Russian Company Clones Have Diverted B2B Advance Payments Since 2017

On July 29, 2026, F6 disclosed a coordinated fraud campaign that has cloned major Russian companies’ websites since 2017. Investigators identified nearly 100 counterfeit domains used to steal advance payments from international B2B buyers; one Azerbaijani company lost an estimated $150,000 in April 2025.
Why conventional supplier checks fail
The operators impersonate fertilizer producers, petrochemical companies, metallurgical plants, logistics providers, and banks. Most content is copied from genuine websites, while contact details are replaced so that inquiries go directly to the criminals.
Victims are approached through phishing emails, cold calls, and multilingual websites in Russian, English, Arabic, and French. Unsuspecting sales representatives have also been recruited to open negotiations before handing prospects to a fraudulent “senior manager.”
A complete imitation of a commercial deal
The criminals send convincing offers, contracts, and invoices carrying fake corporate email addresses and bank accounts. Earlier operations favored .ru domains, while newer replicas increasingly use .com, .org, and .net. Much of the infrastructure shares DNS records, registration data, and the IP addresses 212.127.73.235 and 167.86.100.68.
“A significant portion of the infrastructure shares common DNS records, IP addresses, and other registration data, indicating that these websites are part of a single coordinated campaign,” said Elena Shamshina, technical lead at F6’s Threat Intelligence Department.
The level of replication extends beyond corporate pages. After legitimate businesses published warnings about fraud, the operators copied those notices onto the clone sites and changed the domain references. In a documented 2017 case, fake fertilizer contracts used official-looking letterhead but substituted payment details controlled by the criminals.
For importers and exporters, visual authenticity is no longer sufficient evidence of a supplier’s identity. Businesses should verify the legal entity, subsidiary, domain registration date, contact details, and beneficiary account through independent registries and previously validated channels before approving any transfer.

