What Happened
Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years. According to Russian cybersecurity vendor F6, the threat actors have set up clone websites of Russian companies across fertilizer manufacturers, petrochemical companies
Why It Matters
The article describes a long-running fraud campaign in which threat actors create cloned websites of major Russian companies across sectors such as fertilizer, petrochemicals, logistics, and banking to trick international B2B buyers into sending advance payments for non-existent goods.[1][2] Researchers report nearly 100 counterfeit domains, using lookalike domains, copied site content, and multilingual pages to target victims via cold calls, phishing emails, and fraudulent corporate websites.[1][3] From a RealGround perspective, while this specific campaign is not explicitly described as using AI, it illustrates a mature business-impersonation and web-cloning tradecraft that is increasingly being augmented by generative AI in similar scams, including large-scale cloned-law-firm scams and disinformation operations.[6][8][12] Organizations deploying AI agents for B2B workflows should treat lookalike-domain and business-impersonation campaigns as a critical threat scenario, and use Continuous AI Red Teaming to test whether their AI systems can be tricked into trusting or transacting with cloned entities, as well as to strengthen verification, domain-intelligence, and payment-validati
RealGround Analysis
This signal maps to malicious AI use. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.
Recommended Actions
- Restrict AI agent tool permissions and production write paths.
- Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
- Add human approval workflows for high-impact or state-changing actions.
- Run prompt injection and indirect prompt injection tests against affected workflows.
- Document the owner, control gap, and remediation deadline for this risk class.
Source
https://thehackernews.com/2026/07/nine-year-fraud-campaign.html
