This website uses cookies. By continuing to browse the site, you confirm your consent to the use of these files.

Cyber fraud

Fintech and Public Finance

Cyber fraud is a type of crime in which attackers use digital technologies (the internet, computers, smartphones) to steal money, personal data or access to accounts using social engineering methods and technical attacks.

What is cyber fraud

Cyber fraud is any fraudulent activity carried out via the internet and digital channels. Attackers use phishing, fake websites, social engineering, malicious software and other schemes to deceive people and steal money, data or access to accounts. Unlike traditional fraud, cybercrimes are committed remotely, often from other countries, which complicates catching the perpetrators.

Cyberfraud diagram: attacker → attack methods → victim Typical cyberattack methods: phishing (fake website), social engineering (calls, messages) and malware. Shows the path from attacker to victim. 2. Cyberfraud — attack diagram Attacker Attack methods Victim Phishing (fake website) Social engineering Malware
Cyber fraud — term diagram

Cyber fraud is doubly dangerous because it is almost impossible to find and return lost funds: attackers transfer money to third-party accounts or cash it out, change phone numbers by registering them on third parties, and use other people's accounts. Therefore, it is worth taking measures in advance so as not to become a victim.

By law, the penalty for cyber fraud can range from a large fine to 10 years of imprisonment. The term and amount of the fine depend on the size of the damage and the presence of aggravating circumstances (Art. 159.6 of the Criminal Code of the Russian Federation). A single crime (up to 250,000 rubles) is punishable by a fine of up to 300,000 rubles or imprisonment for up to 3 years. By a group of persons by prior agreement or with major damage (from 250,000 rubles) — up to 5 years of imprisonment. By an organized group or in especially large scale (from 1 million rubles) — up to 10 years of imprisonment with a fine of up to 1 million rubles.

For business, cyber fraud brings not only direct financial losses, but also reputational risks. A client data leak can lead to fines under 152-FZ and loss of trust. The Fintech company offers comprehensive solutions for protection against cyber threats, including SINTeZ-M for secure document workflow and SKIF-BP for data encryption.

Main cyber fraud schemes

Attackers constantly improve their methods. The most common schemes include:

1. The "safe account"

You receive a call from a "bank employee" or "law enforcement" claiming that your money is at risk. They demand that you transfer all your funds to a "special safe account" for protection. Remember: real bank employees never ask you to transfer money to third-party accounts.

2. Phishing and fake websites

Attackers create exact copies of well-known online stores, marketplaces or payment services. You enter your bank card details on a fake website and they fall into the hands of criminals. Always check the browser address bar — the URL must exactly match the company's official address.

3. Hijacking accounts on social networks and messengers

Attackers hack the profile of your friend or relative and ask to borrow money "for an operation", "for a taxi" or to "urgently transfer to a card". Always call the person back on their personal number before transferring money.

4. Investment scams

You are offered "guaranteed income" from investments in cryptocurrency, stocks or "unique startups". They promise quick profits and low risks. After the money is transferred, the "broker" disappears. A legitimate business never guarantees returns.

5. Deepfakes and AI fraud

Modern neural networks make it possible to imitate the voice or even a video call from your management or relatives. Attackers can record your voice (for example, during a short survey disguised as a courier) and use it to confirm operations. If you are asked to urgently transfer money, end the conversation and call back on a verified number.

How to protect yourself from cyber fraud

Following a few simple rules will help you avoid losing money and data:

  • Verify information: If you receive a call from a "bank" or "police", hang up and call back on the official number indicated on the back of your card or on the organization's website.
  • Do not click suspicious links: Carefully study the address bar of websites. Phishing sites can differ by just one letter (for example, sber-bank.ru instead of sberbank.ru).
  • Use strong passwords and two-factor authentication (2FA): Enable login confirmation via SMS, an authenticator app or biometrics for all important accounts — email, social networks, banking applications.
  • Never disclose SMS codes and CVC codes to anyone: Real bank employees never request one-time passwords to confirm operations or the CVV code from the back of the card.
  • Regularly check your credit history: This will help you notice in time if attackers have taken out a loan in your name. You can request your credit history through the Gosuslugi portal.

Read more about how to recognize the tricks of fraudsters in our article on fraud monitoring and antivirus protection.

What to do if you become a victim of cyber fraud

If you have transferred money to fraudsters or disclosed confidential data to them, act quickly and according to plan:

Step 1. Protect your finances

Immediately block the card from which you transferred funds. Do this through the bank's mobile application, the personal account on the website or by calling the hotline. This will prevent further debits.

Step 2. Request cancellation of the transfer

If you made the transfer recently, ask the bank operator whether the operation can be suspended. In some cases, the bank can manage to block the transaction before the funds are credited to the fraudster's account.

Step 3. Collect evidence

Take screenshots: correspondence with the fraudsters, links to the fake website or seller profile, receipts and confirmations from the banking application indicating the details where you transferred money.

Step 4. Contact the police

File a fraud report. You can do this in person at any police station, by calling the emergency number 112, or online on the website of the Ministry of Internal Affairs of Russia. Attach the collected evidence and the account statement to the report.

Step 5. File a chargeback

If you paid for goods or services with a bank card, contact your bank with a statement of disagreement with the transaction (chargeback). Attach evidence of the fraud — if the bank recognizes the case as fraudulent, the money will be returned to the account.

A more detailed instruction on how to return money can be found in the Questions and answers section or on the electronic signature page for secure financial operations.

Liability for cyber fraud

Criminal liability for fraud in the sphere of computer information is regulated by Article 159.6 of the Criminal Code of the Russian Federation. The penalty depends on the amount of damage and the circumstances:

  • Up to 250,000 rubles: a fine of up to 300,000 rubles, or compulsory labor, or imprisonment for up to 3 years.
  • From 250,000 rubles (major damage): imprisonment for up to 5 years with a fine.
  • From 1,000,000 rubles (especially large scale) or by an organized group: up to 10 years of imprisonment with a fine of up to 1 million rubles.

In addition, the court obliges criminals to fully compensate the material damage to the victims. If you have suffered from cyber fraud, be sure to file a civil claim within the criminal case.

To protect business from cyber threats, we recommend implementing DLP and SIEM systems, as well as conducting regular information security audit.

Frequently asked questions

What is cyber fraud in simple words?

Cyber fraud is deception on the internet when attackers use digital technologies to steal your money or personal data. They can call you on behalf of the bank, create a fake website or hack a friend's account on social networks. The main goal is to make you voluntarily transfer money or disclose passwords. Read more about how protection systems work in the article on fraud monitoring.

What types of cyber fraud are the most common?

The most frequent schemes: calls from the "bank security service" demanding a transfer of money to a "safe account", phishing (fake websites of banks and stores), hijacking accounts on social networks to ask for money, investment scams with a guaranteed income, and deepfakes — faking the voice or video of relatives/management with a request for an urgent transfer. Learn how to recognize these schemes in our information security section.

How to recognize a call from a fraudster?

Fraudsters use pressure and urgency: "your money is being stolen", "take out a loan to transfer it to a safe account". They demand immediate action and do not give time to think or consult. Real bank and state employees never request SMS codes, the card CVV code or ask to transfer money to other accounts. SINTeZ-M — our solution for secure document workflow — will help protect your data.

What should I do if I transferred money to fraudsters?

Immediately block the card through the mobile application or the bank hotline. Collect all evidence: screenshots of correspondence, transfer receipts, links to websites. Contact the police with a fraud report. Also file a chargeback (payment return) application with your bank if the payment was made by card. A more detailed instruction is in the Questions and answers section.

What penalty is provided for cyber fraud?

Criminal liability for cyber fraud in Russia is provided under Article 159.6 of the Criminal Code of the Russian Federation. For damage up to 250,000 rubles — up to 3 years of imprisonment. For major damage (from 250,000 rubles) — up to 5 years. For especially large scale (from 1 million rubles) or by an organized group — up to 10 years of imprisonment. The criminals are also obliged to compensate the damage to the victims. Read more about the legal aspects in the article on electronic signature.

How to protect yourself from cyber fraud?

Use strong passwords and enable two-factor authentication (2FA) for all accounts. Never disclose SMS codes and the card CVV code to anyone. Check website addresses before entering data. If someone calls from a "bank" — hang up and call back on the official number. Regularly check your credit history through Gosuslugi to notice foreign loans.

For additional protection of your data in electronic document workflow, use SINTeZ-M and SKIF-BP — they provide reliable encryption and secure document transfer.

Where to report if I was deceived in an online store?

If you paid for goods but the seller disappeared, contact your bank with a request for payment return (chargeback). Also file a report with the police and file a complaint about the fraudulent website with Roskomnadzor so that it is blocked. Leave a review on themed forums — this will help other users avoid falling for the scheme. About how to protect your business from fraudsters, read the article on attestation testing.

Was this information helpful?

Optimize your finances with our solutions

Implement modern financial technologies to automate processes, increase transparency and reduce costs. Individual approach to every client.

Guaranteed result
Selection for your budget
Comprehensive approach
Certified experts

Or contact us:

+7 (499) 238-01-32 sales@fintech.ru

Open from 9:00 am to 6:00 pm