The new scheme looks like this: the fraudster asks the victim to fill out a Google form, in which he requests personal data. Then the applicant receives a call from a fictitious person who offers to link the phone number of the corporate SIM card to the personal account of the online bank. This is supposedly necessary in order to receive a salary from the first day of employment.
"Based on the results south africa whatsapp resource of the study, experts found at least 35 similar announcements in various Telegram channels and chats, which were published by only one account belonging to the fraudster," the channel of the Department for Combating the Illegal Use of Information and Communication Technologies of the Russian Ministry of Internal Affairs said.
of the company "Code of Security" Konstantin Gorbunov explained that at all stages of interviews before receiving a job offer, you should not provide the employer with passport data, corporate data from the current place of work, bank account data, driver's license (the exception is if it is required to perform tasks for the vacancy). Information security consultant of AKTIV.CONSULTING Vladislav Krylov added to this list any codes related to bank accounts and cards (SMS, CVV, push, authorization e-mails), credit history, codes related to instant messengers and personal accounts of communication service providers, personal data of relatives and friends. If the employer asks about this, the candidate should be wary.
It is safe to talk about work experience, achievements, education details, hobbies, participation in events and certificates.
Read also
Fraudsters use the Ministry of Industry and Trade as cover for attacks on the state and business
Fraudsters are massively attacking representatives of Russian businesses and government organizations using social engineering methods. The attackers contact company employees using fake Telegram accounts.
Vladislav Krylov advises, whenever possible, to provide sensitive data during personal communication in the organization’s HR department, as well as after signing consent to the processing of personal data.
He also advised to be wary if the employer asks to pay a fee, commission, or contributions for subsequent employment. You cannot link bank data to other people's numbers.
The Digital Russia project advises to carefully check job sources and not to trust dubious Telegram channels. Konstantin Gorbunov from Security Code advised using popular job search services - HH, Superjob, etc. They are less likely to encounter scammers, as moderation tools work.
However, you should also be vigilant with popular platforms. Konstantin Gorbunov gave an example of how scammers fake Telegram bots of services and send them fake job postings with phishing links. To avoid falling for the trick, you should only go to other services from the platform using links from the official website.
But even the most well-known services may be the target of fraudsters. According to Vladislav Krylov, despite the checks, there is still a risk of fraudsters being registered. To make sure that the employer is reliable, you need to check the information about the legal entity: registration data, TIN, company turnover, average headcount, arbitrations, bankruptcy information, availability of licenses and certificates, information about the founders and governing bodies. Also, to dispel doubts, the candidate can find the company's website and call the numbers listed there. In no case should you link bank data to other people's numbers.
Leading expert on network threats and web developer
-
- Posts: 422
- Joined: Thu Jan 02, 2025 7:50 am