The record
Written from the 1 report below. Nothing here is unsourced.
- Cybersecurity firm F6 has uncovered a fraud campaign running since 2017 in which scammers cloned websites of major Russian companies across sectors like fertilizers, petrochemicals, metallurgy, logistics, and banking to target international firms.
- The fraudsters used lookalike domains, cold calls, phishing emails, and fake contracts and invoices with bogus bank details to trick businesses into paying advances for goods that never existed, with one Azerbaijani company reportedly losing $150,000 in April 2025.
- Nearly 100 counterfeit domains in Russian, English, Arabic, and French have been found, and shared infrastructure indicates a single coordinated operation.
- Legitimate companies whose brands are copied face reputational damage, and businesses are advised to independently verify payment details before transferring funds.
What to watch next
- Whether more victims or additional cloned domains are identified as F6's investigation continues
- Any action by Russian authorities or affected companies against the fraudulent domains
- Whether the scheme expands further into .com, .org, and .net domains targeting non-CIS markets
Coverage1
1 report
English national1
All filed from India
Named Russia · Azerbaijan · Azerbaijani company · Russian companies · Elena Shamshina · F6 · Vera Kolenikova
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
