Own kitchen: how online scammers use the topic of cooking recipes
Online scammers can use the subject of culinary recipes to deceive Russians, experts have warned about this. The love of delicious food is a universal hook that attackers use to catch as many potential victims as possible, disguising malicious attachments, phishing links, and spyware as recipes. For more information about how cybercriminals use culinary recipes, how dangerous such tricks are and how to protect themselves from them, read the Izvestia article.
Why is the topic of cooking recipes interesting to scammers?
Chefs all over the world post step-by-step instructions, offering to repeat their author's recipes, so users of different ages and social groups without the slightest doubt follow the links and download files promising mouth-watering dishes, says Ksenia, deputy head of the audit and compliance department at the information Security IT company Ural Center for Security Systems, in an interview with Izvestia. Kuznetsova.
"The love of delicious food is a universal hook that scammers use to catch the maximum number of potential victims," the expert notes. — Moreover, it is very convenient to disguise malicious attachments, phishing links and spyware under recipes.
In addition, as Ivan Kostenko, an analyst at the cybersecurity monitoring department of Security Vision, notes, criminals take advantage of the credulity of their "audience," which is mostly far from cybergienic. As a rule, potential victims of hackers do not check domains, easily leave their phone numbers and e-mail in exchange for "free recipes", and also download files from unverified sources. Critical thinking is blunted by the topic itself: food is associated with home comfort and safety, and advertising of "healthy" courses is perceived as a concern for health, not as a threat.
What schemes on the topic of culinary recipes to expect in 2026
In 2026, users are approaching the milestone when visual authenticity ceases to be a reliable filter, draws the attention of Sergey Shcherbakov, technical director of Stakhanovets, an expert in the field of IT and information security. According to the expert, deepfakes are reaching a level where well-known chefs, food bloggers and nutritionists will personally recommend potential victims to buy a particular product or sign up for a paid course in a live video.
"Another trend is targeted, personalized attacks through cooking chats and groups," the Izvestia source continues. — Scammers use simple parsers to collect the history of messages, find out what products their target likes, what she is allergic to and what diets she follows, and then send her an individually prepared file, for example, a collection of recipes for her type of food or an exclusive video tutorial from her favorite blogger.
The probability of opening such a file, as Sergey Shcherbakov notes, is very high, since the information provided ideally fits into the personal request of the potential victim. But inside there is malicious software (VPO), which instantly gives attackers access to other people's devices and data.
In addition, fraudsters can offer to download a recipe by clicking on a link that leads to a malicious resource, adds Evgeny Egorov, a leading analyst at the Digital Risk Protection department at F6. In addition, attackers can attract victims with non-existent contests with a prize in the form of a trip to a restaurant or a master class by a famous chef.
— Schemes with hijacking of messenger accounts can also be adapted in the form of a scenario with voting in a culinary contest, where you will need to log in through a fake form, — says the specialist.
What "culinary" schemes of scammers have been encountered before
Meanwhile, online scammers have been trying to speculate on the topic of cooking recipes for years. One of the most popular fraudulent schemes encountered earlier is the so—called free content funnel, Sergey Shcherbakov points out. As part of such scams, the user subscribed to a recipe channel, received useful advice for weeks, after which he was offered to buy a closed course for 5 thousand rubles, although in reality it turned out to be a simple compilation from open sources.
—In addition, cybersecurity experts have previously recorded massive phishing campaigns for brands of trending products, such as Dubai chocolate," says the source. — Fake websites also copied the design of well-known food delivery services and collected bank card data, with the number of such domains reaching several hundred during peak weeks.
Among other threats encountered earlier, Sergey Shcherbakov highlights viral apk files disguised as recipe collections, which, after installation, gave scammers full access to SMS messages and passwords, as well as hacks of large culinary bloggers with a large audience, on whose behalf the scammers then sent advertising links to questionable dietary supplements and other similar products.
According to Ksenia Kuznetsova, such schemes are aimed at a wide audience, but users with insufficient digital security experience are especially vulnerable, such as elderly people who are actively looking for culinary ideas but cannot always recognize fraudulent techniques. However, anyone can be a victim: a housewife planning to diversify the menu, a student learning the basics of cooking, or a parent choosing recipes for baby food.
"The main danger is the loss of personal data, access to banking applications and government Services, as well as infection of the device with malware that can go unnoticed for a long time," the specialist warns.
How to protect yourself from the "culinary" schemes of scammers
In order to protect themselves from fraud schemes on the subject of culinary recipes, experts interviewed by Izvestia advise following certain cybersecurity rules. In particular, Ivan Kostenko recommends searching for recipes on trusted, well-known sites with a good reputation. Large culinary portals and popular thematic communities on social networks take at least minimal care of the safety of their users.
— If you click on a link to an unfamiliar site, take your time: pay attention to the address bar — modern browsers themselves warn about suspicious resources by showing a lock icon with a warning or informing you that the connection is unsafe, — the expert notes.
He also advises paying attention to how the site looks: whether there are many typos, strange section names, whether there are contacts for feedback and real reviews. Ideally, you should register and leave personal information (phone number, e-mail address, payment information) only if you really can't do without it, and only on trusted sites. You should be wary if the site aggressively requires you to enter such information immediately — this is a classic sign of data collection for subsequent spam campaigns or database sales.
In turn, Andrey Sidenko, head of Kaspersky Lab's online child safety department, urges the careful use of artificial intelligence in the context of cooking recipes. For example, there have already been cases when neural networks suggested adding glue to cheese pizza or gave out a recipe for garlic in oil, following which could lead to poisoning.
— The recipe is free by nature: the offer to buy access to a closed collection of recipes or to a "unique technique" is in itself a reason not to trust the resource. The recipe is a text, it does not require installing programs, unpacking archives and individual applications, so the suggestion to download the collection as an executable file or archive with a password is a clear sign of malicious mailing," concludes Alexey Vybornov, an analyst at the Positive Technologies research group.
Переведено сервисом «Яндекс Переводчик»