AntiMalwareJuly 27, 2026🇷🇺Translated from Russian

Beeline Subscribers Targeted in Mass SIM Hijacking via Remote eSIM Issuance

Beeline subscribers have reported mass attempts to hijack their mobile numbers through the remote issuance of eSIM cards. According to Kommersant FM, fraudsters needed only one careless confirmation from the user to complete the attack.

The scheme appeared highly convincing: a system-level prompt appeared on the smartphone screen requesting login to the operator's personal account. This was neither an SMS nor a standard push notification. Once the confirmation button was pressed, a message followed about the issuance of a virtual SIM card. The physical SIM was simultaneously blocked, transferring control of the number to the attackers.

One victim was Kommersant FM editor-in-chief Vladislav Viktorov. IT specialist Alexander Baulin suggested the attack might involve a breach of the operator's infrastructure, but Beeline did not confirm this version.

The company informed Kod Durova about a coordinated attack on mechanisms for remote SIM issuance and replacement. Over several days, fraudsters changed tactics and sent thousands of requests. Beeline claims the attack was repelled and successful hijackings remained isolated. Affected subscribers are receiving assistance to restore service.

According to the operator, similar attacks since the beginning of the year have affected the entire telecom market. Subscribers are advised not to confirm operations they did not initiate, not to share SMS codes, and to contact support immediately for suspicious requests.

Number hijacking goes beyond sudden loss of network signal. With control of the SIM, fraudsters can attempt to restore access to banking applications, Gosuslugi, and other services. Users should therefore read any system notification carefully, as one accidental tap can hand the number to an unauthorized party.

Related articles

AntiMalwareFraud & Social Engineering

Yandex Rolls Out Universal Anti-Fraud Platform to Block Bots and Manipulation Schemes

Yandex has begun deploying its Universal Anti-Fraud system, a single AI-driven platform designed to detect bots, ticket scalping, and other forms of digital fraud across multiple services. The new solution can be integrated into a service within two to four days, replacing the previous months-long process of building separate defenses for each product. Dozens of Yandex services, including Eda, Afisha, Puteshestviya, and applications powered by Alice, are already connected to the platform. In Afisha the system identifies bots that mass-book tickets for popular events to create artificial scarcity, while in Eda it flags repeated fraudulent complaints aimed at obtaining compensation. The platform combines neural networks, analytical methods, and more than one hundred attack-pattern rules, analyzing traffic in real time and applying service-specific parameters. A key advantage is centralized updating: once a new fraud scheme is identified, protections are distributed instantly to all connected products.

HabrFraud & Social Engineering

Protecting C-Suite Leaders: Defending Executives Against Targeted Cyberattacks

According to PT EdTechLab data, 12% of registered data leaks in Russia originate from attacks on top management. Executives often combine maximum privileges with lax cyber hygiene and public visibility, creating high-value targets. The article outlines three primary attack scenarios: targeted whaling phishing with deepfakes, compromise of personal devices used for both work and private tasks, and account takeover via weak passwords or SIM swapping. Detailed recommendations include mandatory multi-factor authentication, separate corporate devices or MDM solutions, EDR coverage, strict password policies, and network segmentation. The piece stresses that technical measures must be paired with direct communication using business impact language to secure executive buy-in and set an example for the wider organization.

Security NEXTFraud & Social Engineering

IPA Reports Record High Fake Warning Scam Consultations in Q2 2026

The Information Processing Promotion Agency (IPA) recorded 3,832 personal security consultations in the second quarter of 2026, marking an 8.5 percent increase from the previous quarter. Fake warning scams, which display fabricated malware alerts to frighten users into contacting fraudsters, rose sharply to 1,428 cases, a 23.7 percent jump and the highest figure in two years. These scams carry risks of financial loss and device compromise through fake support services. Consultations dipped temporarily after arrests in May 2025 but have now exceeded levels seen before those arrests. Phishing reports also increased slightly to 146 cases, including schemes impersonating the National Tax Agency. The trend of rising fake warning incidents has continued for three consecutive quarters, underscoring the need for ongoing public vigilance.

AntiMalwareFraud & Social Engineering

macOS Users Encounter Phishing and Scams More Often Than Windows Users but Adopt Fewer Protections, Kaspersky Study Reveals

A new study from Kaspersky Lab shows that macOS users report higher rates of phishing encounters and various scams compared to Windows users, yet they are less likely to implement basic security measures. Over the past year, 12 percent of macOS users faced phishing attempts versus 9 percent of Windows users, while 16 percent encountered investment fraud schemes compared to 13 percent. Privacy violations and personal data theft were also reported more frequently by Mac owners at 11 percent and 12 percent respectively, against 8 percent and 7 percent for Windows. Security habits differ notably, with only 51 percent of macOS users avoiding suspicious links and emails versus 62 percent of Windows users, and just 35 percent installing additional protection tools compared to 42 percent. Password practices and multi-factor authentication usage follow the same pattern, with Mac users trailing in creating unique or complex passwords and enabling 2FA. Kaspersky notes that while macOS built-in defenses handle many threats effectively, they offer limited protection against social engineering and platform-specific attacks, underscoring that the Apple brand does not serve as automatic security.