Hundreds of fake government websites target users in Central Asia
The sites are designed to collect victims’ contact details, which scammers then use to target them through phone or email to steal money, personal information or gain access to their devices.
Cybercriminals have created hundreds of fake government and news websites to target people in Uzbekistan, Belarus and Tajikistan with bogus offers promising cash payments or passive income.
Researchers at cybersecurity firm F6 identified more than 360 fraudulent domains tied to the campaign. The sites are designed to collect victims’ contact details, which scammers then use to target them through phone or email to steal money, personal information or gain access to their devices.
The websites exploit people’s trust in government social programs, telling visitors they are eligible for financial assistance or can earn passive income through government-backed programs, according to the report released Monday.
Source: https://therecord.media/hundreds-of-fake-gov-websites-central-asia-scam
Related breach coverage
- Non-Zero-Day VPN Flaw Left Japan ‘s Government Shared Network Platform Exposed: 246,000 Records at Risk2026-09-15
Japan ‘s Digital Agency disclosed a VPN breach exposing 246,000 government employee records across 23 ministries. Detected June 25, publicly disclosed September 11. Japan ‘s Digital Agency disclosed that attackers exploited a vulnerability in a VPN device to access its Government Solution Service (GSS), potentially leaking personal information belonging to approximately 246,000 government employees, public […]
- Cisco Warns of Ongoing Exploitation of Critical Email Gateway Zero-Day2026-09-15
Cisco warns of a critical zero-day in Secure Email Gateway, exploited in the wild to gain root access through malicious emails. Cisco disclosed a critical zero-day, tracked as CVE-2026-76461 (CVSS score of 9.8), affecting Secure Email Gateway appliances. The flaw can be exploited remotely without authentication. Attackers can send specially crafted emails containing malicious SQL […]
- Personal, Financial Info Exposed in Revolut Data Breach2026-09-14
The company unintentionally disclosed users’ information to a third party impersonating a government agency. The post Personal, Financial Info Exposed in Revolut Data Breach appeared first on SecurityWeek.
- Revolut Exposed KYC Data After Fraudulent Government Email Passed Security Checks2026-09-12
Revolut handed over KYC documents, selfies, and Bitcoin transaction histories after a fake government email with valid domain credentials passed its checks. Revolut confirmed on September 12, 2026, that it disclosed sensitive customer data to an unauthorized third party after receiving fraudulent information requests sent from an email address operating inside an actual government agency’s […]