Fake Websites of Russian Companies Used to Steal Advance Payments from International Firms

The420.in Staff
5 Min Read

Cybersecurity researchers have uncovered a sophisticated international fraud campaign that operated undetected for more than nine years by creating convincing clone websites of major Russian companies to defraud businesses involved in global trade. According to a report by cybersecurity firm F6, the campaign has been active since 2017 and targeted international companies by impersonating legitimate manufacturers, logistics providers, petrochemical firms, metallurgical plants and financial institutions to steal advance payments for goods that never existed.

Investigators said the attackers built nearly identical replicas of official corporate websites, copying most of the legitimate content while altering contact information, email addresses and banking details. Some fraudulent portals also used lookalike domain names that closely resembled genuine company websites, making it difficult for potential customers to identify the deception. The fake websites were published in English, French, Arabic and Russian, allowing the fraudsters to target businesses across multiple regions.

According to the investigation, the operation primarily focused on business-to-business (B2B) transactions involving companies in Commonwealth of Independent States (CIS) countries and international import-export markets. Cybercriminals reportedly initiated contact through phishing emails, cold calls and fraudulent corporate websites before sending commercial proposals, contracts and invoices containing forged banking details of fake subsidiary companies. Victims were persuaded to transfer advance payments directly into bank accounts controlled by the criminals.

India’s Largest Cybercrime Conference Nears: FutureCrime Summit 2026 Set for 6–7 August at Bharat Mandapam

One documented case involved an Azerbaijani company that allegedly lost approximately US$150,000 in April 2025 after transferring payment for goods that were never delivered. Researchers believe the actual financial impact of the campaign could be significantly higher because many affected organizations may not have publicly reported the incidents.

The investigation identified nearly 100 counterfeit domains impersonating well-known Russian companies. Analysts also found common infrastructure across many of the websites, including shared IP addresses, DNS records and domain registration patterns, indicating that the fraudulent portals were operated as part of a single coordinated cybercrime campaign rather than isolated incidents.

Researchers traced the origins of the operation to 2017, when a Russian chemical company reportedly began receiving calls from farmers asking about prepaid fertilizer orders that had never been shipped. Subsequent investigations revealed that fraudsters had created an almost identical copy of the company’s official website, changing only the contact details and payment information. The attackers also produced highly convincing business proposals, contracts and invoices carrying the company’s branding, making the documents appear authentic while directing payments to fraudulent accounts.

Perhaps the most concerning aspect of the campaign was the attackers’ ability to quickly adapt. When legitimate companies published fraud warnings on their official websites, the cybercriminals reportedly copied those warnings onto their fake websites as well, replacing references to the genuine domains with links to their own fraudulent portals. This tactic further strengthened the credibility of the counterfeit websites and increased the likelihood of deceiving potential customers.

Renowned cybercrime expert and former IPS officer Prof. Triveni Singh said that brand impersonation has become one of the most dangerous forms of financial cybercrime targeting businesses engaged in international trade. According to him, cybercriminals increasingly exploit cloned websites, forged business documents and fake corporate email accounts to build trust before diverting payments to fraudulent bank accounts. He advised organizations to independently verify supplier identities, domain registrations, banking details and official contact information before processing high-value international transactions, even when documents appear genuine.

F6 has advised businesses involved in cross-border trade to conduct thorough due diligence before making advance payments. Organizations should independently verify supplier information through official government business registries, confirm subsidiary details using trusted sources, carefully examine website domains and registration history, and validate banking information through direct communication with verified company representatives. Researchers believe these measures can significantly reduce the risk of falling victim to increasingly sophisticated business impersonation and advance payment fraud schemes that continue to evolve worldwide.

Stay Connected