
Signing up for a million: how scammers trick kids into popular games

Fraudsters are deceiving young gamers by offering "free" subscriptions to games in exchange for bank card details. Parents in social networks complain en masse about such situations: they say that criminals have forced their children to transfer all their money to them. Losses range from tens to hundreds of thousands of rubles. "Izvestia" found out how the new scheme of deception works and how to protect the child from it.
"You can not wait for money"
Fraudsters have begun to deceive children, offering free subscriptions in games, and in fact - withdrawing money from parental cards. Such a case was reported by blogger Anna Bazhenova.
According to the Russian, her daughter played the popular game Roblox and transferred 180 thousand rubles to fraudsters. In addition, the girl was "two steps away from making a loan in the name of her mother".
"Fraudsters offer to get free game currency - robuxes - but for this you need to perform certain actions. And the child's phone is not suitable, only adults - parents, grandparents. The child takes the phone and first communicates in chat, then goes to a video call in Telegram, and the scammers find out the balance of all cards", - shared Bazhenova in Instagram (owned by Meta, recognized in the Russian Federation as extremist and banned).
After what happened, she wrote a statement to the police - they opened a criminal case, but "said that you can not wait for money." The bank could not cancel the operation either.
In the comments to the post, subscribers told about similar situations. "My friend's daughter withdrew money from all cards", "The son on the instructions of fraudsters almost gave access to the online Bank of Dad", "We also passed this stage, we were withdrawn 100 thousand. Further the Bank reacted", "The daughter was caught the same way. Thanks to smartwatches: I saw the SMS with the password," they wrote.
Cybersecurity experts told Izvestia that fraudulent schemes in games are not rare. This can happen if a gamer leaves the game platform and goes, for example, to a messenger or phishing portal.
- Another option - mailing to the mail allegedly on behalf of the administration of the gaming platform. In such letters, fraudsters can offer the child some secret versions of the game, internal currency and so on, - said GR-director of the IS-company "Security Code" Alexandra Shmigirilova.
One way or another, she concluded, it is important for parents to explain to their children the rules of safety in games and to know the key schemes of deception that are used in them.
Expensive subscriptions
Fraud schemes related to the popular game have already been recorded in various Russian cities. For example, in May, a second-grade girl from Chuvashia transferred almost 1.5 million rubles to fraudsters. The girl's father received a message from the bank about closing the deposit.
"At that moment, the phones of both parents and the tablet were at the daughter, who communicated via video link with a stranger," - told the police.
As it turned out, the girl registered in a group in a social network for the distribution of robo-bucks. In order to get them, it was necessary to perform different tasks: to take a picture of the unlocked screen of the parent's phone, to enter the applications of banks, to close deposits and transfer money to the accounts specified by the fraudster to pay for goods on well-known marketplaces.
In total, the second-grader made 11 transactions of 100 thousand rubles each, issued a loan for 460 thousand rubles and managed to pay with this money to buy 200 thousand rubles.
A 10-year-old boy from Yakutia became a victim of the same scheme. He found a link to a Telegram channel on the Internet, where he was promised free 4,500 bonuses for the game Roblox in exchange for his parents' numbers and codes from SMS sent to them. On the same day, more than 500 thousand rubles were debited from their accounts.
It is noteworthy that similar schemes were used in other countries. For example, in Great Britain children were involved in illegal casinos with the help of the same game. The game currency was used as bets on different websites.
Mechanism of deception
As Dmitry Ovchinnikov, head of the Laboratory for Strategic Development of Cyber Security Products at the Analytical Center for Cyber Security "Gazinformservice" explains to Izvestia, fraudulent schemes with the Roblox game have been known for a long time and are very widespread.
- To begin with, this game is very popular with children from six to 12 years old. Many young bloggers make videos of themselves playing the game, and such content is very popular with young players," says Ovchinnikov. - The second important fact is that Roblox has game currency. And this is precisely the point where cheaters turn on.
The method of deception works simply: criminals through local chat rooms, messengers or social networks send phishing messages about the giveaway or the opportunity to easily earn game currency. There is also the scheme described above, where the information occasion is the purchase of a subscription.
- Among the potential victims are all players who have not been told about information security by their parents. It is they who are asked to provide access to the parents' phone, where online banking is installed with a guarantee of 100%. Next, fraudsters can convince the child to report a code from an SMS or push notification, install a spy program. Naturally, as a reward, they promise to transfer game currency," says the Izvestia interlocutor.
As a result, the child performs the actions - and parents are left without funds on their accounts. Such operations are carried out in game form, and the young gamer does not even realize what is happening. According to the expert, such schemes can be used not only in Roblox, but also in any children's games, where there is a paid premium subscription, game currency. Therefore, it is important to know what children play, never give them their gadgets and tell them about the dangers of communicating with strangers on the Web.
Other tricks
Fraudsters began to deceive gamers from the moment the games moved online, says in a conversation with Izvestia expert of the company "Cyberprotect" Sarkis Shmavonyan. Different approaches can be used in schemes of deception with free subscriptions or resources, for example, sites-doppelgangers of popular games, where, when trying to pass authorization, access to an account in Telegram, social networks or even on "Public Services" is compromised. Criminals ask you to enter through them allegedly to get bonuses.- Then follows the compromise of correspondence and data, possibly a ransom demand and other unpleasant consequences. In addition, scammers gain access to the game account and can steal it and all game items. Or, if a person wants to buy something on such a site, the fraudsters get their payment data, " says Shmavonyan.
Another scheme related to games, the expert calls the publication of allegedly free promo codes on thematic channels in messengers and social networks. Such codes can supposedly extend the subscription or provide additional game resources in the account.
- To enhance the effect of "urgency" there may be a time counter or information about a limited number of promo codes, and to apply them you must be authorized in the game account. The result is, once again, the theft of an account," notes the Izvestiya interlocutor.
In all of these techniques, fraudsters can send children links to fake sites or malicious applications, which can lead to tracking users and stealing data, encryption or complete destruction of information.
Ways to protect yourself
To protect children from scammers, experts urge to teach them the rules of cyber hygiene: do not follow links from strangers, do not enter credentials on any sites and in general do not provide anyone with confidential information, use complex passwords and two-factor authentication.
- It is impossible to predict everything, but there is a "parental control", with which you can put both a ban on visiting certain sites and a number of processes, - says GR-director of "Security Code" Alexandra Shmigirilova. - Other technical means of protection include the mandatory installation of an antivirus.
Also, she adds, can provide "passive" security by linking a separate bank card to the game account, where a minimum amount of money will be kept. In this case, even if the fraudsters deduct money from the child due to his/her ignorance, this financial loss will be minimal, and also this option will reduce the risk of fraudsters accessing the parents' main accounts.
In addition, it is necessary to explain to children that free gaming resources can be dangerous and parents should be consulted before installing any application. It's always important for adults to thank children for all referrals and questions - and not to scold them for misbehavior, lest they lose their sense of trust. And, of course, to give the child more time, monitor his interests and who he communicates with on the Web.
- In general, it is important to know how to distinguish a cheater in games. Many developers now prohibit the sending of links in private messages and chats just so that scammers can not conduct their schemes. Therefore, if the "administration" of a platform or game tries to transfer communication to messengers, social networks or other portals, it is more likely to be fraudsters, and they should not respond, " concludes Dmitry Ovchinnikov.
Переведено сервисом «Яндекс Переводчик»