Russians were warned about fraudsters collecting digital profiles of victims
The volume of leaks of personal data of Russians continues to grow, and with them the risks of becoming a victim of fraud increase. Today, attackers are increasingly using so-called digital profiles rather than separate databases, which allow them to collect detailed information about a person and make fraudulent schemes as convincing as possible. On June 6, the head of the group for work with educational organizations of the Cyberprotect company, information security expert Sarkis Shmavonian, told Izvestia.
According to him, a digital profile is a collection of personal data obtained from various leaked and open sources. Previously, scammers worked with disparate information, but now they combine information from various databases, creating a detailed portrait of a potential victim.
"Such profiles may include not only a name, phone number, or address, but also information about a person's place of work, marital status, relatives, income level, fines, and other aspects of their life. Additionally, the attackers use data from open sources — social networks, comments, reviews, photos and other traces of digital activity," Shmavonian explained.
The expert noted that such "enrichment" of data allows fraudsters to create personalized attack scenarios. Unlike the mass mailings of previous years, modern schemes are built taking into account the specific circumstances of a person's life and often look as plausible as possible. Among the most common legends are calls from the company's management, reports of tax inspections, problems with bank accounts, or the need to urgently transfer funds to a "secure account."
According to Shmavonian, in conditions of constant leaks, it is not so much the issue of protecting data from getting into the Network that becomes more relevant, as the ability to recognize fraudulent attempts to use them. The expert recommends adhering to the principles of critical thinking and "zero trust" in unexpected calls and messages.
"Attackers may know passport details, residential address, and even bank card information. However, the presence of such information does not confirm that the interlocutor really represents the organization on whose behalf he is addressing," he stressed.
The specialist advises not to make hasty decisions under pressure, not to disclose confidential information during telephone conversations, and always double-check information through official communication channels. According to him, a calm reaction and willingness to independently contact the organization on whose behalf the appeal was received remain one of the most effective ways to protect against fraudsters.
The expert added that it is emotional pressure and the need to make an urgent decision that most often become the main signs of a fraudulent attack, so in any suspicious situation it is better to interrupt the conversation, take a break and check the information yourself.
On October 9, RTM Group announced that hackers had begun attacking Russian companies through smart gadgets. They began to gain access to confidential information from Russian enterprises using portable speakers, charging stations, and heated mugs.
Переведено сервисом «Яндекс Переводчик»