Russian cybersecurity vendor F6 has disclosed a large-scale fraud campaign that has been operating for more than nine years, using lookalike websites of major Russian industrial companies to siphon advance payments from international firms. The campaign targets the international trade sector, where advance payments for industrial commodities are standard practice, and has documented confirmed losses of 93 million rubles — approximately $1 million.
The Clone Website Infrastructure and Fraud Mechanism
The threat actors behind the campaign set up clone websites that closely mimic the design, branding, and domain naming conventions of legitimate Russian companies across fertilizer manufacturing, petrochemical production, and other industrial sectors. International companies seeking to do business with legitimate Russian firms are directed to these clone sites through what appears to be a combination of targeted outreach and search deception. Once a victim company identifies a supplier through what it believes to be a legitimate company website, it makes an advance payment for goods or services that are never delivered.
Why the Clone Sites Are Difficult to Distinguish
The clone websites are designed to pass visual inspection by international procurement teams who may not be familiar enough with legitimate Russian company domains to spot inconsistencies. The attackers replicate not just the visual design but also the branding language, product listings, and contact formats of the real companies they impersonate. The difficulty of cross-border domain verification — where a buyer in one country tries to confirm whether a Russian company’s website is genuine — is the structural gap that the campaign exploits. F6’s research indicates that the clone infrastructure has been maintained continuously, with the operators updating domains and hosting as needed to evade takedown.
The 93 Million Rubles Documented Loss Floor
F6 documented confirmed cases totaling 93 million rubles, or approximately $1 million USD, in verified losses. The actual loss figure is likely substantially higher because only incidents that victims reported and F6 could independently verify are reflected in the count. The nine-year operational history suggests sustained financial returns for the operators, who have maintained the campaign infrastructure without significant disruption. The structure of international trade payments — where individual transactions often run into hundreds of thousands or millions of dollars for industrial commodity purchases — means that each successful fraud incident carries high potential value.
The Cross-Border Business Verification Gap
The campaign exploits a structural vulnerability in international business transactions: there is no standard mechanism for a company in one country to independently verify the authenticity of a counterparty’s website in another country. Official government registries of registered companies exist but are not always accessible in English, are not linked to company websites, and require domain-specific knowledge to navigate. The campaign operators have effectively commoditized this verification gap, running the clone operation as an ongoing business rather than a series of isolated incidents. The lack of a centralized, multilingual company verification system for cross-border trade creates an environment where clone websites can operate for years without detection by their victims.
Defensive Measures for International Trade Transactions
F6’s disclosure provides actionable guidance for international companies conducting business with Russian firms. Independent verification of company contact information through official government registries, use of verified payment channels, and confirmation of supplier identity through multiple independent sources before making advance payments are the primary defenses. For companies that regularly conduct cross-border commodity transactions, establishing pre-vetted supplier lists and requiring in-person or video-call verification for new counterparties before the first payment can eliminate the attack vector entirely. The nine-year lifespan of the campaign indicates that these basic verification steps are not yet standard practice across the international trade sector, leaving the attack surface open for continued exploitation over extended periods. Companies that trade with Russian industrial firms should treat domain verification as a formal step in their procurement process rather than an informal visual check.
