Russian telecom operator MTS has made a significant leap in the fight against phone fraud. An update to the "MTS Zashchitnik" service, based on three simultaneously operating AI models, has reduced the average response time to suspicious calls from 30 to 15 seconds. This is not just optimization, but a twofold acceleration of a critically important process where every second of delay can cost a subscriber their funds.
The key result is that the accuracy of detecting complex, multi-stage fraud schemes has tripled. This fundamentally changes the balance of power, as attackers are increasingly abandoning primitive one-off calls in favor of elaborate psychological pressure scenarios, stretched over time and consisting of several sequential contacts with the victim.
How the updated "Zashchitnik" works
From January to July 2026, the service detected and blocked over 1.5 billion spam and fraudulent calls. For comparison: this is comparable to the annual voice traffic volume of some small countries. Such an impressive figure directly indicates the scale of the threat Russian subscribers face daily.
The solution's architecture is impressive: every second, three AI models evaluate over 1,100 call parameters. Not only technical metadata about the connection is analyzed, but also the context of the conversation, the interlocutor's speech pace, and other behavioral markers. Special attention is paid to multi-stage attacks when fraudsters make a series of calls to the same person. To improve accuracy, the models were retrained on new data and equipped with more sophisticated language algorithms capable of recognizing manipulative patterns.
The company emphasizes that the update is aimed at promptly responding to constantly evolving fraudster methods. This is critically important, as phone calls are just the first step in a chain that often ends with money transfers, including in cryptocurrency.
Other schemes for defrauding Russians
The fraud landscape in Russia is multifaceted. AI is used not only for protection but also for attacks. Cyberpolice records cases where chatbots directed buyers to fake stores using "data poisoning" techniques—pre-filling the network with fake reviews and false information for indexing.
A separate wave of crimes is linked to fictitious access to cryptocurrency. Scammers send out offers to buy top coins for rubles at a fixed Central Bank rate, luring victims to phishing sites disguised as a "closed gateway" of the Moscow Exchange. Another tool for stealing assets is drainers. F6 specialists have identified at least three hacker groups disguising malware as partner investment programs and emptying wallets after connection via QR code.
Attackers have also targeted messengers. Under the guise of secretary bots on Telegram, infostealers are distributed that steal passwords, session tokens, and crypto wallet data. Such scams often end in criminal cases. In Moscow, police detained a courier who collected cash from pensioners, converted it into digital assets, and sent it to accomplices—damage from two episodes exceeded 6 million rubles.
My analysis: Accelerating the "Zashchitnik" response is an important step, but this is an arms race. While telecoms refine algorithms, fraudsters are actively deploying deepfake voices and deepfake videos to bypass biometrics. The industry needs not only faster filters but also preventive measures, including data sharing on fraudulent wallets between banks and crypto exchanges. Otherwise, we risk only shortening the attack time, but not its ultimate success.