Tech

How do cybercriminals misappropriate money? MIA on fraud methods

In 9 months, damage caused by cybercrimes approached 1 trillion sum, with more than 210 billion sum recovered. According to the Ministry of Internal Affairs, fraudsters are mainly embezzling funds through malicious APK files and calls made on behalf of agencies. "A war is going on in each of our phones," said a representative of the Ministry of Internal Affairs.

How do cybercriminals appropriate funds? MIA on fraud methods

In January–September 2026, material damage caused to citizens in Uzbekistan as a result of cybercrimes committed through information technology amounted to nearly 1 trillion soums.

According to the Deputy Minister of Internal Affairs — Head of the Investigation Department Ramazon Ashrapov, a large portion of the 69,962 crimes recorded in the nine months of this year is related to obtaining citizens' funds through electronic payment systems.

Deputy Head of the MIA Cybercrime Department Jahongir Sagdullayev reported that out of the established 1 trillion soums in damage, more than 210 billion soums were returned to their owners during the investigation proceedings. During this period, nearly 18 thousand crimes were solved.

He explained that a bank card blocking system is operating in cooperation with the Ministry of Internal Affairs, the Central Bank, and the General Prosecutor's Office. If a citizen notices an unauthorized withdrawal from their account in time and contacts the 102 hotline, it becomes possible to block the funds and prevent their subsequent transfer.

"However, if the victim finds out about the incident three to four days later, the money may have already been transferred abroad. Therefore, it is important to contact the internal affairs bodies as soon as a suspicious transaction is detected," he said.

"A war is taking place on the phone of each of us. Today, a fraudster sitting somewhere in some country is appropriating in a second or a minute the money that people have accumulated over months and years," said the MIA representative.

According to Sagdullayev, fraudsters use several methods to appropriate citizens' funds. One of the most common is sending malicious APK files.

Such files are distributed under the guise of a wedding invitation, a photo of an acquaintance, or a condolence message. If the user opens the file and installs it on their device, fraudsters can gain access to their data.

"50 percent of cybercrimes are specifically related to withdrawing money by distributing this APK virus," says the deputy head of the department.

Another method is taking over users' accounts using fake links.

For example, fraudsters use a photograph of a manager or an acquaintance to distribute a message calling on them to vote in a contest. The user who accesses the link is asked for a login code for their Telegram account. The person who enters the code may lose control over their account.

After that, the fraudsters study the victim's correspondence to identify their managers, colleagues, and acquaintances. Then they write to them on behalf of the manager or another acquaintance asking for money. In some cases, messages are sent on behalf of internal affairs bodies or anti-corruption agencies, exerting psychological pressure on employees.

The department representative also called for caution in online shopping. He stressed that if an unknown seller demands full payment before sending the goods, such an offer should be treated with suspicion.

In addition, fake investors and traders promising to double funds in a short period also use widespread fraud methods.

Calls from individuals claiming to represent banks, internal affairs bodies, or other government agencies requesting personal data and SMS codes should also not be trusted. Jahongir Sagdullayev stressed that government agencies do not request personal data from citizens over the phone.

He urged not to send passport copies, SMS codes, account login details, and other information allowing personal identification to strangers.

One of the journalists asked a question regarding cases where fake Telegram accounts are opened on behalf of government officials to request money from their employees. He inquired about where the data of employees is obtained to make contact through such accounts and how many cybercrimes are committed by individuals abroad.

Ramazon Ashrapov explained that opening a malicious file or link alone can create unauthorized access to user data. For this, fraudsters do not necessarily need to collect separate information about each organization or employee.

According to Jahongir Sagdullayev, after fraudsters take control of a Telegram account via fake links, they study the correspondence in it. Through this, they determine who is a manager and who is an employee, and can address other employees on behalf of the manager.

"90 percent of our crimes are transnational, cross-border. 10 percent are internal, individuals from within our country who assist these criminal elements," he says.

The department representative explained data leaks as an interconnected process. For example, as a result of one person opening a malicious file or accessing a fake link, their data may be obtained, and then that data can be used to deceive other people.

Sagdullayev stressed the importance of increasing the digital literacy of the population. According to him, caution should also be exercised when sending personal documents via messengers. As an example of cyber hygiene, he also cited the practice of using a simple phone that is not connected to the Internet. He stressed that not distributing personal data in open sources and not sending it to strangers is of great importance in ensuring cybersecurity.

An APK application called "Qoriqchi" (Guard) has been developed. According to Ramazon Ashrapov, 3 million people have connected to it.

The Deputy Minister stated that events are being held to promote this application among the population, as well as to develop cyber culture among enterprises and organizations, educational institutions, and pensioners.

He stressed that preventing cybercrimes should not be limited solely to the efforts of internal affairs bodies; citizens should also inform their relatives and acquaintances about the application. Increasing the cyber culture of the population and strengthening awareness of fraud methods can help protect the funds of more people.

At the press conference, the issue of cooperation with digital platforms and identifying individuals who committed cybercrimes was also raised.

According to Jahongir Sagdullayev, the MIA has established contacts with Google, Meta, and Telegram. Currently, the opening of offices for these companies in Uzbekistan is also being discussed.

The department representative stressed that obtaining the necessary data from the platforms will help identify the individuals who committed the crime and bring them to justice.

The year 2026 has been declared the "Year of Fighting Cybercrime" in the system of the Ministry of Internal Affairs of Uzbekistan.

According to the ministry's data, in the first half of the year, more than 9 thousand cybercrimes were solved in the country, and 120.49 billion soums of damage caused to over 13 thousand citizens was recovered.

Cookies on xabarchi

We use cookies to remember your language and theme, and to count how many people are reading right now — that count is anonymous, lasts only while your browser is open, and cannot be tied to you or to another visit. With your permission we also measure how the site is read: Microsoft Clarity, which records page views and on-page interactions, and our own count of returning readers. Nothing that recognises you across visits is measured until you accept.