Cybercriminals in Russia are targeting schoolchildren by posing as teachers and sending phishing links to steal personal data, cybersecurity director Viktor Ievlev of Garda warned.
Fraudsters take advantage of children because young users have not yet developed strong digital critical thinking skills and often fail to recognise online security threats.

Speaking to news outlet Lenta.ru, Ievlev explained that criminals create fake online stores and malicious software, disguised as official educational applications, to collect sensitive personal information from students.
Garda is a Russian cybersecurity firm specialising in data security, threat intelligence, and network protection. Industry experts note that cybercriminals frequently target students during the start of the academic year when school-related communications increase.
Phishing Links Disguised as School Portals
Cybercriminals regularly send deceptive links designed to look like electronic gradebooks, personal student portals, and class schedules. By pretending to be teachers, parents, or classmates, the fraudsters trick children into revealing login details and financial information.
Phishing is a cyber attack method where criminals use deceptive websites or messages to trick individuals into revealing sensitive credentials. In Russia, digital educational platforms such as electronic gradebooks have become standard tools for managing homework, grades, and parent-teacher communication across primary and secondary schools.
Because students routinely access these platforms, fake login portals mimicking official school websites can easily pass as legitimate. Once a student enters credentials into a fraudulent site or downloads a corrupted file, attackers can compromise personal accounts or install spyware directly onto the device.
Artificial Intelligence and Deepfake Threats
Ievlev highlighted growing risks associated with artificial intelligence tools and automated messaging bots. Children who enter personal details into unverified AI platforms risk having their data leaked into public databases.
Automated chat bots and AI tools have grown increasingly popular among teenagers for schoolwork and entertainment. However, third-party bots often lack data protection standards, allowing operators or hackers to collect user data.
Fraudsters harvest stolen or leaked personal data to execute sophisticated secondary attacks. Ievlev noted that criminals use artificial intelligence to generate voice or video deepfakes, or call children directly while impersonating trusted acquaintances.
Deepfake technology uses artificial intelligence to generate realistic fake audio or video recordings from existing media clips. During these scam calls, attackers attempt to extort money or convince children to disclose one-time SMS verification codes.
One-time SMS codes function as a critical security layer for online banking and messaging services. Obtaining these codes allows criminals to hijack user accounts, access financial funds, or compromise private records.
Essential Digital Safety Rules for Families
To protect children from digital fraud, Ievlev recommended that parents discuss essential online safety practices with their children, including how to spot fake websites.
Digital hygiene refers to foundational habits that maintain online privacy and cybersecurity. Parents should instruct children to carefully examine web addresses to ensure the domain name matches the official website before entering any information.
Web addresses with minor spelling variations or unfamiliar domain extensions often signal fraudulent sites created by cybercriminals.
Ievlev emphasised that children must understand the dangers of sharing private details online. Students should never publicly post their home address, school location, or other personal information, nor should they upload or message photos of official identity documents and bank cards.
The warning comes amid a broader rise in social engineering attacks targeting messaging platforms across Russia. Scammers recently developed a new scheme to compromise Russian Telegram accounts by exploiting newly introduced features within the messaging app.
