Cybercriminals have started using a new attack scheme against Russian industrial enterprises. In July 2026, the cybersecurity company F6 recorded a massive phishing campaign targeting 500 organizations. The attackers impersonated federal agency employees and demanded confidential data on drone protection.
In letters with the subject "On measures to ensure safe working conditions for employees" sent on behalf of the acting head of a department, enterprises were asked to provide drone and missile shelter schemes, evacuation routes, personnel instructions, and procedures for air raid alerts. Attachments in Word and PDF formats did not contain malicious software but were drafted in an official style with a short response deadline to provoke data leakage.
Several details indicated the fake origin of the letters. The emails were sent from a free email service, and the reply address was registered in the .digital domain zone instead of the official .ru. The contact phone number linked to the domain pointed to another country.
The fake letters allegedly guaranteed employees the right not to report for duty during an air raid alert without the threat of dismissal, only requiring them to notify management. Employers were obliged in the letter not to allow personnel into dangerous areas and to approve shelter and evacuation schemes in the coming weeks.
Read more on the topic:
- Scammers started using a scheme with fake UAV alerts
- Hackers Hacked Russian Aircraft Manufacturing Enterprises Through Fake Letters from Government Agencies
- UAV attacks as bait: Russians are led from alarming Telegram channels to fake "payments"