SecuritylabJuly 20, 2026🇷🇺Translated from Russian

Protecting Your Credit History: How to Check for Unauthorized Microloans and Set Up Self-Bans in Russia

Russians typically learn about loans taken out in their name only after a bank refuses a new card or loan, at which point an unfamiliar debt appears in their credit report. Checking your credit history can be done online and free of charge. First, identify which credit bureaus hold your data, then download the reports and carefully examine all contracts, applications, and creditor requests instead of stopping at the credit score. If you do not plan to take out loans soon, it makes sense to immediately place a self-ban, which makes it significantly harder for fraudsters to obtain credit using your personal data.

Where to Check Your Credit History

There is no single centralized database. Banks, microfinance organizations, and other lenders send data to different credit bureaus, and it is impossible to know in advance which ones hold your information. The list of bureaus storing your credit history is provided by the Central Catalogue of Credit Histories (CCCH) of the Bank of Russia.

Through Gosuslugi, the entire process takes just a few minutes. Open the service for obtaining information from the CCCH, verify your passport details, submit the request, and receive the list of bureaus. Without a Gosuslugi account, you can use the Bank of Russia section “How to find out your credit history,” though this requires a credit history subject code.

Obtain bureau addresses from the official state register maintained by the Bank of Russia, as the list changes periodically and search engines may return outdated information. While major players such as NBKI and United Credit Bureau are well-known, you must check every bureau listed in the CCCH response. In each bureau’s personal account, download the report in PDF format. The electronic version is free twice a year, while the paper version is available once.

What to Look for in Your Credit Report

The credit score reduces your entire history to a single number and explains nothing. Protection against fraud comes from other sections that list contracts, applications, and creditor inquiries. These sections show who accessed your history, which contracts remain open, and where delinquencies exist. For every entry, verify the creditor, date, amount, obligation number, and last update date.

An unfamiliar microloan of just a few thousand rubles is not a minor issue, as fraud chains often begin with small amounts. Pay special attention to the inquiries block. If multiple lenders requested your report on the same day without your involvement, change passwords immediately, check Gosuslugi, and activate a self-ban.

What was foundWhat it meansWhat to do
Unknown loan or microloanFraud or errorSave the report, contact the creditor, file a police report
Multiple MFO applications in one daySomeone was shopping for a loanCheck accounts, SIM card, email, enable self-ban
Closed loan still shown as activeCreditor failed to update dataRequest closure certificate and dispute the record
Delinquency that never occurredPayment accounting errorPrepare receipts and request correction
Inquiry from unknown creditorApplication made without your participationCheck all bureaus and change passwords

Self-Ban on Loans: How to Activate It and When It Helps

A self-ban is recommended for anyone who does not intend to take out credit or microloans in the near future. From 1 March 2025, it can be issued via Gosuslugi; from 1 September 2025, also through MFC. After submission, a mark appears in your credit history, and banks and MFOs must reject applications while the ban remains active.

If a lender issues funds despite an active ban, the contract is concluded in violation of the law. The creditor acquires no rights to demand repayment, the borrower is not obliged to return the money, and the record is removed from the history even if the debt has already been sold.

Through Gosuslugi you can choose a full or partial ban. A full ban blocks consumer loans and borrowings from banks and MFOs. A partial ban can be configured more precisely, for example, prohibiting only remote applications while allowing in-person applications at branches. Mortgages, car loans secured by the vehicle, state-supported education loans, suretyship, transactions on already opened cards, and repayment of existing debts are not covered. Existing loans do not need to be closed to activate the self-ban.

The ban takes effect the day after the mark appears in the history, and it can only be lifted on the second calendar day Moscow time. This one- or two-day pause disrupts telephone scams that pressure victims into making “safe” transfers or urgent loans before they change their minds.

Pre-Travel Security Checks

During travel, control over documents and communications weakens. Passport scans may be sent in chats, phones can be lost, and hotel Wi-Fi is often open. The Russian self-ban does not apply to foreign banks, but access to domestic banks, Gosuslugi, and SIM cards remains vulnerable. After intercepting these, fraudsters can operate remotely regardless of your physical location.

Before departure, download your credit reports, activate a self-ban, and enable bank notifications. Verify logins to Gosuslugi, email, and banks. For international travel, confirm that SMS messages arrive in roaming. Review the security section of Gosuslugi for activity history and close unknown sessions. Do not leave passport scans in open chats. Avoid accessing credit bureaus, banks, or Gosuslugi from other people’s devices or unsecured Wi-Fi. If you lose your passport, immediately report it to the police and keep the confirmation. If your phone is lost, block the SIM card and active sessions, then download a fresh report upon return.

What to Do If Fraudsters Have Already Taken Out a Loan

Disputes are won with documents, not phone calls to call centers. The earlier written evidence appears, the stronger your position.

  • Download reports from all your credit bureaus, save the PDFs and screenshots of disputed entries, and note the creditor, contract date, amount, and obligation number.
  • Submit a written statement to the creditor denying the contract and receipt of funds, and request an investigation including signing method, phone number, disbursement details, and IP addresses. If you were in another city that day, attach tickets, bookings, and receipts.
  • File a police report in person at an МВД department, via the agency’s website, or by calling 102 (not 112, which is for emergencies). Keep the notification coupon.
  • Dispute the record through the credit bureau free of charge. The bureau must provide a reasoned response within 20 working days; direct contact with the creditor requires a response within 10 days.
  • If the creditor remains silent, file a complaint via the Bank of Russia internet reception. If enforcement proceedings begin, check the FSSP database of enforcement proceedings.

Note that the FSSP database does not show recent loans and applications; it is useful only after the dispute reaches court or enforcement proceedings.

Paying someone else’s debt “to make them stop” is tempting but almost always harmful. Payment complicates the dispute and may be viewed by the creditor as acknowledgment of the debt. Written statements and persistent correction of the record are far more effective.

Protection Checklist

Credit fraud rarely relies on a single vulnerability; usually several gaps coincide. Therefore, protection depends on consistent habits rather than one-time settings.

  • Check your credit history twice a year at every bureau and additionally after losing a passport, phone, or SIM card.
  • Activate a self-ban if you do not currently need credit.
  • Use different passwords for email, Gosuslugi, banks, and mobile operators, and enable two-factor authentication everywhere it is available.
  • Periodically review the Gosuslugi security section and activity history.
  • Never dictate SMS codes or card details over the phone or send passport photos to unverified chats.
  • Store document copies in a secure location and update bank records immediately after changing your passport.

Related articles

HabrFraud & Social Engineering

Behavioral Anti-Fraud: How Systems Analyze User Actions Beyond Device and Browser Fingerprints

Anti-fraud systems are shifting from static device and browser fingerprinting toward continuous behavioral analysis powered by machine learning. The article explains why matching User-Agent strings with Canvas or font rendering is no longer sufficient, as bot developers can easily synchronize these static signals. Modern defenses now record dozens of micro-events during a session, including keystroke timing, mouse trajectories, scroll speed, and focus changes, to build a dynamic Trust Score. These models are trained on large clusters of real-user behavior and flag sessions whose patterns fall outside legitimate clusters even when fingerprints appear realistic. The text details dwell time, flight time, error-correction patterns, natural hand tremor, and acceleration curves governed by Fitts’s law as key biometric markers. It also covers browser-level signals such as Event.isTrusted, CDP artifacts, and navigator.webdriver flags that reveal automation frameworks. The discussion extends to mobile sensors and concludes that perfectly error-free, mathematically smooth input is itself a strong indicator of synthetic activity.

BoletimSecFraud & Social Engineering

Free Online Panel Examines Rising Omnichannel Scams and Multichannel Fraud Tactics

The Brazilian human risk management firm Eskive is hosting its third free online panel on August 18 at 11 a.m. to address the growing threat of omnichannel cyber fraud. Experts will discuss how attackers combine multiple channels such as email, SMS, and other vectors to create more convincing social-engineering narratives that bypass traditional single-channel defenses. The event will feature CEO Priscila Meyer as moderator along with cyber threat intelligence specialist Thiago Bordini and Santa Catarina Civil Police investigator Elias Edenis. Participants will gain practical insights from real client simulations, live Q&A sessions, and interactive quizzes designed to improve organizational preparedness. The panel aims to highlight why users accustomed to recognizing basic phishing or smishing attempts remain vulnerable when fraudsters deploy coordinated, multi-channel campaigns.

BoletimSecFraud & Social Engineering

OpenAI Disables Coordinated ChatGPT Network Used for Financial Scams and Identity Forgery

OpenAI has deactivated a coordinated network of ChatGPT accounts that supported financial fraud, romance scams, and identity forgery operations. Criminals leveraged the AI to generate fake personas, translate conversations, and craft targeted messages aimed at victims across multiple schemes. The investigation originated from reports of suspicious activity observed on WhatsApp. Scammers used the tool to produce forged documents including stock confirmations, legal notices, passports, and fake financial interfaces to increase credibility. Operations typically began on social media or messaging apps, building emotional trust or urgency before requesting deposits, activation fees, or nonexistent fines. Indicators of possible human trafficking and forced labor were also uncovered through job advertisements and internal discussions about worker control in Poipet. OpenAI has blocked the accounts and shared operational indicators with law enforcement and technology companies.

AntiMalwareFraud & Social Engineering

Positive Technologies Uncovers Disinformation Factory Linking 45 Domains and 74 Telegram Channels

Researchers at Positive Technologies have exposed an integrated disinformation operation that combined fake government emails with a network of pseudo-news websites and synchronized social media channels. The campaign began with emails sent from lookalike domains such as minpromtorg.digital and gosuslugi.digital, requesting employee lists and salary data to prepare targeted phishing attacks. Parallel to the email activity, operators maintained at least 45 domains including rulenta.live and crime24.live that mixed genuine stories with fabricated content and cited nonexistent sources. These sites were amplified through dozens of Telegram channels and accounts on VKontakte, Odnoklassniki, YouTube, Instagram, and TikTok, creating a self-reinforcing loop where fabricated claims were quoted back as credible reporting. Investigators noted a possible infrastructure overlap with the cybercriminal group Rare Werewolf, although direct attribution remains unconfirmed. The operation demonstrates a complete information pipeline from initial reconnaissance via email to wide distribution of disinformation across multiple platforms.