Uzbekistan Economy Finance Technologies Culture Sports Tourism World Media OutReach Newswire
Uzbekistan

F6 Uncovers B2B Fraud Scheme Using Fake Corporate Sites

UzDaily Editorial Team · 31.07.2026 · 12:15 · 56 views
F6 Uncovers B2B Fraud Scheme Using Fake Corporate Sites
F6 Uncovers B2B Fraud Scheme Using Fake Corporate Sites / Photo: AI-generated image.

Tashkent, Uzbekistan (UzDaily.uz) — Cybersecurity firm F6 has uncovered a large-scale fraudulent campaign in which attackers created clone websites of major Russian enterprises for over nine years to steal funds from international clients.

According to the research, companies from CIS countries, the Middle East, and Central Asia, including Uzbekistan, were among the primary targets of the attacks.

Specialists from F6's Threat Intelligence and High-Tech Crime Investigations departments discovered 98 domains imitating official websites of enterprises in the chemical, metallurgical, petrochemical, food, and financial sectors, as well as logistics operators and banks. Most of the fake resources completely copied the content of the original sites and used similar domain names.

As F6 analysts noted, the attackers did not act through mass phishing mailings, but targeted international trade participants specifically. Cold calls, email correspondence, and fake corporate websites were used to find potential victims.

After establishing contact, potential clients were invited to visit fake web resources containing altered contact details. In some cases, scammers involved unsuspecting managers in initial negotiations who then transferred the client to a so-called "senior manager."

Next, buyers received commercial proposals, contracts, and invoices with fake bank details. As a result, funds were transferred to the attackers rather than the real supplier. According to F6, an Azerbaijani company lost about US$150,000 as a result of such a scheme in April 2025.

Elena Shamshina, technical head of F6's Threat Intelligence Department, reported that infrastructure analysis revealed shared DNS records, IP addresses, and registration data among a significant portion of the identified domains, indicating a single organized campaign.

The research also showed links between part of the infrastructure and earlier fraudulent schemes. The earliest identified domain was registered in 2017 and, according to specialists, may have been used by the attackers since that time.

Unlike previous similar campaigns where .ru domains predominated, the new scheme actively uses international top-level domains, including .com, .org, and .net. Some of the fake sites feature Russian, English, Arabic, and French versions, enabling scammers to target foreign companies.

Vera Kolenikova, senior specialist at F6's High-Tech Crime Investigations Department, stated that specialists also discovered fake commercial offers, contracts, and invoices created using counterfeit corporate email addresses and bank details.

According to her, the attackers prepare a complete package of documents to build trust with potential clients. Beyond the financial losses of victims, such actions damage the business reputation of companies whose brands are exploited in the fraudulent scheme.

F6 also reported that after some companies published fraud warnings on their official websites, the attackers copied these notices onto their fake resources, replacing the official website address in the text with their own domain.

Following the study, the company warned clients of its Threat Intelligence service about the identified threat and recommended thoroughly verifying counterparties through independent sources, confirming bank details and contact information through official channels, checking domain names and site registration dates, performing additional verification of payment details before transferring funds, and avoiding hasty decisions made under pressure.