Global Scam IntelligenceDaily updates on global scam news and tactics
Back to home
PhishingPublished: August 4, 2026Russia

Russian Central Bank Reports Sharp Rise in Social Engineering Attacks While Phishing Incidents Decline

Russia's Central Bank released cybercrime statistics for Q2 2026, showing a 49.75% surge in social engineering attacks to 28,678 incidents, while phishing declined 90.71%. DDoS attacks increased 41.67%, indicating criminals are shifting tactics away from traditional phishing toward human-factor and infrastructure attacks.

Understanding the Shift in Fraud Tactics

Russia's Central Bank statistics reveal a significant transformation in criminal tactics. Scammers are moving away from traditional phishing website operations toward direct social engineering attacks targeting human vulnerability.

The Surge in Social Engineering

The most dramatic change is the rise of social engineering fraud—attacks that increased 49.75% from Q1 to Q2, climbing from 19,151 to 28,678 incidents. In these schemes, fraudsters build trust through phone calls, emails, or messages to extract personal information, banking credentials, or financial details from victims.

Other Attack Trends

DDoS attacks (infrastructure overwhelm attacks) rose 41.67%, from 60 to 85 incidents. Conversely, phishing-based fraud plummeted 90.71%, dropping from 2,863 to 266 incidents. Financial pyramid schemes also declined 65.30%, falling from 3,429 to 1,190 cases.

Telephone Fraud Patterns

Telephone-based fraud shows a telling pattern: toll-free numbers (8-800 prefix) increased 5%, while regular landlines dropped 13.31% and mobile numbers fell 6.69%. Criminals appear to be concentrating on toll-free numbers, which are harder to trace.

Regulatory Response

Russia's Central Bank issued 7,751 requests to telecom operators for blocking illegitimate numbers. Additionally, 242 illegal domains were reported to domain registrars for removal, and 4,400 domains were forwarded to the Russian General Prosecutor's Office for access restriction measures.

Red Flags and Prevention

Warning Signs:

  • Unsolicited calls or messages requesting bank details or personal information are always suspicious
  • Bank staff never ask for PINs, passwords, or authentication codes by phone
  • Pressure tactics creating artificial urgency are hallmarks of fraud
  • Suspicious links in emails or unexpected file attachments should be avoided

Protection Steps:

  • Never comply with requests from unknown callers
  • Verify claims by contacting your bank directly using official channels
  • When in doubt, consult trusted advisors or authorities

Reporting

Report suspected fraud or suspicious contacts to Russia's Central Bank or regional financial authorities.

Source: RUБЕЖ

Share