AntiMalwareJuly 27, 2026🇷🇺Translated from Russian

Beeline Subscribers Targeted in Mass SIM Hijacking via Remote eSIM Issuance

Beeline subscribers have reported mass attempts to hijack their mobile numbers through the remote issuance of eSIM cards. According to Kommersant FM, fraudsters needed only one careless confirmation from the user to complete the attack.

The scheme appeared highly convincing: a system-level prompt appeared on the smartphone screen requesting login to the operator's personal account. This was neither an SMS nor a standard push notification. Once the confirmation button was pressed, a message followed about the issuance of a virtual SIM card. The physical SIM was simultaneously blocked, transferring control of the number to the attackers.

One victim was Kommersant FM editor-in-chief Vladislav Viktorov. IT specialist Alexander Baulin suggested the attack might involve a breach of the operator's infrastructure, but Beeline did not confirm this version.

The company informed Kod Durova about a coordinated attack on mechanisms for remote SIM issuance and replacement. Over several days, fraudsters changed tactics and sent thousands of requests. Beeline claims the attack was repelled and successful hijackings remained isolated. Affected subscribers are receiving assistance to restore service.

According to the operator, similar attacks since the beginning of the year have affected the entire telecom market. Subscribers are advised not to confirm operations they did not initiate, not to share SMS codes, and to contact support immediately for suspicious requests.

Number hijacking goes beyond sudden loss of network signal. With control of the SIM, fraudsters can attempt to restore access to banking applications, Gosuslugi, and other services. Users should therefore read any system notification carefully, as one accidental tap can hand the number to an unauthorized party.

Related articles

AntiMalwareFraud & Social Engineering

Booking.com Security Overlooked Fake Downing Street Listing in Which? Fraud Test

Researchers from Which? successfully listed a fake apartment at 10 Downing Street on Booking.com to test the platform's fraud defenses. The listing included the exact address, photos of the UK Prime Minister's residence, and a description of a one-bedroom property near Parliament. Booking.com processed a payment for a week-long stay and failed to refund it even after more than six weeks. A fabricated positive review mentioning the official cat Larry was approved almost instantly. The platform also permitted a phishing link sent through its internal chat system asking for credit card details. The listing remained active from June 18 until its removal on August 27, prompting Which? to call for an Ofcom investigation into Booking.com's systemic security failures.

BoletimSecFraud & Social Engineering

Password Spraying Campaign Targets AWS Root Accounts in Over 150 Organizations

A password spraying campaign targeted AWS root accounts across more than 150 organizations between July 24 and August 23, 2026. Attackers performed repeated login attempts against identities holding maximum privileges in the cloud environment. The root account is created with every AWS account and grants full access to resources, configurations, billing, and sensitive administrative functions. Researchers observed a median of two attempts per organization, with some targets receiving up to eight attempts. No successful authentications linked to the campaign have been identified so far. The attacks leveraged distributed proxies across multiple countries and networks, including hosting infrastructure and residential proxies, while using user agents that mimicked older versions of Microsoft Edge and Firefox. Since June 2025, AWS has required MFA for root users, significantly raising the bar for account takeover even if a password is discovered.

AntiMalwareFraud & Social Engineering

Unsolicited iPhone 15 Pro Max Delivery to Reddit User Sparks Fears of Targeted Cyber Attack

A Reddit user received an unexpected iPhone 15 Pro Max in a sealed box that was never ordered. Apple’s service identified the serial number as belonging to a device purchased or activated in December 2023, with its warranty already expired in 2024, creating a clear mismatch between the new-looking packaging and the device’s documented history. The included FedEx label contained a tracking number that does not exist in the carrier’s system. Discussion on the platform raised the possibility of a targeted attack, potentially a form of whaling, in which the phone could have been pre-modified to steal data or credentials once connected to a network or Apple ID. No concrete evidence confirms the package originated from an attacker, and alternative explanations such as a delivery error or order fraud remain possible. Experts recommend that recipients avoid powering on the device, inserting a SIM card, or entering any account credentials, and instead consider returning it to Apple for inspection or disposing of it as electronic waste.

AntiMalwareFraud & Social Engineering

Scammers Embed Phishing Inside Telegram Mini Apps After August Update

Cybercriminals are increasingly abusing Telegram's Mini Apps and WebView features to deliver phishing attacks that mimic legitimate banking, payment, and cryptocurrency services. Following the platform update on August 25, attackers can now present fake interfaces for transfers, airdrops, and voting systems directly inside the messenger. Victims are tricked into entering confirmation codes, connecting wallets, or pasting commands into PowerShell under the guise of fixing errors or claiming bonuses. The attacks rely heavily on social engineering rather than automated malware, requiring users to actively authorize actions such as signing transactions or providing phone verification details. Fake voting schemes are used to harvest account credentials, while crypto-related lures prompt users to link wallets to malicious services. Experts emphasize that simply opening a Mini App does not lead to immediate theft, but authorizing or connecting assets does expose users to significant risk.