Researchers at Russian cybersecurity vendor F6 exposed a nine-year fraud operation targeting international businesses through cloned websites of legitimate Russian enterprises. The attackers created replica sites mimicking major fertilizer manufacturers and petrochemical companies, deceiving foreign firms into sending advance payments to fraudulent accounts.
The operation demonstrates sophisticated social engineering paired with basic technical deception. Threat actors registered domains resembling legitimate Russian businesses, then used phishing emails and other contact methods to convince international procurement teams that they were negotiating with real suppliers. Once payment details were agreed upon, victims transferred funds to accounts controlled by the fraudsters rather than the actual companies.
F6's investigation reveals the campaign operated continuously for over nine years, suggesting sustained profitability and minimal disruption from law enforcement or security teams. The longevity indicates the attackers likely targeted multiple victims across different industries and geographic regions without coordinated takedown efforts.
The fraud targets procurement workflows at international companies seeking Russian raw materials. Perpetrators exploit the complexity of cross-border supply chains, where verification procedures are often limited to email correspondence and basic document checks. The fertilizer and petrochemical sectors present high-value targets because bulk orders involve significant advance payments, sometimes reaching millions of dollars.
Victims include businesses that failed to independently verify supplier contact information or payment instructions through official channels. The scheme works because it combines credible-looking documentation with social engineering that exploits legitimate business urgency around supply agreements.
Organizations importing from Russian suppliers should implement verification protocols including direct phone contact with known company numbers, payment verification through established banking channels, and independent confirmation of any changes to payment instructions. Third-party supplier verification services can identify registered business identities before fund transfer.
The campaign underscores how straightforward domain spoofing and email-based fraud remain effective against enterprises despite technological security advances. Even companies with security awareness training fall victim when social engineering targets procurement processes specifically.
