Russian telecom operator MTS has carried out a major update to its anti-fraud system "Zashchitnik" (The Defender). Now, the service is powered by three artificial neural networks that analyze phone conversations in real time. The results are impressive: the average response time to a suspicious call has dropped from 30 to 15 seconds, and the accuracy of detecting complex, multi-stage fraud schemes has tripled. This is not just a cosmetic improvement, but a fundamentally new level of subscriber protection.

How the updated "Zashchitnik" works

From January to July 2026, the service blocked over 1.5 billion spam and fraudulent calls. For comparison, that is comparable to the population of an entire country. Every second, the three AI models evaluate more than 1,100 call parameters. They take into account not only the technical characteristics of the connection, but also the context of the conversation, the speed of the interlocutor's speech, and other signs of suspicious activity.

The key focus of the algorithms is combating multi-stage attacks, where fraudsters make a series of consecutive calls to one person. The models were retrained on new data and equipped with more sophisticated language algorithms. This is critically important, as scammers constantly change their pressure tactics on victims, and now the system responds to their tricks much faster—reducing the time a user remains under psychological pressure.

Related threats: from drainers to fake gateways

It is telling that phone fraud is only the first link in a long chain of attacks. Cybercriminals are actively using AI in other schemes as well. Cyber police are recording cases where chatbots direct buyers to fake stores through "data poisoning"—the network is pre-filled with fake reviews. A separate wave of crime is linked to fictitious access to cryptocurrency: fraudsters offer to buy top coins at a fixed Central Bank rate and lure victims to phishing sites disguised as a closed gateway of the Moscow Exchange.

Equally dangerous are drainers—malicious programs disguised as affiliate investment programs. F6 specialists have identified at least three hacker groups that empty wallets after connection via QR code. Meanwhile, on Telegram, infostealers that steal passwords and crypto wallet data are being distributed disguised as secretary bots. Such scams often end in criminal cases. In Moscow, police detained a courier who collected cash from pensioners, converted it into digital assets, and sent it to accomplices; the damage from two episodes exceeded 6 million rubles.

My comment: Doubling the reaction speed of "Zashchitnik" is an important step, but the arms race with scammers continues. While operators improve AI algorithms, criminals are mastering new attack vectors, especially in the crypto sphere. Subscribers should remember: no automatic protection can replace basic digital hygiene and healthy skepticism when dealing with strangers.