More than 360 fake government websites central asia residents could encounter have been tied to a fraud campaign aimed at people in Uzbekistan, Belarus and Tajikistan, according to cybersecurity firm F6. The domains pose as government portals or regional news outlets and advertise financial aid or government-backed passive-income programs, turning public trust in social benefits into a collection funnel for scammers.
F6’s findings, reported by The Record, have not been independently tied to a named criminal group. The number of people who lost money or data in the campaign is also unknown.
How do the fake government websites trick people?
The first step is deliberately low-friction. Visitors are told they qualify for a payout and asked for basic contact information, often a name and phone number. In Uzbekistan, some fraudulent pages promised weekly payments of 15 million Uzbek sums, about $1,300, according to F6.
Some domains are bare landing pages with a form. Others do more production work: they imitate regional news sites, publish fabricated reports about assistance programs, and send readers to questionnaires. The point is not the webpage itself. It is getting a phone number or email address that lets the operators continue the fraud away from the browser.
After someone submits details, the operators may call while claiming to be a personal manager. F6 said those callers can demand a commission or processing payment before releasing the supposed benefit, request additional personal information, or try to obtain access to the target’s device.
The higher-risk version involves an app presented as necessary for enrollment or identity verification. F6 said the app is malware that can give an attacker control of the device and could enable theft from a victim’s accounts. Other targets have reportedly been asked to provide passport scans, documents that can be reused in further fraud, including attempts to take loans in a victim’s name or run phishing schemes.
What should visitors watch for?
- A government-payment offer promising unusually large or recurring sums.
- A form requesting a name and phone number before providing verifiable program information.
- A follow-up caller claiming to manage a benefit application.
- A demand for a fee or commission to receive money that was advertised as assistance.
- A request to install an app for registration or identity checks.
- A demand for a passport scan as part of the claimed verification process.
Those signals describe the methods F6 observed, rather than proof that every site using one is fraudulent. Still, the campaign’s design is clear: a convincing-looking public-service page is used to start a conversation, then the operators seek money, identity documents, or control of a phone. F6 has not identified who runs the domains, leaving both attribution and the campaign’s real-world toll unresolved.
This story draws on original reporting from The Record.