Template Complaint to Law Enforcement Authorities for Victims of WYP.kz Open Download
Application template for requesting a payment deferral from the bank Open Download

Phishing

Theft of personal data, passwords, and account access through fake websites and malicious messages.

News | 72 countries, 260 brands, and 4,389 phishing domains

Group-IB researchers uncovered a large-scale smishing operation known as Error544. The campaign targeted users in 72 countries, abused the names of more than 260 brands, and relied on thousands of phishing domains to steal personal and financial information. In this video, we explain how the scheme worked, what tactics the attackers used, and how users can verify suspicious links before visiting a website.

News | 72 countries, 260 brands, and 4,389 phishing domains
10.06.2026 News | 72 countries, 260 brands, and 4,389 phishing domains
Phishing | Scammers create fake FIFA websites

Scammers actively exploit interest in football and major sporting events by creating fake FIFA websites. In this video, we explain how to identify fraudulent websites, what information scammers try to obtain, and what steps can help protect your personal and financial data.

Phishing | Scammers create fake FIFA websites
01.06.2026 Phishing | Scammers create fake FIFA websites
Phishing | AI can use personal data to create personalised phishing attacks
AI can already collect information about a person from publicly available social media profiles and use it to create highly personalised phishing attacks. Just a few posts may be enough for a fraudulent message to look convincing and appear tailored specifically to you. Stay vigilant: avoid clicking suspicious links, limit the visibility of your profile and enable two-factor authentication.

ИИ уже умеет собирать информацию о человеке из открытых соцсетей и использовать её для персонализированного фишинга.
Достаточно нескольких постов, чтобы мошенническое сообщение выглядело убедительно и “именно под вас”.

Будьте внимательны: не переходите по подозрительным ссылкам, ограничивайте публичность профиля и включайте двухфакторную защиту.

Phishing | AI can use personal data to create personalised phishing attacks
23.05.2026 Phishing | AI can use personal data to create personalised phishing attacks
Phishing | A “Bank Bonus” Turns into a Telegram Account Hijacking

Fraudsters use the names and logos of well-known companies to offer “bonuses” on Telegram and then gain access to users’ accounts.

In this post, we explain how this scheme works, how scammers take control of Telegram accounts, and provide practical recommendations to strengthen your account security and protect your personal data.

Phishing | A “Bank Bonus” Turns into a Telegram Account Hijacking
16.05.2026 Phishing | A “Bank Bonus” Turns into a Telegram Account Hijacking
News | SMS blasters — a new tool used by scammers

Scammers were sending phishing SMS messages on a massive scale using so-called SMS blasters — devices that imitate cellular base stations.

These devices forced nearby phones to connect to a less secure network, allowing attackers to bypass telecom operators' protections and send up to 100,000 messages per hour.

A group of suspects has been detained in connection with the case.

News | SMS blasters — a new tool used by scammers
08.04.2026 News | SMS blasters — a new tool used by scammers
Жаңалықтар | Instagram пайдаланушыларының деректерінің таралуы

17,5 миллионнан астам Instagram пайдаланушысының деректері таралғаны туралы ақпарат тарауда.

Аты-жөндер, электрондық пошта мекенжайлары мен телефон нөмірлері фишингтік шабуылдар мен аккаунттарды бұзу әрекеттерінде пайдаланылуы мүмкін.

Құпиясөзіңізді өзгертіңіз, екі факторлы аутентификацияны қосыңыз және күмәнді сілтемелерге өтпеңіз.

Жаңалықтар | Instagram пайдаланушыларының деректерінің таралуы
11.01.2026 Жаңалықтар | Instagram пайдаланушыларының деректерінің таралуы
News | Data breach at an OpenAI partner

On November 9, 2025, a data security incident occurred at Mixpanel, an analytics service previously used by OpenAI for web analytics.

According to OpenAI, this was not a breach of OpenAI's own systems. Passwords, API keys, payment information, chats, prompts and responses were not exposed.

However, attackers may have obtained account names, email addresses, approximate locations, browser and operating system details, referral sources, as well as user or organization IDs.

The main risk associated with this type of exposure is phishing and more convincing fraudulent messages impersonating trusted services. OpenAI stated that it has stopped using Mixpanel and is notifying affected users.

News | Data breach at an OpenAI partner
27.11.2025 News | Data breach at an OpenAI partner
Phishing | Fake advertisement for CTS travel cards

The Astana Cyber Police and CTS have warned about fake advertisements promoting supposedly discounted travel cards valid for six months for 1,250 tenge.

According to CTS, this information is false: such travel cards do not exist, and the advertisements redirect users to suspicious websites.

The purpose of these campaigns is to steal users' personal and banking information.

Phishing | Fake advertisement for CTS travel cards
04.11.2025 Phishing | Fake advertisement for CTS travel cards
News | Data leak at Discord

A data breach occurred at Discord following an attack on a contractor responsible for processing customer support requests.

The attackers may have gained access to support tickets, attached files and certain personal information belonging to users who contacted support.

Users who submitted documents, photographs, account information or other personal data may be at particular risk.

This material explains what information may have been exposed, why two-factor authentication is important and how to review your active sessions for suspicious activity.

News | Data leak at Discord
05.10.2025 News | Data leak at Discord
News | What are the dangers of public Wi-Fi?

Starting October 4, new rules for connecting to public internet networks will take effect in Kazakhstan.

Users will be able to authenticate in one of two ways: by entering a one-time SMS password sent to their phone number or by using a digital signature.

The changes are intended to improve security when using public Wi-Fi networks, which may pose risks to privacy, finances and personal data.

At the same time, questions remain about who will identify and shut down malicious Wi-Fi hotspots designed to steal digital signatures and other user data.

News | What are the dangers of public Wi-Fi?
24.09.2025 News | What are the dangers of public Wi-Fi?