Scammers in Russia are targeting residents with fraudulent phone calls while posing as delivery drivers and flower sellers ahead of September 1, cybersecurity and consumer protection experts have warned.
The callers attempt to steal personal data by asking victims to dictate text message confirmation codes over the phone, claiming the numbers are required to process pending delivery orders.
Alexandra Pozharskaya, deputy head of the Popular Front project For Borrowers Rights and the Moshelovka anti-fraud platform, told TASS that fraudsters use the stolen credentials to gain unauthorized access to critical online accounts. She warned that the requested numbers often function as multi-factor authentication passcodes for Gosuslugi, the Russian government services portal, or for personal online banking applications.

Gosuslugi serves as Russia's centralized digital administrative network, storing citizen identification records, tax files, real estate documentation, and verified credentials connected to private banks. Pozharskaya stressed that SMS passcodes should never be shared with anyone, adding that genuine couriers and flower vendors will never ask customers to verify orders by providing one-time access codes by phone.
Moshelovka operates as a public anti-fraud monitoring platform run by the Popular Front, allowing Russian citizens to report suspicious calls, cyber threats, and financial phishing campaigns.
Targeting parents ahead of school year
The surge in phone scams coincides with the approach of September 1, celebrated in Russia as Knowledge Day to mark the official start of the primary and secondary school year. During the run-up to the holiday, families across the country routinely place delivery orders for bouquets, school supplies, and gifts for educators, creating opportunities for cybercriminals to target distracted shoppers.
Denis Ushakov, a pre-sale engineer at Russian cybersecurity firm Spikatel, previously noted that fraudulent operations aimed at parents of school-age children have increased again in the days leading up to the new term. Ushakov said attackers play on public trust in educational institutions and state authorities, using urgent language to force individuals to act before verifying who is calling.
