In the second quarter of 2026, Russian banks prevented 17.5 million attempts to steal almost 1.9 trillion rubles from clients. For comparison, from January to March, they stopped 16.8 million suspicious transactions totaling 1.8 trillion, according to the Central Bank's report.

Despite the increase in blocked attacks, fraudsters still managed to withdraw 7.35 billion rubles through 458.7 thousand transactions without the clients' voluntary consent. The volume of losses slightly decreased compared to the first quarter, and the share of returned money increased from 5.7% to 7%.

Most individual thefts involved bank cards — over 237 thousand cases totaling 1.3 billion rubles. Through the System of Fast Payments, attackers stole 2.74 billion rubles, and through remote banking services — another 2.17 billion rubles. However, only 2.1% of the stolen funds were returned to clients via SBP.

The number of attacks using social engineering increased the most — by almost 50%, to 28.7 thousand cases. Fraudsters are increasingly not hacking systems directly, but rather convincing people to transfer money themselves or disclose data. At the same time, the number of phishing attacks decreased by 5.3%, and incidents involving malicious software — by 10.5%.

In April 2026, the Ministry of Digital Development sent a package of amendments "Antifraud 2.0" to the State Duma: the document provides for a mechanism for returning stolen funds through "Gosuslugi", mandatory blocking of suspicious numbers by telecom operators, and the right of banks to refuse transfers if there are signs of malicious software — the main part of the changes should come into force on March 1, 2027.

Read more on the topic: