Modern technologies are developing at an incredible pace, providing criminals with new tools to carry out their plans.
A lack of public awareness about potential threats and protection methods leaves a significant portion of society vulnerable.
According to statistics, women are more often victims than men. The absolute majority live in cities. Citizens with higher education, as well as secondary education, are equally susceptible to deception. In this case, education does not create immunity against naivety; on the contrary, confidence in one's own competence sometimes leads to carelessness. Therefore, knowledge about cyber fraud and awareness of protection methods are more relevant than ever. Everyone, regardless of their educational level, must be prepared to resist fraudsters.
Fraudsters regularly change their deception schemes, pursuing only one goal – to steal money. Telephone fraud (vishing) remains relevant.
In most cases, fraudsters call via messengers (Telegram, WhatsApp, Viber), and may also use landline and mobile communications, posing as employees of a mobile operator. Under the pretext of extending a contract or the validity of a SIM card or tariff, they offer to install a fake application. To do this, they send a file in *.apk format via the same messenger.
If the user launches the file, a fake application will be installed, which gives fraudsters access to the data on the device: logins, passwords, SMS codes, photos, messages, and other information, as well as allowing them to take out an online loan in the user's name and steal money.
For example, since the beginning of the year, numerous cases have been recorded: fraudsters, using the internet and the "Viber" messenger, posing as an "MTS" employee, under the pretext of extending a subscriber number, obtain personal data and
SMS codes.
Fraudulent schemes involving calls from malicious actors via messengers to citizens are common. During conversations, these malicious actors impersonate bank employees, law enforcement officers, or employees of state organizations and enterprises:
For example, this year, an employee of an educational institution approached one of the Internal Affairs Departments (ROVD) in Vitebsk. She reported that an unknown individual called her mobile phone, posing as an employee of "Energosbyt" (Energy Sales). Under the pretext of replacing meters, the caller obtained her passport details (full name, identification number, residential address). Furthermore, via the internet, using the "Viber" messenger, the same individual, impersonating an employee of the National Bank, attempted to obtain a total of 36,000 rubles by falsely claiming it was necessary to prevent the processing of loans in her name.
Scammers attempt to convince citizens that a loan is being taken out in their name by one of the banks. To safeguard their funds and expose dishonest bank employees, they persuade individuals to transfer their money to a "secure account" or to take out loans in their own name for subsequent transfer to the scammers' accounts. Additionally, telephone scammers may impersonate citizens' relatives, claiming that these relatives have caused accidents involving third parties and require funds to resolve the issue favourably and prevent criminal proceedings.
Citizens who fall under the influence of these scammers, in an effort to assist law enforcement agencies in exposing dishonest bank employees, lose their vigilance. Without verifying the identity of the caller, they engage in dialogue with the scammers, take out loans in their own name, and subsequently transfer the obtained funds to the scammers' accounts. Following this, the scammers cease communication with the victims.
For instance, a worker from one of Vitebsk's enterprises, during a conversation in the "Telegram" messenger via the internet, was targeted by scammers. Posing as a law enforcement officer and under the pretext of processing a loan to aid in exposing a fraudster, the criminals attempted to obtain 40,000 rubles.
One of the most common methods of committing fraud on the global Internet is also the misappropriation of funds under the pretext of receiving advance payment for the sale of goods on online trading platforms and in social network groups, such as Instagram, VKontakte, Telegramim trading platform. Subsequently, the victim is prompted to deposit a small sum of money as an initial payment to commence training. After the victim makes the so-called initial deposit, they begin to receive calls from other individuals who introduce themselves as personal brokers. Later, under the pretext of higher earnings, the victim is encouraged to deposit a larger sum of money. To lend credibility to their actions, the fraudsters, posing as a withdrawal of earned funds from a fake trading platform, transfer a negligible amount to the victim, thereby convincing the victim that they are dealing with a legitimate organisation. Furthermore, to fully persuade the victim, the fraudsters send copies of non-existent documents, photographs of identification cards, certificates, and licenses, often in a foreign language, via correspondence or email. After some time, the victim receives neither the funds they deposited nor the fictitious earnings. Ultimately, when the victim realises they have been deceived, the perpetrators either cease communication or continue their illegal activities through intimidation. Additionally, other individuals may contact the victim, posing as employees of a foreign law firm specialising in the recovery of fraudulently obtained funds; however, these individuals are also fraudsters. The trading application, installed at the fraudsters' direction, will display the victim's deposited funds on its balance, but in reality, the victim has no access to these funds.
For instance, in the city of Orsha, a 36-year-old worker from one of the enterprises found an advertisement on social media offering profitable investment opportunities. Following a link, he filled out a questionnaire, providing his personal details. Immediately after, a trading specialist contacted him and quickly familiarised the novice investor with the process. The man took out two loans, borrowed a substantial sum, and transferred over 26,000 rubles to the account specified by the fraudsters. Subsequently, under the guise of paying various taxes and fees for fund withdrawal, the Orsha resident was persuaded to transfer an additional 10,000 rubles.
By the time the Orsha resident realised he was being deceived, he had already transferred over 40,000 rubles to the fraudsters.
It should be noted that scammers study their victims to commit crimes, gathering data about them, their interests, social circle, and other information from the internet. Having a voice sample or photos of acquaintances, they can create fake text or video messages.
For example, several similar incidents have been registered in 2024. In a messenger, scammers created an account of a state organization's head and wrote to an employee in their name, stating that lists of employees suspected of financing extremist groups had been received, and that a search of the woman's home might soon be conducted and undeclared funds seized. The woman was very frightened for her money because she trusted her manager. Subsequently, the scammers, acting as her manager, suggested she communicate with the Head of the Regional Financial Investigations Department, who in turn connected her with an investigator. For three days, the woman lived in fear for her savings. To preserve them, the scammers "advised" her to transfer them to a supposedly special secure account. The woman also took out a loan within a week, cashed it, and transferred it to the same account, from which all the money, amounting to 55 thousand rubles, was soon stolen.
It is important to remember that in order to obtain personal data of owners and accounts, scammers create clone pages of banks, theatre websites, hookah lounges, and investment (trading) exchanges.
To receive stolen money abroad, as well as to obscure "digital footprints," scammers need to transfer it through intermediate accounts opened in Belarusian banks by straw individuals, so-called "drops." Often, there are more than a dozen intermediate accounts.
In our country, a bank account can be opened by a citizen from the age of 14, with the permission of legal representatives, meaning even minors can open bank accounts. Criminals exploit this. While abroad, offenders select individuals who agree to open a bank account in their name and sell the access details for a small sum – these are logins and passwords for internet banking personal accounts, as well as providing one-time SMS codes.
Scammers on the internet cannot directly post advertisements seeking such individuals. Therefore, they disguise their interest by offering various other seemingly legitimate earning opportunities. For example, they send out advertisements via Telegram seeking couriers in any city with stable pay, or people for unloading goods, or individuals for a "mystery shopper" vacancy, or lure them with promises of high and fast payment.
Most often, individuals with unstable or low incomes, predominantly young people, respond to such vacancies. Initially, the advertisement initiator disappoints the interested party, informing them that the vacancy has already been filled, and immediately offers an alternative way to earn money, such as opening a bank account and providing access details for a reward.
In addition to money stolen by cybercriminals, funds obtained from the illegal drug trade may also be processed through intermediary accounts. Account holders are responsible for the money that passes through their bank accounts.
It should be noted that Article 222 of the Criminal Code of the Republic of Belarus provides for criminal liability for the distribution, for mercenary motives, of bank payment card details or authentication data that are in illegal possession of a person, which enable access to accounts, electronic or virtual wallets.
There have been instances where minors have been involved in criminal activities.
To avoid becoming another victim of cybercriminals, please remember the following rules:
– When making purchases online, payment should only be made after receiving the goods and verifying their condition;
– Do not forget that scammers may use fictitious details, photographs of other people's passports, other people's social media accounts, or other people's phone numbers to confirm their identity. The best way to communicate is through a personal meeting with the seller and on-site inspection of the goods;
– Do not trust the attractive design of a website or an online store page, or user comments. Nowadays, it is not difficult to create a website with any information. It has become impossible to distinguish honest sellers from scammers;
– Purchase goods from trusted stores, or before purchasing, verify them by monitoring online;
– do not fall for the tricks of fraudsters who promise to sell you goods at a low price, no matter how favorable the terms of the transaction may be.
– law enforcement officers and bank employees do not call via messengers and do not ask you to take out a loan or assist in apprehending criminals, nor do they offer to insure and secure funds;
– pay attention to the subscriber numbers from which you receive calls in messengers; most often, subscriber numbers from which criminals call belong to foreign countries. Subscriber numbers of the Republic of Belarus begin with the code "+375";
– do not install any applications on your mobile phone at the instruction of unknown persons;
– do not transfer money to a "secure account";
– do not disclose your personal data, bank card details, or SMS codes to unknown persons;
– do not follow links from unknown users;
– if you receive such calls, immediately end the conversation and report the incident to the police.
We also recommend subscribing to the Telegram channel "Digital Literacy" (invitation link "t.me/cifgram"), where up-to-date information on methods of committing cybercrimes and countermeasures is regularly published.
Cybercrime Counteraction Department
KM UVD Vitebsk Regional Executive Committee