- More than 360 domains reported.
What changed
The Record reports that F6 researchers identified more than 360 fraudulent domains impersonating government programmes and news outlets. The campaign targets people in Uzbekistan, Belarus and Tajikistan with supposed payments or income opportunities. Initial forms collect contact details for subsequent calls or messages.
Why it matters
The reported sequence matters because the first page need not request payment or deliver malware. According to F6's findings as reported by The Record, later contact can introduce processing fees, requests for identity documents or an application that gives attackers device access. A modest initial request can therefore precede a more intrusive approach.
What remains unproven
F6 has not identified the operators, and the number of victims is unknown. The domain count measures infrastructure discovered by researchers; it does not measure successful fraud or losses.
Read beyond this page.
Recorded source-check date: 15 Sep 2026. A link is not, by itself, evidence that every claim has been independently verified.
Changes & version history
Version 3 · 15 Sep 2026
Scheduled release of checksum-bound AI-assisted editorial review
Version 2 · 15 Sep 2026
Checksum-bound editorial review scheduled for release
Version 1 · 15 Sep 2026
Source-linked private review edition
