Russian fraudsters are targeting parents and teachers with fake delivery scams ahead of Teacher's Day, consumer rights official Alexandra Pozharskaya has warned.
The warning was reported by Russian state news agency TASS following a rise in social engineering attacks designed to compromise personal accounts. The scheme involves couriers delivering actual flower bouquets sent from an unknown sender directly to the homes or workplaces of unsuspecting victims.
On the day of delivery, the courier hands over the flowers without requesting any payment, signature, or personal details in return. The fraud begins twenty-four hours later when the recipient receives a phone call from individuals pretending to represent the delivery company.
The callers ask the victim to provide an SMS verification code sent to their mobile phone, claiming it is required to officially confirm delivery. In other cases, the callers tell the recipient that the numerical code is needed for internal reporting and accounting records.

How scammers gain trust
Pozharskaya, deputy head of the People's Front project For Borrowers' Rights, explained that the single security code grants criminals full access to sensitive digital services. Once obtained, the code allows fraudsters to break into the victim's Gosuslugi state services portal, mobile banking applications, or instant messaging accounts.
Sending a tangible, high-value gift such as a fresh bouquet is a deliberate tactic to build trust and disarm the target. Upon receiving an unexpected gift, the recipient naturally feels obligated and relaxed, making them significantly more willing to read out security codes over the telephone.
In more aggressive variations of the scam, the initial call is followed by a contact from individuals posing as law enforcement agencies. These fake security officials inform the victim that their personal account has already been compromised, using fear to manipulate them into withdrawing cash and handing it over to purported couriers under the pretense of keeping their funds safe.
Background on Teacher's Day and state services
Teacher's Day is celebrated in Russia every year on October 5 as a major national occasion honoring schoolteachers and educational staff. It is customary across Russian primary and secondary schools for parents' committees and pupils to present teachers with elaborate floral arrangements, box chocolates, and commemorative gifts.
Because teachers and class parents frequently exchange gifts during late September and early October, receiving an unexpected floral delivery appears entirely routine. Cybercriminals exploit these seasonal traditions to ensure their unsolicited deliveries do not raise immediate suspicion.
The target of the scam, Gosuslugi, is Russia's unified government services portal used by tens of millions of citizens to access tax records, official identity documents, property registries, and healthcare services. Because the portal is linked to official identity verification, gaining access allows bad actors to apply for microloans, steal identity credentials, or hijack linked banking accounts.
The People's Front, created as a nationwide civic coalition in Russia, operates the For Borrowers' Rights initiative to monitor financial fraud, track predatory lending practices, and issue public guidance on cyber threats.
Protecting digital identities
The flower scheme reflects a growing trend of hybrid cybercrime in Russia, where physical interactions are combined with phone fraud to bypass standard digital security awareness. Experts emphasize that legitimate courier services and government portals never ask customers to dictate SMS verification codes over the phone.
Addressing broader digital security measures, cybersecurity expert Anastasia Patrusheva previously advised internet users to maintain multiple email addresses for online registrations. Having separate email accounts helps isolate personal communication from commercial platforms and reduces the exposure of primary credentials.
Patrusheva added that whenever an online service does not require official identity verification, users should use fictitious names and birth dates. Withholding accurate personal details prevents scammers from compiling a comprehensive digital profile that could later be used in targeted fraud attacks.
