A nine-year-long cyber heist has been uncovered, with hackers cloning websites of Russian companies to trick victims into making advance payments on fake projects. The operation, which began in 2017, is believed to have netted millions of dollars for the attackers.
At its core, this scam relies on social engineering and phishing tactics to lure unsuspecting individuals into sending funds in anticipation of future work or services. The hackers accomplished this by creating convincing replicas of genuine Russian company websites, complete with authentic logos, contact information, and even fake client testimonials. These decoy sites were then used to solicit advance payments from potential clients, who were convinced that the projects were legitimate.
The attackers’ modus operandi involved registering domain names that closely mirrored those of real companies, often using variations in spelling or punctuation to avoid detection. They would then create a convincing replica of the company’s website, complete with fake project details and client testimonials. This cloned site was used to contact potential clients, pitching them on fake projects and extracting advance payments. The hackers also employed email phishing campaigns to send targeted messages to victims, increasing their chances of success.
The operation is believed to have been carried out by a sophisticated group of attackers, who demonstrated an impressive level of adaptability and perseverance over nearly a decade. Their ability to stay ahead of the curve and evade detection highlights the ongoing cat-and-mouse game between cybercriminals and security professionals. The fact that this scam was able to fly under the radar for so long also underscores the importance of vigilance in cybersecurity.
The aftermath of this heist serves as a stark reminder of the need for increased awareness and caution when dealing with online transactions, particularly when it comes to advance payments. As we continue to navigate an increasingly complex digital landscape, it’s essential that we prioritize education and training in cybersecurity best practices. By doing so, we can empower individuals and organizations to better protect themselves against such scams and stay one step ahead of the attackers.
Practically speaking, businesses and individuals should exercise extreme caution when dealing with online transactions involving advance payments. This includes thoroughly vetting any potential clients or partners, verifying their identity through multiple channels, and ensuring that all communication is conducted over secure channels. By taking these precautions, we can minimize our vulnerability to such scams and reduce the risk of falling victim to cyberheists like this one.
Source: The Hacker News — 2026-07-29