AntiMalwareJuly 12, 2026🇷🇺Translated from Russian

Scammers Impersonate Neighbors to Lure Residents into Fake Bomb Shelter Chat Groups for Data Theft

Scammers have developed a new social-engineering tactic that capitalizes on heightened public concern over safety by pretending to be neighbors and inviting people to join chat groups about equipping residential buildings with bomb shelters.

According to reports from the Telegram channel “Lapsa Media” and the author channel “Bez obmana” run by Alexander Yelshevsky, the fraudsters call residents and claim that an urgent meeting of building occupants is being organized to discuss the creation of a bomb shelter. The caller introduces himself as a neighbor, stresses the importance of the gathering, and urges the recipient to be added to a common chat so they can participate.

How the Scam Unfolds

Instead of discussing the supposed shelter, the conversation quickly shifts to requests for personal data. Victims are asked to provide their name, phone number, or other identifying information under the pretext of being added to the attendance list. The scammers further claim that without joining the chat and appearing on the list, the person will be unable to attend the meeting.

The fundamental flaw in the story is that residents cannot simply vote to establish a bomb shelter. Such facilities must be created in accordance with official state requirements and safety regulations. Therefore, any claim of an urgent neighbor meeting that cannot be accessed without handing over personal information to a stranger over the phone is itself a strong indicator of fraud.

Second Stage of the Scheme

If the target continues the conversation, a follow-up stage often occurs. The victim may later receive calls from individuals posing as government officials who state that the victim’s data has fallen into the hands of criminals. These callers then pressure the person to transfer money or perform other actions under the guise of protecting their information or resolving the issue.

Recognizing and Avoiding the Scam

  • The caller avoids any suggestion of an in-person meeting and insists on continuing the discussion exclusively by phone.
  • The conversation rapidly moves away from the supposed shelter topic toward requests for personal data.
  • The caller pressures the victim to join an unknown chat immediately.

Security experts advise ending such calls at once. Personal information should never be shared with strangers over the phone. If the caller is genuinely a neighbor, any legitimate issue can be discussed face-to-face within the building.

Related articles

BoletimSecFraud & Social Engineering

Cordial Spider Deploys Work Panel Platform for Tech Support Scams Against Corporate Identities

A criminal platform called Work Panel is turning fake technical support calls into structured operations aimed at taking over corporate accounts. The service combines target research, page cloning, telephony, and credential capture within a single control panel. It is linked to the group tracked as O-UNC-045, also known as Cordial Spider. Campaigns target users of multiple identity providers and combine telephone social engineering with fake authentication pages. Operators research names, job titles, corporate emails, phone numbers, and professional profiles before calling to impersonate help-desk staff. While one operator keeps the victim on the line, a manager monitors the phishing session in real time. Captured credentials are sent only to operation managers via Telegram, reducing internal theft risks among the criminals themselves.

AntiMalwareFraud & Social Engineering

Scammers Deploy Fake Russian Defense Ministry Websites to Harvest Data from Relatives of Fallen Soldiers

Russian threat intelligence firm F6 has uncovered a phishing campaign that used counterfeit Ministry of Defense portals to target relatives of participants in the special military operation. The attackers registered lookalike domains and populated them with official logos, coats of arms, and navigation menus copied from the legitimate mil.ru site, leaving only the registration form under their control. Victims were invited to register for state awards ceremonies and asked to supply full name, phone number, passport details, SNILS, and INN; an additional “Add guest” button collected the same information for accompanying persons. The stolen data can be used to reset access to government services, apply for microloans, or launch follow-on social-engineering attacks against military families. F6 analysts noted that the fraudulent pages were likely generated with a large language model, evidenced by an unhandled JSON error that appeared only after data submission. Although the discovered domains have been blocked inside Russia, the low technical barrier means new clones can be stood up quickly.

AntiMalwareFraud & Social Engineering

Russia to Launch Unified Payment Card Registry in 2026 to Combat Dropper Fraud Schemes

Starting September 1, 2026, Russia will introduce a single nationwide system for recording all payment cards issued by domestic banks. The registry will include every card regardless of the payment system used, covering existing Visa and Mastercard products as well as expired cards that banks continue to service. The measure is designed to give banks visibility into the total number of cards held by any individual across multiple institutions, thereby disrupting dropper schemes that rely on multiple accounts for laundering stolen funds. No immediate mass closure of cards will occur; instead, the first year will focus on data collection and preparation. From September 1, 2027, a hard limit of 20 cards per person will apply to new issuances only, while existing cards above the limit will remain operational. The policy grants individuals time to decide which cards they truly need before the issuance restriction takes effect.

AntiMalwareFraud & Social Engineering

Scammers Launch Fake Cyberpolice Russia Telegram Bot to Steal Accounts and Sell Fake Subscriptions

Fraudsters have created a counterfeit Telegram bot impersonating Russia's Cyberpolice, complete with official insignia and a convincing backstory. The bot promotes a paid subscription service for protection against cyber threats, essentially selling users defense against the scammers themselves. In a second attack vector, the bot requests a six-digit confirmation code, which grants attackers full access to the victim's Telegram account. Cyberpolice Russia has publicly stated that its units do not provide any paid services for threat notifications or protection. The legitimate bot operates under the exact handle cyberpolicerus_bot, and users are advised to verify the name character by character because scammers frequently alter letters or add symbols. Victims are reminded never to share six-digit Telegram codes with anyone, including entities claiming to represent law enforcement.