Types of fraud

Phishing (via SMS, email, calls)

The targeted distribution of false messages imitating official notifications from banks, payment systems, marketplaces, or government agencies

QR Code Scams

Use of fake QR codes that lead to fake payment pages or change transfer details

Social engineering

A method in which scammers use psychological techniques to obtain confidential information, access systems, or induce the victim to perform certain actions.

Fake websites and apps

Creating copies of official websites and mobile applications to steal personal data or money

Fraud in messengers

Fraud through popular instant messengers (Telegram, WhatsApp, Viber, etc.), often using fake accounts

Financial Security: What Everyone Needs to Know

Social engineering

  • Posing as an employee of a bank, law enforcement agency, or government agency in order to persuade the victim to hand over card details.

  • Creating a sense of urgency

    — “Your account is blocked, transfer money to a “safe” account.”

  • Pressure on emotions (fear, greed, sense of duty).

Phishing (via SMS , email, calls)

  • SMS with a link to a fake website to enter login/password.

  • Email with a fake form or invoice.

  • Calls (vishing) , where the attacker, posing as a bank security service, clarifies “confirming data”.

Fake websites and apps

  • A domain that is similar to the official one, but contains extra characters or errors.

  • Missing HTTPS certificate or fake certificate.

  • Requirement to enter full card details, CVV code, and online banking passwords.

QR code scams

  • Putting a fake QR sticker over the original in a cafe, store or parking lot.

  • Sending QR code in a messenger "for payment" with substituted details.

Fraud in messengers

  • The scammer pretends to be a friend or relative and asks for an urgent money transfer.

  • Creation of fake groups or channels with “investment projects” and promises of high profits.

  • Sale of non-existent goods/services with a requirement for prepayment.

Поделитесь

Common schemes: browse by category

Common Scams - Recognize Them Right Away

Practical recommendations

This section contains simple and effective tips to help reduce the risk of fraud and keep your finances safe. By following these recommendations, you can recognize threats early and protect yourself from fraudulent activity.

Never disclose codes, PIN, CVV

Banks and payment systems never request your PIN, card CVV, or one-time passwords from SMS or push notifications. If you receive a call or email with such a request, it's 100% a scam. Even bank employees, law enforcement agencies, or government agencies don't need this information to help you.

Check the website address and phone number

Before entering your details, make sure the website uses HTTPS (see the lock in the address bar). Check the domain name (scammers often substitute letters or use similar symbols, such as "bunk" instead of "bank"). When calling, check the number—it's best to call the official bank number listed on the website or card.

Set limits on transactions

Set daily and one-time limits for cards and accounts in mobile banking. Limits will help minimize damage in the event of a card or account compromise. For large transactions, use pre-approval (via the call center or app).

Set up transaction notifications

Enable SMS or push notifications for all incoming and outgoing transactions. Prompt notifications will help you quickly spot unauthorized charges and block your card.

Use Face ID/two-factor authentication

Enable biometric authentication (Face ID, Touch ID) to log in to the mobile app and confirm transactions. Activate two-factor authentication (2FA) in online banking and email services. This creates an additional barrier even if your login and password are stolen.

Fraud protection algorithm

First steps in case of fraud

First steps in case of fraud

Emergency measures

What to do immediately after contacting scammers: stop communicating, protect your money, change your passwords, and secure evidence. Here's a step-by-step guide for the first few hours and days, including what to do if funds have already been debited.

Read more

1. First steps (immediately, within 10 minutes)

Stop contact

  • Do not answer calls/messages, block the number/account.

Protect your money
  • Block your card/account in mobile banking or call the number on the back of the card/only on the official website.

  • Disable “fast payments”/transfers, temporarily lower limits.

Change your passwords
  • Online banking, mobile app, email, instant messaging, marketplaces.

Record the evidence
  • Screenshots of correspondence, phone numbers, links, account names, call times, amounts, and transfer details.

  • Don't delete messages and notifications.

2.    Within 24 hours

Notify the bank
  • Via the app/official Call Center: describe the situation, request an urgent blocking of instruments, cancellation/dispute of disputed transactions (if applicable).

  • Write down the request number and the employee’s full name.

Check your devices and SIM
  • If you installed AnyDesk/TeamViewer/"antivirus from the operator" at the request of unknown persons, delete it.

  • Update your OS/antivirus, check your phone/PC for malware.

  • If you experience signs of SIM swap (no network connection/SMS not arriving), contact your mobile operator immediately, have your SIM card reissued, and set a secret code for service.

Report to the service where you were deceived
  • Marketplace/social network/messenger/payment service – file a complaint against the seller/channel/bot, provide evidence, and request a block and assistance.

Contact law enforcement agencies in your region.
  • File a crime report (either electronically or in person).

  • Please attach screenshots, receipts, contact information of the scammers, and transfer details.

  • Save the incoming number (notification slip) and the contact information of the person in charge.

3. If the money has already been written off

Card/bank transfer
  • File a chargeback/claim immediately – deadlines are limited, so the sooner you file, the better your chances.

  • Provide the bank with all materials: screenshots, numbers, links, statements, receipts.

Transfer to a third party's wallet/card
  • Ask the bank to send a request to the recipient bank to freeze the funds (if still possible).

  • At the same time, file a complaint with the law enforcement agency.

Cash via ATM/terminal
  • Notify the bank of the location/time/amount; if available, save the receipt and security camera footage (if available through the store owner).

4. If personal/payment data has been leaked

  • Issue a new card, cancel automatic payments and relink them again.

  • Change passwords wherever you used old ones.

  • Check your service settings for any unknown devices/sessions – terminate them.

  • Enable notifications for all transactions and set low default limits.

  • Enable credit activity monitoring (if available from your bank/credit bureau) and set up alerts.

Further actions and data protection

Further actions and data protection

Statements, investigations, prohibitions

What to do if personal data has been leaked or money has already been lost: what to write to the bank, how to assist the investigation, and what mistakes to avoid.

Read more


1. What to tell the bank/in the application (template)

“Please record this report of fraudulent activity.

Date/time of event: ____.


Channel: call/SMS/messenger/website.

Amount and currency: ____.


Operation details (if any): ____.

Description: (briefly: how they contacted, what they asked for, what website they directed to).


Attachments: screenshots, numbers, links, receipts.
Please: block the instruments, prevent further charges, initiate a dispute/reversal of the transfer (if applicable) and provide the case number."

2. How to help the investigation

  • Save the original files and metadata (screenshots, PDFs, photos of screens with date/time).

  • Don't edit the conversation, don't forward it in pieces, it's better to export the entire chat.

  • Write down all new contacts of scammers, but do not engage in dialogue.

3. What NOT to do

  • Do not translate “refund fees”, “insurance”, “taxes” – this is a continuation of the scheme.

  • Do not provide codes from SMS/push, PIN, CVV, passwords, or card details.

  • Do not install software at the request of a “bank employee/law enforcement agency”.

  • Do not go to "refund addresses" and do not give documents to strangers.

  • Don't delete your messages and notifications - they are important evidence.

Financial Security: What Everyone Needs to Know

Checklist

  1. Stop contact → Block card/account → Change passwords + 2FA.

  2. Recording of evidence.

  3. Bank: application, challenge, application number.

  4. Platform/service: complaint and blocking of the scammer's account.

  5. Law enforcement agency: application with attachments.

  6. Devices/SIM: check, remove software, reissue if necessary.

  7. Monitoring: notifications, limits, statement control.

Поделитесь