Global Scam IntelligenceDaily updates on global scam news and tactics
Back to home
PhishingPublished: August 24, 2026Russia

Russia Sees Surge in Phishing Scams Impersonating Government Services Portal

Cybercriminals in Russia are distributing links to fake government service portal websites designed to deceive users. The fraudsters create fake security alerts claiming account breaches and use psychological pressure to trick victims into voluntarily entering login credentials and banking information.

Overview of the Scam

A new phishing scheme is targeting Russian citizens through fraudulent websites designed to impersonate the official government services portal Gosuslugi. Security analysts at F6 have identified the mechanics of this sophisticated attack.

How the Scam Works

Characteristics of the Fake Website

  • Visual design closely mimics the official Gosuslugi login page
  • A countdown timer displays immediately upon opening
  • A warning message falsely claims the user's account has been compromised

Fake Warnings Displayed

  • Simulated electronic signature download in progress
  • Fake loading screen for tax certificates (2-NDFL form)
  • Claims that passport and other personal documents are at risk

Method of Extracting Information

  • Instead of requesting a standard SMS verification code, the scammers direct users to click a link to the fraudulent government service site
  • Victims are prompted to enter login credentials and banking details on the fake site
  • All entered information is immediately transmitted to the criminals

The Criminals' Intent

The primary goal is to induce panic and fear in users. When people are stressed and frightened, they are more likely to act without careful consideration. Scammers exploit this psychological vulnerability by overwhelming victims with urgency, causing them to abandon caution and voluntarily surrender sensitive information such as usernames, passwords, and bank account details.

How to Identify Fraudulent Sites

Differences Between Legitimate and Fake Websites

  • Official Gosuslugi never displays sudden logout notifications or suspicious security warnings unprompted
  • Always check the URL in your browser's address bar for subtle misspellings (e.g., "0" vs "O", or "1" vs "l")
  • Legitimate Gosuslugi sends verification codes through the app or email, never through SMS requests to click external links
  • Urgent warnings and countdown timers are classic phishing tactics

Prevention Tips

  1. Don't Click Unsolicited Links: Never click links received via email or SMS. Instead, type the official URL directly into your browser or use the official mobile app.

  2. Verify the URL: Always check the address bar to confirm you are on the legitimate domain (gosuslugi.ru).

  3. Never Enter Personal Information: Government and financial institutions will never request passwords or bank details through web forms.

  4. Avoid Storing Document Photos: Do not keep photographs of important documents like passports on your phone, as these can be stolen and misused by criminals.

  5. Keep Your Device Updated: Maintain current security software and operating system updates.

Where to Report

If you believe you are a victim of this scam or have received suspicious messages, contact local law enforcement or Russian cybersecurity authorities. You should also report the incident directly to Gosuslugi's official support team.

Summary

Urgent warnings and countdown timers are powerful psychological manipulation tools used by fraudsters. Stay calm, verify information through official channels, and remember that legitimate government services will never pressure you for sensitive information through unsolicited communications.

Source: YAMAL1.RU

Share