How a Decade-Long Fraud Campaign Cloned Russian Company Sites to Steal Payments

ยท
Listen to this article~5 min
How a Decade-Long Fraud Campaign Cloned Russian Company Sites to Steal Payments

A nine-year fraud campaign cloned Russian company websites to steal advance payments from international firms. Learn how the scammers operate and how to protect your business from similar attacks.

Cybersecurity researchers recently pulled back the curtain on a massive fraud operation that has been running for over nine years. The scheme? Creating fake websites that look exactly like major Russian companies to trick international businesses into sending advance payments straight into the criminals' pockets. According to Russian cybersecurity firm F6, the threat actors have built clone sites for companies across different industries, including fertilizer manufacturers and petrochemical firms. But this isn't just about one or two fake pages โ€” we're talking about a systematic, long-term campaign that shows how sophisticated online fraud has become. ### How the Scam Works The attackers didn't just slap together a few shady pages. They put serious effort into making their clone websites look legitimate. Think about it: if you're an international company looking to buy fertilizer or chemicals from a Russian supplier, you'd probably search online, find what looks like the right site, and reach out. That's exactly what the scammers are banking on. Here's how the typical playbook goes: - They register domain names that are almost identical to real company URLs - They build out full websites with product listings, contact pages, and even fake testimonials - They impersonate company representatives via email to negotiate deals - They request advance payments โ€” sometimes for hundreds of thousands of dollars โ€” and then vanish once the money hits their accounts This isn't a quick hit-and-run. The campaign has been active since at least 2015, which means these scammers have been refining their methods for nearly a decade. That's a scary thought for any business doing cross-border transactions. ### Why This Matters for Your Business You might think, "Well, I don't deal with Russian companies, so I'm safe." But here's the thing: this type of fraud isn't limited to any one country or industry. The same techniques can be โ€” and are being โ€” used to target companies everywhere. The United States is a prime target because of the volume of international trade we do. What makes this campaign particularly dangerous is how long it's flown under the radar. Nine years is an eternity in the cybersecurity world. The attackers have had time to perfect their approach, build trust with victims, and create an infrastructure that's hard to take down. ### Red Flags to Watch For So how do you protect your business from falling into this trap? Here are some warning signs that should set off alarm bells: - Unexpected emails from suppliers you haven't worked with before, especially if they push for advance payments - Domain names that are slightly off โ€” like using a .net instead of .com, or adding an extra letter to a familiar company name - Poor grammar or odd phrasing in business communications, though these scammers are getting better at this - Pressure to make quick decisions or bypass normal payment approval processes - Requests to wire funds to accounts in different countries than where the supplier is based ### The Takeaway for Digital Privacy As someone who works with antidetect browsers and digital privacy tools, I see this as a reminder that the web is full of impersonators. The same technology that lets legitimate businesses operate globally also lets criminals hide their tracks. Antidetect browsers can help protect your digital identity, but they won't stop you from clicking on a fake website. The best defense is a healthy dose of skepticism and good verification practices. Always double-check supplier credentials through independent channels. Call the company using a phone number you find on their official site โ€” not the one in an email. And never, ever send large payments without confirming the recipient's identity through multiple methods. This campaign is a wake-up call for any business that relies on online transactions. The scammers are patient, persistent, and increasingly sophisticated. But by staying alert and following basic security protocols, you can avoid becoming their next victim.