Protecting Your Credit History: How to Check for Unauthorized Microloans and Set Up Self-Bans in Russia
Russians typically learn about loans taken out in their name only after a bank refuses a new card or loan, at which point an unfamiliar debt appears in their credit report. Checking your credit history can be done online and free of charge. First, identify which credit bureaus hold your data, then download the reports and carefully examine all contracts, applications, and creditor requests instead of stopping at the credit score. If you do not plan to take out loans soon, it makes sense to immediately place a self-ban, which makes it significantly harder for fraudsters to obtain credit using your personal data.
Where to Check Your Credit History
There is no single centralized database. Banks, microfinance organizations, and other lenders send data to different credit bureaus, and it is impossible to know in advance which ones hold your information. The list of bureaus storing your credit history is provided by the Central Catalogue of Credit Histories (CCCH) of the Bank of Russia.
Through Gosuslugi, the entire process takes just a few minutes. Open the service for obtaining information from the CCCH, verify your passport details, submit the request, and receive the list of bureaus. Without a Gosuslugi account, you can use the Bank of Russia section “How to find out your credit history,” though this requires a credit history subject code.
Obtain bureau addresses from the official state register maintained by the Bank of Russia, as the list changes periodically and search engines may return outdated information. While major players such as NBKI and United Credit Bureau are well-known, you must check every bureau listed in the CCCH response. In each bureau’s personal account, download the report in PDF format. The electronic version is free twice a year, while the paper version is available once.
What to Look for in Your Credit Report
The credit score reduces your entire history to a single number and explains nothing. Protection against fraud comes from other sections that list contracts, applications, and creditor inquiries. These sections show who accessed your history, which contracts remain open, and where delinquencies exist. For every entry, verify the creditor, date, amount, obligation number, and last update date.
An unfamiliar microloan of just a few thousand rubles is not a minor issue, as fraud chains often begin with small amounts. Pay special attention to the inquiries block. If multiple lenders requested your report on the same day without your involvement, change passwords immediately, check Gosuslugi, and activate a self-ban.
| What was found | What it means | What to do |
|---|---|---|
| Unknown loan or microloan | Fraud or error | Save the report, contact the creditor, file a police report |
| Multiple MFO applications in one day | Someone was shopping for a loan | Check accounts, SIM card, email, enable self-ban |
| Closed loan still shown as active | Creditor failed to update data | Request closure certificate and dispute the record |
| Delinquency that never occurred | Payment accounting error | Prepare receipts and request correction |
| Inquiry from unknown creditor | Application made without your participation | Check all bureaus and change passwords |
Self-Ban on Loans: How to Activate It and When It Helps
A self-ban is recommended for anyone who does not intend to take out credit or microloans in the near future. From 1 March 2025, it can be issued via Gosuslugi; from 1 September 2025, also through MFC. After submission, a mark appears in your credit history, and banks and MFOs must reject applications while the ban remains active.
If a lender issues funds despite an active ban, the contract is concluded in violation of the law. The creditor acquires no rights to demand repayment, the borrower is not obliged to return the money, and the record is removed from the history even if the debt has already been sold.
Through Gosuslugi you can choose a full or partial ban. A full ban blocks consumer loans and borrowings from banks and MFOs. A partial ban can be configured more precisely, for example, prohibiting only remote applications while allowing in-person applications at branches. Mortgages, car loans secured by the vehicle, state-supported education loans, suretyship, transactions on already opened cards, and repayment of existing debts are not covered. Existing loans do not need to be closed to activate the self-ban.
The ban takes effect the day after the mark appears in the history, and it can only be lifted on the second calendar day Moscow time. This one- or two-day pause disrupts telephone scams that pressure victims into making “safe” transfers or urgent loans before they change their minds.
Pre-Travel Security Checks
During travel, control over documents and communications weakens. Passport scans may be sent in chats, phones can be lost, and hotel Wi-Fi is often open. The Russian self-ban does not apply to foreign banks, but access to domestic banks, Gosuslugi, and SIM cards remains vulnerable. After intercepting these, fraudsters can operate remotely regardless of your physical location.
Before departure, download your credit reports, activate a self-ban, and enable bank notifications. Verify logins to Gosuslugi, email, and banks. For international travel, confirm that SMS messages arrive in roaming. Review the security section of Gosuslugi for activity history and close unknown sessions. Do not leave passport scans in open chats. Avoid accessing credit bureaus, banks, or Gosuslugi from other people’s devices or unsecured Wi-Fi. If you lose your passport, immediately report it to the police and keep the confirmation. If your phone is lost, block the SIM card and active sessions, then download a fresh report upon return.
What to Do If Fraudsters Have Already Taken Out a Loan
Disputes are won with documents, not phone calls to call centers. The earlier written evidence appears, the stronger your position.
- Download reports from all your credit bureaus, save the PDFs and screenshots of disputed entries, and note the creditor, contract date, amount, and obligation number.
- Submit a written statement to the creditor denying the contract and receipt of funds, and request an investigation including signing method, phone number, disbursement details, and IP addresses. If you were in another city that day, attach tickets, bookings, and receipts.
- File a police report in person at an МВД department, via the agency’s website, or by calling 102 (not 112, which is for emergencies). Keep the notification coupon.
- Dispute the record through the credit bureau free of charge. The bureau must provide a reasoned response within 20 working days; direct contact with the creditor requires a response within 10 days.
- If the creditor remains silent, file a complaint via the Bank of Russia internet reception. If enforcement proceedings begin, check the FSSP database of enforcement proceedings.
Note that the FSSP database does not show recent loans and applications; it is useful only after the dispute reaches court or enforcement proceedings.
Paying someone else’s debt “to make them stop” is tempting but almost always harmful. Payment complicates the dispute and may be viewed by the creditor as acknowledgment of the debt. Written statements and persistent correction of the record are far more effective.
Protection Checklist
Credit fraud rarely relies on a single vulnerability; usually several gaps coincide. Therefore, protection depends on consistent habits rather than one-time settings.
- Check your credit history twice a year at every bureau and additionally after losing a passport, phone, or SIM card.
- Activate a self-ban if you do not currently need credit.
- Use different passwords for email, Gosuslugi, banks, and mobile operators, and enable two-factor authentication everywhere it is available.
- Periodically review the Gosuslugi security section and activity history.
- Never dictate SMS codes or card details over the phone or send passport photos to unverified chats.
- Store document copies in a secure location and update bank records immediately after changing your passport.
Related articles
Google Quietly Rolls Out Android Developer Verifier App to Curb APK Sideloading Fraud
Android users are discovering a new system application called Android Developer Verifier with the package identifier com.google.android.verifier that Google installs automatically through system updates without any separate consent prompt. The service prepares devices for upcoming restrictions on installing APK files from unknown sources by checking whether an app is registered to a verified developer who has passed identity verification and supplied legal information to Google. This verification does not guarantee an application is safe but allows Google to associate it with a specific individual or company, helping combat social-engineering scams in which fraudsters pressure victims into disabling protections and installing malicious APKs. To install software from an unverified developer, users will need to enable developer mode, confirm they are not under duress, reboot the device, wait 24 hours, and re-authenticate with PIN or biometrics. The new requirements begin on 30 September in Brazil, Indonesia, Singapore, and Thailand, with worldwide expansion planned for 2027 and later. While the app can currently be removed, it is unclear whether future updates will restore it, and advanced users retain the option to sideload via ADB, which bypasses the new checks entirely.
Aurorium Anti-Detect Browser Uses AI Fingerprinting Linked to Real Hardware and User Profiles to Evade Modern Anti-Fraud Systems
Aurorium is an anti-detect browser that differentiates itself from competitors by embedding spoofing directly into the browser kernel rather than relying on JavaScript patches. The product generates fingerprints using AI that analyzes the operator’s actual device hardware and matches it to a realistic social profile including age, income, occupation, and geography. Network routing is handled at the kernel level so that WebRTC and DNS traffic is forced through proxies without disabling features that anti-fraud systems flag. The company also published a detailed Cure53 security audit that identified and subsequently fixed four critical vulnerabilities. Team-oriented features include built-in CRM, task management, multi-team support, and a mobile application. The review highlights that Aurorium’s approach reduces the common mismatch between generated fingerprints and the supposed user’s real-world context that often triggers detection.
CACTER Upgrades PhishSim Anti-Phishing Simulation System to Help Enterprises Reduce Phishing Risks in Four Easy Steps
CACTER has released an updated version of its PhishSim anti-phishing drill system designed to replace traditional theoretical training with realistic, immersive phishing simulations. The platform can replicate common attack vectors including fake links, malicious attachments, and disguised QR codes while impersonating legitimate senders and official domains to mimic both APT and spear-phishing campaigns. Organizations using the system have reportedly lowered their average employee click rate from 23.88% to 4.16% through regular, customized exercises. Key features include a continuously updated template library tailored to specific industries and business scenarios, automated visual reports that rank departments and classify employee risk levels, and actionable remediation recommendations. The entire workflow is completed in just four steps—selecting templates, grouping employees, launching drills, and reviewing reports—allowing companies to run ongoing training without dedicated security specialists. The solution emphasizes measurable results and a closed-loop process of simulation, analysis, and improvement to strengthen email security posture.
Dutch Police Arrest Leader of 700-Person Investment Scam Network That Stole Over €100 Million Monthly
Dutch authorities have arrested the suspected leader of a massive international investment fraud operation that employed more than 700 people across roughly 20 offices in multiple countries. The 46-year-old Israeli-Polish citizen, described as a known hacker, was detained in Poland while traveling from Dubai and later extradited to the Netherlands. The group posed as financial consultants, using fake trading platforms to convince victims to invest increasingly large sums, primarily in cryptocurrency, while never actually placing the funds. Victims in the Netherlands alone reported nearly €25 million in losses across 550 complaints, with many losing over €10,000 and suffering severe consequences including inability to buy food and suicidal thoughts. Additional arrests occurred in Belgium, Cyprus, and Greece, while Europol assisted in disrupting the network's infrastructure and identifying further suspects.