Telecom giant MTS has made a major upgrade to its cybersecurity system. The updated algorithms in the MTS Defender service now show impressive momentum: response time to suspicious calls has dropped from 30 to 15 seconds, and the accuracy of detecting complex multi-step fraud schemes has tripled. This is not just a cosmetic improvement, but a qualitative leap in preventive security technologies.

From January to July 2026, the system detected and neutralized over 1.5 billion spam calls and fraudulent attacks. This scale clearly demonstrates how massive the pressure on subscribers has become. At the core of the update is the simultaneous operation of three AI models that analyze more than 1,100 parameters of each call in real time every second.

How does the new system work?

The key difference is a comprehensive approach. The AI evaluates not only the technical characteristics of the connection, but also behavioral patterns: conversation context, the caller's speech rate, intonation accents, and other markers of suspicious activity. Special focus is placed on multi-stage attacks, where fraudsters make a series of consecutive calls to one person, gradually increasing pressure. To achieve this, the models were retrained on new data and supplemented with complex linguistic algorithms.

The update is critically important because phone calls are just the first link in the chain of crime. Often, victims are led to transfer funds, including cryptocurrency. Reducing blocking time directly shrinks the vulnerability window during which a subscriber remains under the psychological influence of scammers.

Threats beyond calls

Alongside call protection, the market faces other sophisticated schemes. AI is also used for attacks: chatbots direct buyers to fake stores through "data poisoning" techniques, flooding the network with false reviews. A separate wave of crime is linked to fictitious access to cryptocurrency — scammers offer to buy top coins for rubles at a fixed Central Bank rate, luring victims to phishing sites disguised as a closed gateway of the Moscow Exchange.

Equally dangerous are drainers — malicious programs disguised as affiliate investment programs. Experts have identified at least three hacker groups that empty wallets via QR codes. Additionally, infostealers are spreading on Telegram disguised as secretary bots, stealing passwords and crypto wallet data. Such scams often end in criminal cases: in Moscow, police detained a courier who collected cash from pensioners, converted it into digital assets, and sent it to organizers, causing damages of over 6 million rubles.

My take: Accelerating Defender's response is an important step, but the arms race with scammers continues. While AI learns to recognize their schemes, criminals adapt their methods. The key takeaway for users: technical protection is only part of the barrier. Financial literacy and critical thinking remain the last line of defense, especially in the cryptocurrency sphere, where transactions are irreversible.