THE ESSENTIALS
  • More than 360 domains reported.

What changed

The Record reports that F6 researchers identified more than 360 fraudulent domains impersonating government programmes and news outlets. The campaign targets people in Uzbekistan, Belarus and Tajikistan with supposed payments or income opportunities. Initial forms collect contact details for subsequent calls or messages.

Why it matters

The reported sequence matters because the first page need not request payment or deliver malware. According to F6's findings as reported by The Record, later contact can introduce processing fees, requests for identity documents or an application that gives attackers device access. A modest initial request can therefore precede a more intrusive approach.

What remains unproven

F6 has not identified the operators, and the number of victims is unknown. The domain count measures infrastructure discovered by researchers; it does not measure successful fraud or losses.

THE EVIDENCE RECORD

Read beyond this page.

Recorded source-check date: 15 Sep 2026. A link is not, by itself, evidence that every claim has been independently verified.

  1. The Record ↗
Changes & version history

Version 3 · 15 Sep 2026
Scheduled release of checksum-bound AI-assisted editorial review

Version 2 · 15 Sep 2026
Checksum-bound editorial review scheduled for release

Version 1 · 15 Sep 2026
Source-linked private review edition

Request a correction ↗