AntiMalwareAugust 14, 2026🇷🇺Translated from Russian

Scammers Target Remote Workers with Fake Compensation for Home Internet and Devices

Russian remote workers are facing targeted attacks from fraudsters who pose as employers, government agencies, or corporate IT departments. One common lure involves promises of compensation for home internet expenses and personal computer use. To claim these nonexistent payments, victims are directed to phishing sites for identity verification or asked to share SMS codes, according to Alexander Lunev, head of the information security training group at Yandex.

Instead of receiving funds, employees may unknowingly provide login credentials or payment information to attackers. The promised compensation turns out to be entirely remote, never reaching the victim's bank account. A separate scenario starts with emails claiming to come from a company's IT service, urging immediate renewal of system access, account confirmation, or installation of updates through provided links.

The sense of urgency is designed to prompt quick action before the recipient questions why a corporate administrator is contacting them from an unfamiliar address. Home networks add another layer of vulnerability, as users are responsible for their own router configurations unlike protected office setups. Multiple devices including work laptops, smartphones, cameras, smart TVs, and speakers often share the same router, meaning a single compromise can expose the entire household ecosystem.

Yandex specialist Alexander Lunev advises replacing default router and Wi-Fi passwords, applying firmware updates, and disabling quick device connection features. Smart devices should be moved to an isolated guest network separate from work computers. Any urgent requests should be verified through independent channels such as known phone numbers or corporate messengers. Legitimate companies, banks, and agencies never request passwords or SMS codes over the phone.

Related articles

AntiMalwareFraud & Social Engineering

Scammers Pose as Employers to Remotely Lock iPhones and Demand Ransom

Russian police have warned of a new social engineering scheme in which fraudsters impersonate potential employers to gain control of victims' Apple devices. The attackers instruct targets to sign out of their personal Apple accounts and authenticate using credentials supplied by the supposed employer. Once the device links to the fraudster's account, the scammers can remotely lock the iPhone or iPad and demand payment for unlocking it. Authorities emphasize that paying the ransom does not guarantee recovery of the device and may lead to further extortion demands. Victims are advised never to enter third-party Apple credentials on personal hardware and to contact Apple Support with proof of purchase if a device is already locked. The scheme exploits the Find My and Activation Lock features built into iOS devices.

Security NEXTFraud & Social Engineering

Phishing Reports Fall 42.6% in June While Abused URLs Rise 3.2%

The Phishing Countermeasures Council recorded 72,370 phishing reports in June 2026, a 42.6% drop from 126,061 reports the previous month. Despite the decline in reports, the number of malicious URLs increased to 42,241, up 3.2% from the prior month. More than 90% of the phishing emails received by the council's monitoring addresses used unique domains. The largest share of attacks targeted the EC sector at 42.7%, followed by credit and finance services at 27.4%. The council noted that this marks the second consecutive month of declining reports after a peak in April.

AntiMalwareFraud & Social Engineering

WhatsApp Begins Limited Beta Testing of On-Device Scam Alert to Detect Fraud While Preserving End-to-End Encryption

WhatsApp has started limited beta testing of its Scam Alert feature, which uses an on-device machine learning model to analyze message patterns and linguistic indicators of fraud. The system runs entirely locally on the user's smartphone, ensuring that conversation content is never sent to WhatsApp or Meta. Users receive warnings about suspicious messages from unknown contacts and can choose to block, report, ignore, or mark the chat as trusted. To maintain transparency, each model release is logged in an immutable journal managed by Cloudflare with Ed25519 signatures and SHA-256 hashes. The company receives only anonymized statistics on detections and user actions. In parallel, Signal has introduced automatic key verification using a cryptographically verifiable log audited by Cloudflare and Trail of Bits.

AntiMalwareFraud & Social Engineering

Google Chrome Blocks Over 7 Billion Unwanted Notifications Daily on Android

Google reported that its Chrome protection systems blocked more than 7 billion unwanted notifications every day on Android during the first quarter of 2026. Websites increasingly use browser notifications to deliver phishing attempts, fraudulent payment requests, and malware. Chrome applies a multi-layer "Swiss cheese" defense model where several overlapping filters compensate for each other's weaknesses. The browser automatically revokes notification permissions from sites that have not been visited recently or that trigger repeated security warnings, and it can also cancel associated subscriptions. For particularly noisy resources, Chrome enforces a hard limit of 1,000 messages per minute and returns HTTP 429 responses to excess traffic. Google also made permission prompts less intrusive on Android, which reduced background activity and improved battery life. Users can review and manage notification permissions through Safety Hub on both desktop and mobile versions of Chrome.