F6: Nine-Year Clone Site Campaign Stole B2B Advance Payments
F6 exposed a nine-year campaign cloning Russian industrial company sites to steal advance payments from international buyers.
Russian cybersecurity firm F6 published research Tuesday exposing a fraud campaign that has been running for at least nine years: threat actors built lookalike websites for legitimate Russian companies — fertilizer manufacturers, petrochemical firms, and other industrial suppliers — then collected advance payments from international buyers who thought they were placing real orders.
The Hacker News reporting on F6’s research confirms the campaign spans multiple industrial sectors. Nine years is not an oversight. Nine years means the operation covered its costs and then some, repeatedly.
How the fraud worked
The mechanics are simple. Fraudsters registered domains closely mimicking the names of legitimate Russian industrial companies, dressed up those sites with copied branding and product information, then waited for international procurement contacts to land there through searches or forwarded links.
Buyers submitted orders through the fake portals, wired advance payments — standard practice for large-volume commodity purchases — and received nothing. By the time the discrepancy surfaced, the payment was gone.
Fertilizer and petrochemical procurement fits the attack profile well: high invoice amounts, normalized advance payment terms, international wire transfers, and buyers who may be purchasing from a supplier for the first time through an online search rather than a warm introduction.
What doesn’t fix this
No software patch addresses vendor impersonation at the domain level. No endpoint agent detects an international wire going to a bank account associated with a lookalike domain. The attack operates entirely in the gap between “we found a website” and “we verified this is actually the company we think it is.”
Spending money on more security tooling will not close that gap. Process does.
What actually helps
For procurement teams sourcing from international industrial suppliers:
-
Out-of-band verification before any wire. Don’t use contact details from the website or order confirmation. Look up an independent contact — through official trade registries, a prior relationship, or a direct referral — and confirm banking details through that channel before transferring anything.
-
Domain registration checks. A supplier your company has been buying from for a decade should not have a website registered six months ago. WHOIS lookups are free. Make them part of your supplier onboarding checklist.
-
Treat payment instruction changes as red flags. Any mid-transaction request to update bank details or wire coordinates should halt the transaction and trigger re-verification through a known-good contact. This is identical to standard business email compromise defense — the fraud vector is the same.
-
Register your legitimate supplier contacts early. Before a transaction begins, establish a verified point of contact through a channel you initiated — not one that arrived unsolicited. Procurement staff receiving a new “preferred contact” email mid-deal should treat it as suspicious until independently verified.
Priority call
If your organization sources goods from Russian industrial suppliers, review your advance payment verification workflow. F6’s disclosure doesn’t suggest the campaign wrapped up — nine years of operational persistence suggests the opposite. Until there’s a confirmed takedown or arrests, assume it continues.
For reference: the Spain BEC ring dismantled last month moved €140 million through 800 accounts using comparable payment-diversion mechanics. The fraud vector is proven and replicable. The defense is boring and manual and works.
Found this useful? Share it.


