AntiMalwareAugust 3, 2026🇷🇺Translated from Russian

Russian Interior Ministry Advises Citizens Against Posting Personal Dossiers on Social Media

The Ministry of Internal Affairs of Russia has called on citizens to share fewer details about themselves and their relatives on social networks. Information such as places of study and employment, home addresses, and family details should be kept out of public profiles.

As reported by RIA Novosti citing official ministry materials, a comprehensive digital self-portrait can attract the interest of recruiters and fraudsters. Collected data enables them to analyze potential targets, locate weak points, and develop tailored interaction scripts designed to exploit trust.

The MVD further advises against conducting detailed public discussions of personal opinions and against responding to personal questions from unknown individuals. Before any conversation, users should verify the ownership of the profile in question. If a contact raises suspicions, the recommendation is to add the account to a blacklist and simultaneously file a complaint with the platform moderators.

This is not the first warning issued by the ministry on the topic. In October 2025 the MVD reminded the public that published personal data can become a valuable resource for fraudsters. Russians were urged not to publish full names, dates of birth, or any information that could be used to compile additional details about an individual.

Social networks have long ceased to function merely as collections of vacation photographs. For an attacker they represent a ready-made questionnaire revealing where a person lives, works, studies, whom they communicate with, and what they trust. The guiding principle remains straightforward: the less strangers know about a person’s life, the more difficult it becomes to construct a personalized scenario of deception or recruitment.

Related articles

BoletimSecFraud & Social Engineering

Cordial Spider Deploys Work Panel Platform for Tech Support Scams Against Corporate Identities

A criminal platform called Work Panel is turning fake technical support calls into structured operations aimed at taking over corporate accounts. The service combines target research, page cloning, telephony, and credential capture within a single control panel. It is linked to the group tracked as O-UNC-045, also known as Cordial Spider. Campaigns target users of multiple identity providers and combine telephone social engineering with fake authentication pages. Operators research names, job titles, corporate emails, phone numbers, and professional profiles before calling to impersonate help-desk staff. While one operator keeps the victim on the line, a manager monitors the phishing session in real time. Captured credentials are sent only to operation managers via Telegram, reducing internal theft risks among the criminals themselves.

AntiMalwareFraud & Social Engineering

Scammers Deploy Fake Russian Defense Ministry Websites to Harvest Data from Relatives of Fallen Soldiers

Russian threat intelligence firm F6 has uncovered a phishing campaign that used counterfeit Ministry of Defense portals to target relatives of participants in the special military operation. The attackers registered lookalike domains and populated them with official logos, coats of arms, and navigation menus copied from the legitimate mil.ru site, leaving only the registration form under their control. Victims were invited to register for state awards ceremonies and asked to supply full name, phone number, passport details, SNILS, and INN; an additional “Add guest” button collected the same information for accompanying persons. The stolen data can be used to reset access to government services, apply for microloans, or launch follow-on social-engineering attacks against military families. F6 analysts noted that the fraudulent pages were likely generated with a large language model, evidenced by an unhandled JSON error that appeared only after data submission. Although the discovered domains have been blocked inside Russia, the low technical barrier means new clones can be stood up quickly.

AntiMalwareFraud & Social Engineering

Russia to Launch Unified Payment Card Registry in 2026 to Combat Dropper Fraud Schemes

Starting September 1, 2026, Russia will introduce a single nationwide system for recording all payment cards issued by domestic banks. The registry will include every card regardless of the payment system used, covering existing Visa and Mastercard products as well as expired cards that banks continue to service. The measure is designed to give banks visibility into the total number of cards held by any individual across multiple institutions, thereby disrupting dropper schemes that rely on multiple accounts for laundering stolen funds. No immediate mass closure of cards will occur; instead, the first year will focus on data collection and preparation. From September 1, 2027, a hard limit of 20 cards per person will apply to new issuances only, while existing cards above the limit will remain operational. The policy grants individuals time to decide which cards they truly need before the issuance restriction takes effect.

AntiMalwareFraud & Social Engineering

Scammers Launch Fake Cyberpolice Russia Telegram Bot to Steal Accounts and Sell Fake Subscriptions

Fraudsters have created a counterfeit Telegram bot impersonating Russia's Cyberpolice, complete with official insignia and a convincing backstory. The bot promotes a paid subscription service for protection against cyber threats, essentially selling users defense against the scammers themselves. In a second attack vector, the bot requests a six-digit confirmation code, which grants attackers full access to the victim's Telegram account. Cyberpolice Russia has publicly stated that its units do not provide any paid services for threat notifications or protection. The legitimate bot operates under the exact handle cyberpolicerus_bot, and users are advised to verify the name character by character because scammers frequently alter letters or add symbols. Victims are reminded never to share six-digit Telegram codes with anyone, including entities claiming to represent law enforcement.