or payment data.

HispasecFraud & Social Engineering

Trezor Warns of Email Provider Breach Used in Targeted Phishing Campaign Against Hardware Wallet Users

Trezor has disclosed that attackers compromised an external email provider and leveraged it to send phishing messages that appeared to originate from the company. The emails carried the subject line 'Critical Security Alert: STM32 Entropy Vulnerability' and falsely claimed a hardware flaw in STM32 microcontrollers that would reduce entropy and allow seed phrase reconstruction. No such CVE exists, and the campaign followed classic social-engineering patterns of urgency and brand impersonation aimed at stealing recovery phrases. Trezor has since disabled the malicious domain and continues investigating how the provider was accessed. Similar messages may have reached users of BitBox, suggesting possible compromise of shared service providers across the hardware wallet ecosystem. The incident underscores the difficulty of detecting phishing when it originates from legitimate third-party infrastructure.

AntiMalwareFraud & Social Engineering

Free Robux Lures Used in Phishing Campaign Targeting Children's Messenger Accounts

Scammers have launched a new wave of attacks aimed at children and teenagers by promising free in-game currency for Roblox, Brawl Stars, and Standoff 2. The scheme, uncovered by specialists from F6, uses short YouTube videos that direct victims to phishing sites disguised as reward platforms. One prominent site branded as NovaDrop tricks users into selecting a messenger and game before presenting a rigged roulette that awards a fake prize of 25,000 coins. To claim the reward, victims must enter a phone number and six-digit verification code, which actually authorizes the attackers in the chosen messenger. Once inside, the criminals can read conversations, view documents and media, access contacts, and send messages to the victim's friends while sometimes remaining undetected. The attackers are increasingly focused on hijacking existing accounts due to difficulties in purchasing new Russian profiles for their operations.