YooMoney's YuScan Automates E-commerce Risk Assessment Scanning Up to 1,000 Sites Per Hour
YooMoney has published a detailed technical overview of YuScan, its internal service for automated risk assessment of e-commerce websites. The tool helps banks and payment organizations detect merchants that attempt to mask prohibited or high-risk activities behind seemingly legitimate storefronts.
Since its launch in 2020, YuScan has analyzed more than 550,000 merchant applications. During this period YooKassa has not received any regulatory fines related to servicing prohibited business activities.
The service is intended for organizations that process over 10,000 pages daily, work with acquiring, marketplaces, KYC/AML checks, or must comply with Russian Federal Law 152-FZ. Manual analysis of such volumes quickly becomes a bottleneck, so YuScan was developed to perform deep, automated audits at scale.
From URL to Report in Minutes
YuScan starts from a merchant’s homepage and recursively crawls the entire site structure. It behaves like a real browser by executing JavaScript, waiting for dynamic elements, and scrolling through pages. This approach reveals content that would remain hidden under simple HTTP requests.
Asynchronous processing allows the system to handle up to 1,000 sites per hour. For modern sites that rely heavily on JavaScript, the crawler uses the Playwright library. When standard automation is blocked by advanced anti-bot systems such as Cloudflare, YuScan switches to Camoufox, which modifies browser behavior at the C/C++ level to produce cleaner fingerprints and avoid detection.
Technology Stack and Architecture
The service is written in Python. The API layer is built with FastAPI, data is stored in PostgreSQL, and the crawling core is based on the open-source Scrapy framework. Playwright handles browser automation while custom scaling and risk-scoring logic sit on top of Scrapy’s queue and pipeline system.
After data collection, multiple analysis stages begin. Text, images, reviews, external links, and registration details are examined. Images are converted into vector embeddings and compared against sensitive categories such as alcohol, tobacco, and online gambling. Large language models evaluate context to reduce false positives.
External Signals and Final Scoring
YuScan also checks whether a domain appears in Roskomnadzor registries, reviews third-party feedback, analyzes WHOIS records, and looks for signs of cloned or fraudulent sites. Extracted company details (INN, KPP, OGRN, contacts, and legal documents) help distinguish real businesses from temporary or opaque operations.
Since the introduction of automated checks, merchant onboarding times have improved significantly: simple cases are completed in under three hours, half of all companies begin processing payments within one day, and seven out of ten finish the process within two days.
Related articles
Free Robux Lures Used in Phishing Campaign Targeting Children's Messenger Accounts
Scammers have launched a new wave of attacks aimed at children and teenagers by promising free in-game currency for Roblox, Brawl Stars, and Standoff 2. The scheme, uncovered by specialists from F6, uses short YouTube videos that direct victims to phishing sites disguised as reward platforms. One prominent site branded as NovaDrop tricks users into selecting a messenger and game before presenting a rigged roulette that awards a fake prize of 25,000 coins. To claim the reward, victims must enter a phone number and six-digit verification code, which actually authorizes the attackers in the chosen messenger. Once inside, the criminals can read conversations, view documents and media, access contacts, and send messages to the victim's friends while sometimes remaining undetected. The attackers are increasingly focused on hijacking existing accounts due to difficulties in purchasing new Russian profiles for their operations.
Dynamic QR Codes Enable Personalized Redirects and Conceal Final Destinations
Dynamic QR codes printed on menus, receipts, and advertisements do not contain the final destination URL. Instead they point to an intermediary service that logs each scan and issues a redirect chosen at scan time. The redirect decision can depend on device model, language, IP address, country, and previous scans, allowing different users to receive entirely different pages. Owners can change the target after printing without replacing the physical code, creating risks when domains or accounts change hands. Each scan records time, device details, and approximate location, leaving a trail users did not consent to. Attackers exploit these properties with overlay stickers, QR codes inside documents that bypass email filters, and fake payment pages that request card details instead of processing a true QR payment.
Booking.com Security Overlooked Fake Downing Street Listing in Which? Fraud Test
Researchers from Which? successfully listed a fake apartment at 10 Downing Street on Booking.com to test the platform's fraud defenses. The listing included the exact address, photos of the UK Prime Minister's residence, and a description of a one-bedroom property near Parliament. Booking.com processed a payment for a week-long stay and failed to refund it even after more than six weeks. A fabricated positive review mentioning the official cat Larry was approved almost instantly. The platform also permitted a phishing link sent through its internal chat system asking for credit card details. The listing remained active from June 18 until its removal on August 27, prompting Which? to call for an Ofcom investigation into Booking.com's systemic security failures.
Password Spraying Campaign Targets AWS Root Accounts in Over 150 Organizations
A password spraying campaign targeted AWS root accounts across more than 150 organizations between July 24 and August 23, 2026. Attackers performed repeated login attempts against identities holding maximum privileges in the cloud environment. The root account is created with every AWS account and grants full access to resources, configurations, billing, and sensitive administrative functions. Researchers observed a median of two attempts per organization, with some targets receiving up to eight attempts. No successful authentications linked to the campaign have been identified so far. The attacks leveraged distributed proxies across multiple countries and networks, including hosting infrastructure and residential proxies, while using user agents that mimicked older versions of Microsoft Edge and Firefox. Since June 2025, AWS has required MFA for root users, significantly raising the bar for account takeover even if a password is discovered.