Cloned company sites stole B2B advance payments
A campaign cloned Russian corporate websites to steal B2B advance payments. Learn its tradecraft, warning signs and payment controls.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 29 July 2026
- READING TIME
- 15 min read
- TOPIC
- Human Security
On 29 July 2026, researchers described a B2B fraud campaign in which criminals spent years cloning the websites of established Russian companies, impersonating their sales teams and directing foreign counterparties to transfer advance payments into controlled accounts. F6 associated almost 100 fraudulent domains with the operation, while the oldest infrastructure traces date to 2017.
This was not a basic phish with one misspelling and a fake invoice. The fraudsters created a credible transaction context: they copied the identity of companies in fertiliser, petrochemicals, metallurgy, logistics and banking, prepared documents, conducted conversations and supplied payment details. The campaign shows why supplier verification cannot depend on a polished website, corporate signature or a document provided by the same person asking for money.
What the 29 July reporting establishes
The Hacker News reported F6’s investigation findings, presented as research into long-running infrastructure. According to the publication:
- nearly 100 domains impersonating existing companies were identified;
- activity goes back to at least 2017;
- fraudulent businesses communicated in English, French, Arabic and Russian, among other languages;
- contact started through messages, commercial enquiries or telephone calls;
- targets received a cloned website, contracts, invoices and banking details;
- at least one Azerbaijani company reportedly lost $150,000 in April 2025;
- recurring infrastructure included
212.127.73[.]235and167.86.100[.]68.
The $150,000 figure describes one reported case, not the campaign’s total proceeds. The public material does not provide a full victim count or a confirmed aggregate loss, so one transaction should not be extrapolated across every domain.
How the fraud path worked
The model was tailored to international trade, where a large order, lengthy negotiation and prepayment can be normal. A criminal first built the credible identity of a salesperson or intermediary. A prospective buyer received an offer for a product whose price, supply or availability encouraged quick action.
The fraudster then reinforced trust through several layers:
- a domain resembling the genuine company’s brand;
- a website copied from the legitimate service;
- names of real employees or executives;
- documents presented as contracts, specifications and invoices;
- a telephone conversation in an appropriate language;
- a bank account described as belonging to the supplier or its subsidiary.
Every layer appeared to validate the previous one, but all of them could originate from a single source—the fraudster. This is the problem of false evidence independence. If the domain, telephone number, document and account number all arrived through one correspondence channel, they are not four independent confirmations.
Why cloning a real company is effective
The criminal does not need to invent a brand, history and portfolio. A legitimate company has already invested in reputation, search visibility, plant photography, certificates and documentation. Copying those materials creates a false corporate presence much faster than building a fictional enterprise from scratch.
An international buyer may not know the local company register, tax-number format, banking customs or language. A one-letter domain difference, extra hyphen or different country suffix may not look suspicious. An attractive price, limited stock or the prospect of losing a contract creates further pressure.
The campaign included a particularly deceptive device: criminals also cloned legitimate companies’ warnings about fraudulent websites but changed the reference to the real domain. A visitor could see an “avoid fraud” notice on a fraudster-controlled site and accept it as authenticity evidence.
More than conventional Business Email Compromise
The mechanism shares BEC characteristics: partner impersonation, business-process manipulation and payment diversion. It does not necessarily require access to a genuine mailbox. In the cloned-supplier variant, an attacker builds a parallel identity and acquires a new customer before a legitimate relationship exists.
That distinction changes detection:
- conventional BEC focuses on a bank-account change inside an existing thread;
- fake-supplier fraud requires validation at the very start of the relationship;
- SPF, DKIM and DMARC on the real domain will not stop mail from a lookalike attacker domain with valid configuration;
- a secure email gateway may pass a malware-free document because the attack depends on persuasion;
- an invoice scanner may correctly read an account number without verifying its owner.
The defence therefore depends on procurement and payment controls, not only a technical email filter.
Who faces the highest exposure
The target population includes anyone who can start a supplier relationship, approve an advance or alter counterparty data:
- procurement teams;
- international sales and trade;
- accounts payable and treasury;
- operations directors;
- brokers and intermediaries;
- logistics and import functions;
- small companies where one person creates a supplier and releases payment.
Risk increases when the organisation rewards speed, does not segregate duties or accepts account confirmation through the same channel that delivered the invoice.
A step-by-step supplier verification process
Secure onboarding must create an independent trust path.
1. Find the legal entity outside the received message
Do not treat the offer’s domain as your sole source. Find the company through an official registry, trusted chamber of commerce, prior industry documentation or a known partner. Compare the legal name, registration number, address, directors and domain.
2. Examine domain history
A recent registration is not automatically fraudulent, but a long-established international corporation rarely moves all sales activity to a domain created days earlier. Review registration time, historical DNS, TLS certificates and confusingly similar names.
3. Confirm the individual through an independent channel
Call a number found in an independent source, not the signature of the suspicious message. Ask the switchboard to connect you to sales. If the contact claims to represent a subsidiary, verify its existence through the parent.
4. Verify the bank account
A bank logo and professional PDF are insufficient. Check the beneficiary, account country, currency and business rationale. A personal, intermediary or unrelated-jurisdiction account requires escalation. Confirm every account change again through an independent path.
5. Segregate creation and approval
The person creating a supplier record should not single-handedly approve its first advance. Four-eyes control should cover both counterparty data and payment.
6. Start with controlled exposure
Where the business model allows it, limit the first order, use a letter of credit, escrow, trade-credit insurance or another mechanism that reduces exposure. A “small test payment” alone does not prove honesty—a criminal can deliberately fulfil it to build confidence.
Warning signals for finance and procurement
One signal may have a legitimate explanation. A combination should stop the process:
- the domain differs from the one in an independent register;
- a long-established company uses a newly registered domain;
- pricing is far below the market and expires quickly;
- the seller refuses a video call, visit or contact through headquarters;
- the account is in a country unrelated to the supplier or delivery;
- the beneficiary does not match the contract’s legal entity;
- an intermediary insists on full prepayment;
- documents use inconsistent names, addresses or registration formats;
- every discrepancy is explained through “sanctions,” “restructuring” or a “new subsidiary” without independent evidence;
- an anti-fraud notice names a different legitimate domain than official registries.
Responding after a transfer
Time is critical. If funds may have reached a fraudster:
- contact the bank immediately and request a hold, recall or freeze;
- provide beneficiary details, correspondence, the invoice and chronology;
- notify law enforcement and the relevant response body for the jurisdiction;
- preserve messages in original format with headers, files and call records;
- contact the genuine company through an independent channel;
- block domains and accounts in organisational systems;
- establish whether the fraudster obtained documents that could be used against other partners;
- warn other transaction participants without publicly disclosing investigative detail.
Do not wait for absolute certainty before calling the bank. Recovery is more likely before the money moves through additional accounts.
Source findings versus Breachroad conclusions
Reporting based on F6’s investigation supports the campaign’s longevity, nearly 100 domains, sectors, languages, repeated infrastructure and the stated loss case. It does not publish a complete victim list or global loss figure.
The onboarding, segregation-of-duties, independent callback and first-transaction controls are Breachroad defensive recommendations. They are not claims about how every victim operated.
What an organisation should change today
- require independent verification for every new supplier;
- call back on a number found outside the received correspondence;
- block payment when the beneficiary does not match;
- apply four-eyes control to onboarding and the first advance;
- monitor domains similar to key partner names;
- rehearse both BEC and fake-supplier scenarios;
- maintain a 24/7 bank-escalation route for suspicious transfers.
The best procedure still fails if employees are punished for pausing an “urgent” transaction. Corporate cybersecurity and phishing training teaches finance, sales and procurement teams to recognise manipulation inside real business processes. Complement it with our guides to Business Email Compromise and vishing.
An IT security audit can assess supplier-approval flows, financial-system permissions, domain protection and incident readiness. In this fraud model, payment governance is as important as email security.
Test the process, not only the employee
Run a tabletop in which procurement receives a polished offer, cloned website, call and documents. Introduce subtle discrepancies only before payment: a young domain, foreign beneficiary and advance-payment pressure. Measure whether staff find an independent number, who can pause onboarding, whether the system enforces a second approval and how quickly the bank can be reached.
Connect the findings to the Cyber Threat Intelligence lifecycle and monitoring for domains resembling your organisation and key partners. The Breachroad Academy gives non-technical employees a common foundation for evidence verification.
The decisive metric is the percentage of new or changed bank accounts confirmed through a channel independent of sales correspondence. If the organisation cannot measure it, it does not know how many payments depend entirely on trust in an inbox and website.


