Vitebsk Regional Executive Committee

Digital Security

  • Cybersecurity
  • Information materials
  • digital security on the Internet
  • https://drive.google.com/drive/folders/1aFITanxXVUDBfyEBBiQLtrhGrsNI30w0
  • Telegram channel "Digital Literacy"
  • Information materials on the prevention and combating of cybercrime
  • Information on cybercrime prevention
  • Ensuring the security of payments on the Internet

    Currently, cybercrime poses a serious threat to the development of the economy and society. In recent years, the number of cybercrimes has significantly increased, requiring urgent measures to protect information and ensure cybersecurity. One of the main problems is the insufficient awareness of cybersecurity among the population. Many citizens do not take sufficient precautions when using the Internet, which makes them vulnerable to criminals.

    According to statistics, women are twice as likely to become victims as men. The absolute majority live in cities. People with higher education are equally susceptible to deception as those with secondary education. Among the victims of cybercriminals are mainly economically active citizens representing almost all spheres of activity – accountants, economists, directors, deputy directors of private and state institutions, heads of departments and divisions of state institutions, teachers, doctors and nurses, students, lawyers, programmers, and representatives of other professions.

    Scammers regularly change their deception schemes to steal people's money. The main forms of deception are telephone and Internet fraud, as well as phishing resources.

    TELEPHONE FRAUD – VISHING

    Scammers, posing as bank employees, telecommunication operators, or government agencies, contact citizens, create a stressful situation, report a problem, and then offer help in resolving it. To gain trust, they may send photos of official documents or even initiate a video call on a messenger.

    A common method is when scammers, using various fictitious situations, persuade potential victims to download a file sent via messenger or install a specific mobile application. In both cases, scammers gain the ability to remotely control the device on which it is installed. Thus, they gain access to users' personal data, including the ability to take out online loans. Scammers also persuade victims to take out loans from banks and transfer the money to a "secure" account.

    Always be vigilant and do not trust strangers, do not install unverified programs and files received via messenger from unknown sources under any pretext, do not transfer money to anyone, and do not transfer it to bank accounts at the instruction of strangers.

    In Orsha, a woman received calls from unknown numbers for several days. Eventually, she agreed to listen to a pseudo-investigator. He shocked her by stating that illegal transactions were being made from her account to fraudulent accounts and that it was necessary to prevent them and identify the perpetrators. The woman refused to believe him, so a supposed employee of a well-known bank, dressed in business attire with bank insignia, continued the conversation via video link. The woman believed the callers and, at their recommendation, installed an application that allowed the fraudsters to see everything happening on her phone, including SMS codes. During the conversation with the fake banker, she revealed her mother's maiden name as a code word, and then accomplices of the fraudsters used this information to arrange an overdraft and an online loan in the woman's name during the conversation and transferred the funds to their own accounts. In total, 18,000 rubles were stolen from the woman.

    To commit crimes, fraudsters study their victims, gathering data about them, their interests, social circle, and other information from the internet. Having a sample of the voice or photos of acquaintances, they can create fake text or video messages.

    For example, several similar incidents were registered in May. In a messenger, fraudsters created an account impersonating the head of a state organization and wrote to an employee, claiming that lists of workers suspected of financing extremist groups had been received, and that a search of the woman's home might soon be conducted, with undeclared funds being seized. The woman was very scared for her money because she trusted her supervisor. Subsequently, the fraudsters, acting as her supervisor, suggested she speak with the Head of the Regional Financial Investigations Department, who in turn connected her with an investigator. For three days, the woman lived in fear for her savings. To protect them, the fraudsters "advised" her to transfer them to a supposedly special secure account. The woman also took out a loan within a week, cashed it out, and transferred it to the same account, from which all the money, totaling 55,000, was soon stolen.

    Similar cases have been recorded involving pedagogical workers in the region, where fraudsters used messenger accounts impersonating the directors of educational institutions. More than 7 teachers reported to the police within 3 days, while some reported later. Primarily, the fraudsters persuaded teachers to take out loans from banks.

    Scammers regularly devise new ways to deceive people and obtain their money. They post advertisements on the Internet for supposedly investment platforms that do not actually exist, in order to lure investors and steal their money. The first step to contact a curator is to fill out a form, where you need to leave your name and phone number. Then, the interested party is contacted by a so-called curator, under whose guidance, in the hope of making easy money, the potential victim transfers money to an electronic wallet themselves. To get at least their invested money back, scammers demand payment of commissions, fees, etc. For some time, scammers show the victim their profits, until the deceived person runs out of money, after which contact with them is terminated. The money remains in the fraudulent accounts.

    A young Vitebsk resident became interested in the opportunity to invest his money in an investment project. After he followed the curator's instructions and transferred money to a digital wallet, the amount of his money supposedly began to increase; the young man saw profits in his account on the platform. However, as soon as he tried to withdraw the money, he was immediately blocked. He twice found firms on the internet offering assistance in withdrawing money, but none of the "firms" provided him with the proper services, after which the man turned to the police. In total, he lost more than 20,000 rubles.

    To avoid becoming a victim of a cybercriminal, end the conversation with an unknown person as soon as possible, no matter who they claim to be.

    FAKE STORES on social media

    Every day, people who have prepaid for goods found in advertisements on social networks and marketplaces and did not receive them also turn to the police. Scammers intentionally create accounts in the name of stores, where they post advertisements for non-existent goods at reduced prices (shoes, clothing, mobile phones, bedding, Christmas trees, garden hanging chairs-cocoons, and other goods). A potential buyer contacts the administrator of the "store," and they are promised delivery of the goods after full payment. Payment is offered to be made to a bank card or to an account via ERIP. However, after receiving the funds, the goods are not sent, and the buyer is blocked.

    PHISHING

    In order to obtain personal data of account holders, scammers create clone pages of banks, theater websites, hookah lounges, and investment (trading) exchanges.

    A young mother from Orsha, on maternity leave, transferred 2 thousand rubles for a phone to a provided account via ERIP but did not receive it. Then, scammers offered her to get her money back to her bank card. They sent a link in a messenger, and by clicking on it, the girl entered the card number and the secret code from the back, intended only for debit transactions, into the fields. Having obtained this information, the scammers deceived her again, withdrawing all the money from the card.

    To prevent this, it is necessary to:

    • consider the reasons for a low price of a product that differs from the price for the same product on the website, or be wary of why a store has no website;
    • carefully check information about the store: contact the seller via a Belarusian mobile number, not via the Internet;
    • use a separate card for online payments;
    • do not follow links from unknown persons;
    • check the page address where you enter card details (for Belarusian organizations, the address bar should look like this: "website name".BY/"website section");
    • enable the bank's free "3-D Secure" service in the card settings.

    SWATTING

    A trend called "swatting" is spreading in the youth gaming cyber environment. Its essence lies in creating an unfavorable situation for government agencies, disrupting their work, or taking revenge on an offender by creating problems for them with law enforcement agencies. In the first half of 2024, 4 schoolchildren were identified in the region, and in the previous 2 years – eight, who organized the sending of emails to the mailboxes of organizations in Belarus and other countries with false reports of bomb threats to facilities.

    All identified individuals are minors, the youngest swatter is 12 years old. All of them intentionally used de-anonymization methods and special software, which they believed would allow them to hide their tracks. The teenagers were interested in the topic of swatting and in most cases knew that criminal liability for committing these acts begins at 14 years of age and provides for up to 7 years of imprisonment.

    INVOLVEMENT IN CYBERCRIME

    To receive stolen money abroad and to obscure "digital footprints," fraudsters need to transfer it through intermediary accounts opened in Belarusian banks in the names of nominees, so-called "drops." Often, there are more than a dozen intermediary accounts. There are cases where illegally obtained money passed through 72 intermediary bank accounts, access to which fraudsters bought from their owners.

    In our country, a bank account can be opened by a legally competent citizen from the age of 14, meaning even minors can open bank accounts. Criminals exploit this. While abroad, offenders select individuals who agree to open a bank account in their name and sell access details for a small sum – these are logins and passwords for internet banking, as well as one-time SMS codes or code cards.

    Fraudsters cannot directly post advertisements online seeking such individuals, so they conceal their interest by offering various other seemingly legitimate earning opportunities. For example, in Telegram, they send out advertisements seeking couriers in any city with stable pay, or people for unloading goods, or individuals for the "mystery shopper" position, or they lure them with promises of high and quick payment.

    Most often, individuals with unstable or low incomes, predominantly young people, respond to such vacancies. Initially, the advertisement initiator informs the interested party that the vacancy has already been filled and immediately offers an alternative way to earn money, such as opening a bank account and transferring access details for a reward.

    In addition to money stolen by cybercriminals, funds obtained from illegal drug trafficking may also be processed through intermediary accounts. Account holders are responsible for the money that passes through their bank accounts.

    It should be noted that under our legislation, Article 222 of the Criminal Code provides for responsibility of up to 10 years of imprisonment for the creation for the purpose of sale or sale of bank payment cards or other payment instruments, such as bank accounts or electronic wallets, as well as the dissemination of access details to them.

    There are cases where minors have been involved in criminal activities.

    16 teenagers from two secondary vocational education institutions in the region, having contacted a customer from the Internet, registered bank cards in their names and, for a reward of 15 to 50 rubles, handed them over for use to unidentified persons. Using these bank cards, cybercriminals transferred stolen money. Criminal cases have been initiated against 8 teenagers, and checks are being conducted against the rest, with a decision being made on initiating criminal cases.

    In addition, there are examples of teenagers being involved in the criminal chain in other ways.

    A 14-year-old student from a Vitebsk school asked his 15-year-old classmate to temporarily use his bank payment card. The boy registered an account on a cryptocurrency exchange. Unknown persons contacted him and offered him to earn money. The young man provided the bank card details of his classmate, to which he received 10,000 rubles, and then bought cryptocurrency for the entire amount for them. During the check, it was established that the received money was stolen from a pensioner from Vitebsk.

    Thus, the student provided services for the purchase and sale of cryptocurrency to third parties, which entails liability for illegal entrepreneurial activity under Part 3 of Article 13.3 of the Code of Administrative Offenses of the Republic of Belarus. Conducting transactions on a cryptocurrency exchange by teenagers is not an isolated case. Over 450 thousand rubles passed through another teenager's crypto wallet.

    For conducting cryptocurrency transactions in favor of third parties, a large fine and confiscation of up to one hundred percent of the income received as a result of such activity to the state revenue are threatened.

    Appendix: leaflet on responsibility

    ENTERPRISES Cybercrimes aimed at seizing funds of economic entities, including state enterprises of the Republic of Belarus, are registered in the region.

    Hackers plan in advance and gain unauthorized access to the organization's data, turn it into a jumbled set of characters, and offer to decrypt it after transferring funds to the specified account. Attackers primarily rely on human errors and weaknesses, rather than on software vulnerabilities, which are much more difficult to overcome.

    It is necessary to understand that an attacker will not be able to achieve their goal and steal funds if the attack is detected and stopped in a timely manner. This is possible at any stage of the attack by taking appropriate protective measures aimed at preserving well-being, including by employees adhering to the following rules:

    1. ensure an adequate level of information security in accordance with the development and updating of software, as well as the regulatory legal acts of the Republic of Belarus
    2. regularly back up important data;
    3. never trust the sender of an email, double-check the information provided, as well as the main identification data and header information of emails (you can find out and analyze the sender's IP address and other necessary information) before replying to the email, even if it is from a long-term partner from a new address;
    4. do not click on links or open attachments if the sender of the email is not who they claim to be;
    5. in case of changes in the settlement account details of a partner, verify this fact through any other communication channels (in person, by phone, etc.);
    6. use the EDS (electronic digital signature) key directly when working with the relevant software, and remove it from the USB port after finishing work;
    7. carefully check the website address and domain, and the date of its creation;
    8. promptly change passwords for accounts, including when relocating, dismissing, or hiring a new employee;
    9. immediately change the password and/or block accounts if access details are entered on a suspicious website;
    10. always be vigilant and verify the information received.

    Department for Combating Cybercrime of the Internal Affairs Directorate of the Vitebsk Regional Executive Committee

Vitebsk Regional Executive Committee