EN

Why scammers know your bank, address, and recent activity

· · The Ateo Digital editorial team

When a scam caller addresses you by your full legal name, knows which bank you use, and mentions a “recent purchase,” this is not magic and not “wiretapping via SORM.” It is a standard scheme: database leak → aggregation in a Telegram bot → social engineering → pressure through urgency. The chain is well known and described in publications by TASS and foreign investigations.

Understanding the scheme takes away its main weapon — the effect of “they know everything about me, so it must be true.” When you know where the caller got this data, the conversation stops being frightening.

Below is exactly how the scammer gathers context, how the call is structured, and which three simple rules stop any such attack.

In brief

  • Knowledge of your full name, bank, and address is not “wiretapping,” but the result of several leaks being merged.
  • Databases are bought for a few hundred roubles in Telegram bots — this is publicly available infrastructure.
  • The call itself is social engineering: a cover story, pressure, urgency, and a threat.
  • Protection is not in technology, but in the rule “do not act on an incoming call.”
  • Two-factor authentication not by SMS, but through an app, is the best technical protection.

How a typical attack works

An attack on an ordinary person is rarely “personal” at the beginning. It is an assembly line: victims are called by the hundreds per day, using a list with basic details. The context is filled in on the fly.

Step 1. Collecting the database

The input is a bundle of “full name + phone number + bank.” This is already available in ready-made form after major leaks in 2023–2025 (see our analysis of the scale of the leaks). Using one phone number, a profile can be assembled in a Telegram bot within a few minutes: bank, region, and sometimes recent purchases and delivery address.

Step 2. Choosing the cover story

The scammer chooses a scenario based on the profile. For pensioners — “a call from social services.” For an active online banking user — “the security service.” For someone who has a loan — “a restructuring specialist.” For someone who recently made a transfer — “transaction cancellation.”

Step 3. Social engineering and scareware

The call is built from a template: an introduction (name, position, identifier), mention of context known to the victim (bank, last transaction, address), creation of fear (“someone is trying to debit your account,” “a loan has been issued in your name”), and a demand for urgent action (dictate a code, transfer money to a “safe account,” open an app for remote access). The main technique is urgency: the victim is not allowed to think.

Step 4. Confirmation and closing

If the victim starts to hesitate, they bring in a “colleague” with another role — an “Interior Ministry investigator” or a “Central Bank employee.” This increases trust: “several different people are saying the same thing.” At this moment it is important to remember: they are all calling from the same preassembled database.

Signs of a scam call

SignalWhat it meansWhat to do
The “bank” calls, but asks for a code from an SMSA bank never asks for the codeHang up and call back using the number on the card
“Urgently, or things will get worse”Classic pressure through urgencySay “I will call back in 30 minutes” and hang up
They ask you to install “AnyDesk” / “Rust Desk”This is remote access to your phoneNever install it — banks and the police do not ask for this
“This is an Interior Ministry investigator, do not tell anyone”The police do not forbid you from contacting relativesHang up and contact a relative
“Transfer it to a safe account”“Safe accounts” do not exist at banksStop the conversation; file a complaint with the bank
They know your full name, bank, and last purchaseThe result of a lookup in leaked databasesThis is not proof of legitimacy — it is a signal of an attack

How to check right now

If the caller introduced himself as an investigator and mentioned a “criminal case related to your transfers,” this is a standard scenario of the scheme. Real procedural actions are carried out by a summons, not by a phone call. But if you are worried, you can make sure you are definitely not on the Russian Interior Ministry wanted list.

To check whether your e-mail itself has leaked, use Have I Been Pwned; to check the wanted list, use Wanted Radar search by full name and date of birth.

Check a full name in the Russian Interior Ministry wanted register

What distinguishes a real call from a scam call

A real bank does not ask you to “urgently transfer money to a safe account,” does not tell you which apps to install, and does not request SMS codes. A real Interior Ministry investigator summons you by an official notice, not by phone, and does not forbid you from calling relatives. The Central Bank does not call ordinary citizens directly.

If in doubt, hang up without explaining yourself. Call the bank back using the number printed on the back of the card, or through the mobile app. This rule is the same for all schemes — it neutralizes 99% of phone fraud.

What to do next

  • Set the rule “do not act on an incoming call” — for yourself and for older relatives.
  • Move two-factor authentication from SMS to an authenticator app (Aegis, 2FAS).
  • Enable a ban on operations by phone instruction at your bank (if such an option exists).
  • Set up a self-ban on loans through Gosuslugi (Госуслуги) — this blocks the “a loan was taken out using leaked data” scenario.
  • If there is an attempted fraud — file a police report and a complaint with the bank (it is recorded in the anti-fraud system).
  • Discuss the scheme with parents and elderly relatives: they are the scheme’s main target audience.

Conclusion

A scammer knowing your bank and address is not “security-service wiretapping,” but the result of buying a ready-made database in a Telegram bot. This chain has been described in detail by both state sources (TASS) and foreign investigators (The Guardian (resource blocked in Russia)). Protection is not technical, but behavioral: do not act on an incoming call.

Check through Wanted Radar