In short: On 23 July 2026 State Duma deputy Anton Nemkin and analysts at Anti-Malware.ru warned of a new scheme. Fraudsters call while posing as Russian Post staff, mention a letter or parcel, and — under the pretext of confirming your address — steer you into a fake Telegram bot that mimics the official service. There they extract personal data, card details and SMS codes. A real postal service never asks for a code or a move to a third-party bot.
What happened?
Russian media and security experts reported a fresh social-engineering wave built on a familiar, trusted brand: the national postal service. The caller claims a registered letter or parcel is waiting and that they only need to "confirm the delivery address". The request sounds harmless — almost everyone is expecting some package — which is exactly why it works.
This is the same manufactured-trust playbook we described in our report on the two-call SMS-code scam: impersonate an institution, create a plausible reason to talk, then move the victim to a channel the attacker controls. The novelty here is the destination — not a phishing website, but a counterfeit Telegram bot dressed up as an official assistant.
How does the scheme work?
The sequence reported across sources is consistent:
1. The call. Someone claiming to be a Russian Post employee says a letter or parcel needs to be delivered and asks you to clarify your address.
2. The redirect. To "process" the delivery, they ask you to open Telegram and use a bot that supposedly belongs to the post office. Attackers copy the official service as closely as possible to disarm suspicion.
3. The extraction. Inside the fake bot you are asked for personal details, bank-card data and an SMS confirmation code.
4. The theft. With that code or those card details, the criminals seize accounts, authorise payments or link your number to services under their control.
Why it works — and what it means for your data
The scheme succeeds because it fuses everyday plausibility (a waiting parcel) with a trusted name. Under mild time pressure people stop verifying and start following instructions. But the mechanics are ordinary phishing: nothing is "hacked". The victim is persuaded to hand over the key themselves, which is why the same logic also drives fake-contract phishing and copycat-chat scams.
That points to an important nuance about digital hygiene. A no-logs VPN encrypts your traffic and hides your IP on public Wi-Fi — vital when you connect from a café, a post office queue or an airport — as explained on our features page. But no tool can protect an account whose owner voluntarily dictates a one-time code to a stranger. Technical privacy and human vigilance are two separate layers, and this scam attacks the second one.
What should you do to stay safe?
Never move to a bot or link a caller sends. A real postal service will not route you into a Telegram bot to "confirm" a delivery. Any such request is a red flag — end the call.
Never read out codes. An SMS code, card number or password requested by phone is, by itself, proof of fraud. No legitimate operator needs them.
Verify independently. Check a shipment yourself through the official app, website or a tracking number you looked up — never through contacts the caller provided.
Harden your accounts. Turn on two-factor authentication and use a unique password per service; a password manager and 2FA contain the damage if one credential leaks. On public Wi-Fi, a no-logs VPN such as LiMP VPN keeps your traffic encrypted — combine it with the habits above and read more privacy basics on our blog.
Sources
This report is based on coverage by Moscow 24 and Anti-Malware.ru (23 July 2026), citing State Duma deputy Anton Nemkin via RIA Novosti.
