In Astana, the activities of a criminal group suspected of organizing mass phishing SMS campaigns to obtain personal data and money have been stopped, reports infohub.kz.

According to the Financial Monitoring Agency, a citizen of a Southeast Asian country is suspected of having, in January of this year, for a reward, recruited a local resident to organize illegal activities on the territory of Kazakhstan. The investigation believes that other individuals later joined the scheme, ensuring the operation of equipment in the capital.

The criminals used an SMS blaster—a device that imitates a mobile base station and allows mass messaging bypassing operators' filtering systems. In four days, about 150,000 phishing SMS were sent to Beeline, Kcell, and Activ subscribers, posing as well-known companies with offers to exchange bonuses. By clicking on the link, users were taken to a fake website where they were asked to enter personal and banking data, including card details, CVV, and SMS confirmation codes.

Thus, the suspects gained access to citizens' confidential information and their bank funds. The investigation established that the seized SMS blaster is a special technical device intended for operational-search activities and covert investigative actions.

A criminal case has been initiated under Article 399, Part 2 of the Criminal Code, "Illegal manufacture, production, acquisition, sale, or use of special technical means for covertly obtaining information." Currently, four suspects have been taken into custody. The investigation is ongoing. Further information is not subject to disclosure in accordance with Article 201 of the Criminal Procedure Code of the Republic of Kazakhstan.