Typical situations of committing high-tech crimes

1. After gaining unauthorized access to user pages on social networks, an attacker sends messages to users in the "Friends" section, requesting assistance with money transfers under various pretexts: "Hi, could you lend me some money, I'll return it in a couple of days," "Hi, please put 10 rubles on my phone, I'll pay you back," "Hi, can I transfer my money to your card, as my card has expired (or I can't transfer to my own)." Subsequently, the attacker gains the trust of sympathetic users and, allegedly for the purpose of transferring funds to them, asks for their bank card details and codes from SMS messages. As a result, the user, misled about the identity of the sender and unaware of the criminal intent, provides this information. The attacker then gains access to the user's funds and steals them. After conducting an unauthorized money transfer, the attacker often informs the user that something is not working and asks them to repeat the actions with a different card (belonging to relatives or acquaintances).
2. On trading platforms such as "Kufar," "Baraholka," etc., an attacker finds an advertisement posted by a user for the sale of property. The attacker then contacts the user via various messengers, expressing a desire to purchase the advertised property but stating an inability to pick it up due to various reasons. The attacker offers to pay by transferring funds to the user's bank card. Once the user agrees, the attacker sends them a link to a phishing page of a banking institution (the page may visually resemble an internet banking page, differing only by a symbol in the website's domain name address bar). Upon clicking the link,
at the provided link, the user does not notice that they are not on the active internet banking page of a specific bank. In the opened window on the specified website, the user is typically prompted to enter their internet banking login and password, or passport details, as well as codes from SMS messages. After entering this information, the user is usually informed of an error or non-payment. At this time, the attacker sees all the entered information and enters it on the actual bank's website, thereby gaining access to the user's funds and stealing them. After conducting an unauthorized money transfer, the attacker often tells the user that something is not working and asks them to repeat the actions with a different card (of relatives or acquaintances).
3. On marketplaces such as "Куфар", "Барахолка", etc., the attacker
posts an advertisement for the sale of a popular item, often at a price below market value. Users who see the advertisement contact the advertiser, and during the correspondence, the attacker claims they cannot meet to hand over the item and suggests using services like "Доставка Куфар", "Белпочта (ЕМС)", "courier service (СДЭК)", etc. If the user agrees, the attacker sends the user a link to a phishing page of a delivery service. On this website, the user is typically prompted to enter their bank card details to pay for the goods or courier services, or provide passport details, mobile phone number, and codes from SMS messages. After entering this information, the user is usually informed of an error, or the website stops loading (freezes). At this time, the attacker sees all the entered information and enters it on the actual bank's website, thereby gaining access to the user's funds and stealing them. After conducting an unauthorizedan attempted money transfer operation, the attacker often informs the user that something is not working, and asks them to repeat the specified actions with a different card (of relatives or acquaintances).
4. The individual receives an incoming call on their mobile phone from an attacker. As a rule, in this method, the attacker uses a phone number spoofing service and provides a subscriber number belonging to a bank or similar to it. The attacker then introduces themselves as a bank employee (they may use the user's name and patronymic, as well as mention part of the bank card number, or information about recently made payments). The attacker reports suspicious money transfer operations for large sums to card accounts of foreign banks. When the user states that they have not made any such operations, the attacker informs them that these operations need to be blocked, and therefore asks the user to provide specific bank payment card details or passport data, after which they inform the user that they are sending SMS messages with codes that the user will need to provide after an audible signal. At this time, the attacker enters all the received information on the bank's actual website, after which they gain access to the user's funds and steal them. Also, in our country, one of the common types of cybercrime is the theft of subscriber funds through mobile banking. Scammers, under various pretexts, ask citizens for their phone, and, pretending to dial a number, actually activate the mobile banking service using a USSD request or internet access, which allows them to carry out payment transactions from the subscriber's account and obtain a limited microloan from the mobile operator.