🟡 Medium  |  Source: The Hacker News


A nine-year fraud campaign has been uncovered in which threat actors created convincing clone websites of major Russian companies — including fertiliser and petrochemical firms — to trick international businesses into making advance payments for goods that never arrive. Discovered by Russian cybersecurity vendor F6, the operation has been running since at least 2016 and targets companies conducting cross-border trade. The campaign highlights the enduring risk of domain spoofing and brand impersonation in B2B procurement fraud.

Security Architect’s Take: Ensure your organisation’s supplier onboarding and payment approval workflows include independent domain verification steps — cross-check vendor website domains against official business registry records before processing any advance payments. Consider integrating threat intelligence feeds that flag newly registered lookalike domains targeting companies in your supply chain.

Original advisory: Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments