Skip to main content
LiMP VPN
All news

Scam Alert: Fake 'Cancelled Work Record' Hits Accounts

Scam Alert: Fake 'Cancelled Work Record' Hits Accounts

In short: On 24 July 2026 the Moshelovka anti-fraud project (part of the People's Front) warned of a new scheme: scammers pretend to be Social Fund (SFR) or Federal Tax Service (FNS) staff and claim a person's work record has been "cancelled" by a technical error. The goal is to panic the victim into handing over an SMS code, a Gosuslugi password or card details. State agencies never annul a work record by phone — treat any such call as fraud.

What happened?

Russia's Moshelovka project reported a fresh social-engineering wave built around a scary but false premise: that your official employment history — the basis for a future pension — has vanished. The pitch is deliberately alarming, because losing accrued years of work touches almost everyone. It is the same playbook we described in our report on the two-call SMS-code scam: manufacture urgency, then ask for the one thing that unlocks your account.

This is not an isolated trick. Through 2026 Gosuslugi has become a favourite target precisely because a single account links your identity, documents, benefits and often your bank — the same credential-theft logic behind fake-contract phishing. The account, not the work record, is what the attackers are really after.

How does the scheme work?

The sequence is consistent across reports:

1. The hook. A call or message arrives from someone claiming to be an SFR or FNS employee. They say a "technical failure" wiped your work record and that you now risk losing your pension or benefits.

2. The pressure. They create urgency — the problem must be "fixed" immediately, or you will supposedly lose money you have earned over years.

3. The ask. To "restore the record" or "process compensation", they ask you to read out an SMS confirmation code, log in on a fake copy of Gosuslugi, or share card details.

4. The takeover. With the code or password, they seize your Gosuslugi account — and from there reach your documents, linked services and money.

Why it works — and what it means for your data

The scheme succeeds because it pairs a genuine fear (losing a pension) with a trusted brand (state services). Under stress, people stop checking and start complying. But the mechanics are ordinary phishing: no system was hacked, and no VPN or antivirus is bypassed — the victim is persuaded to hand over the key themselves.

That is the important nuance about digital hygiene. A VPN encrypts your traffic and hides your IP on public Wi-Fi, which matters when you connect from a café or airport — see our features page. But no tool can protect an account whose owner voluntarily dictates the one-time code to a stranger. Technical privacy and human vigilance are two separate layers, and this scam attacks the second one.

What should you do to stay safe?

Never read out codes. No real SFR, FNS or Gosuslugi employee will ever ask for an SMS code, password or card number by phone. A request for a code is, by itself, proof of fraud.

Verify independently. Hang up and check your work record and personal account yourself by opening gosuslugi.ru manually — not via any link sent to you.

Turn on two-factor authentication for Gosuslugi and your email, and use a unique password there. If an attacker phishes one password, 2FA and a password manager keep the damage contained.

Protect the channel too. On public Wi-Fi, a no-logs VPN such as LiMP VPN keeps your login traffic encrypted; combine it with the habits above and read more privacy basics on our blog.

Sources

This report is based on coverage by RIA Novosti and Anti-Malware.ru (24 July 2026), citing the Moshelovka project.

Scam Alert: Fake 'Cancelled Work Record' Hits Accounts