Russian telecom operator MTS has carried out a deep modernization of its anti-fraud system "Zashchitnik" (Protector). The key change is the implementation of three parallel AI models that analyze every call in real time. The result is impressive: the average response time to suspicious activity has been reduced from 30 to 15 seconds, and the accuracy of detecting complex multi-stage fraud schemes has tripled. This is not just a cosmetic update, but a qualitative leap in subscriber protection.

How the updated "Zashchitnik" works

From January to July 2026, the service has already blocked over 1.5 billion spam calls and fraudulent calls. These figures clearly demonstrate the scale of the threat subscribers face daily. The new architecture involves the simultaneous evaluation of over 1,100 parameters of each call per second. The system takes into account not only the technical characteristics of the connection, but also the context of the conversation, the speed of the interlocutor's speech, and other behavioral markers.

Special emphasis is placed on countering multi-stage attacks, where fraudsters make several consecutive calls to one person, gradually gaining their trust. To improve accuracy, the models were retrained on new data and supplemented with more complex language algorithms. This allows for faster recognition of changing pressure scenarios and reduces the time during which a victim remains under the influence of scammers.

Threats extend beyond telephony

Phone calls are just the first link in the chain of attacks. Fraudsters are also actively using AI for other schemes. For example, chatbots redirect buyers to fake stores through "data poisoning" — filling the network with fake reviews. A separate wave of crimes is linked to fictitious access to cryptocurrency: scammers offer to buy top coins at a fixed Central Bank rate and lure victims to fake websites disguised as a closed gateway of the Moscow Exchange.

No less dangerous are drainers — malicious programs disguised as affiliate investment programs. F6 specialists have recorded at least three hacker groups using QR codes to empty wallets. In Telegram, infostealers that steal passwords and session tokens are distributed under the guise of secretary bots. Such scams often end in criminal cases: in Moscow, police detained a courier who collected cash from pensioners, converted it into digital assets, and sent it to accomplices — the damage from two episodes exceeded 6 million rubles.

My comment: Speeding up blocking to 15 seconds is a critically important metric, because it is in the first seconds of a conversation that fraudsters establish emotional control over the victim. However, the arms race continues: attackers will adapt, using deepfakes and more sophisticated social engineering. Investors and cryptocurrency users should remember: no anti-fraud system can replace basic digital hygiene and critical thinking when faced with any unexpected offers.