Russian telecom operator MTS has conducted a deep update of artificial intelligence algorithms within its "Zashchitnik" (Defender) service. The result is impressive: the system's response time to suspicious calls has been reduced from 30 to 15 seconds, and the accuracy of detecting complex multi-stage fraud schemes has tripled. This is not just a cosmetic improvement, but a qualitative leap in the fight against telephone fraud.
The key change is the simultaneous operation of three specialized AI models. Every second, they analyze more than 1,100 parameters of an incoming call. The system evaluates not only the technical characteristics of the connection, but also the context of the conversation, the speed of the interlocutor's speech, and other behavioral markers that give away a malicious actor.
Hunting for "multi-step schemes"
Special emphasis in the update is placed on countering multi-stage attacks, when fraudsters make a series of consecutive calls to a single subscriber, gradually increasing psychological pressure. The new algorithms have been fine-tuned on fresh data and supplemented with more complex language models, allowing such schemes to be recognized at an early stage.
It is important to note the scale of the threat: from January to July 2026, the service detected and blocked more than 1.5 billion spam and fraudulent calls. This figure clearly demonstrates how massive the telephone attack on subscribers has become.
Reducing response time is critically important, because every extra call is a chance for the attacker. A phone conversation often becomes only the first link in a chain that leads to a transfer of money, including in cryptocurrency.
The cryptocurrency trail in fraud schemes
Fraudsters are actively mastering digital assets. A separate wave of crimes is associated with fake access to cryptocurrency: scammers send out offers to buy top coins for rubles at a fixed Central Bank rate, luring victims to phishing sites disguised as a closed gateway of the Moscow Exchange.
No less dangerous are drainers — malicious programs disguised as partner investment programs. F6 specialists have recorded at least three hacker groups that empty wallets after connection via a QR code. And in Telegram, under the guise of secretary bots, infostealers are being distributed that steal passwords and cryptocurrency wallet data.
The scale of the problem is also confirmed by practice: in Moscow, police detained a courier who collected cash from pensioners, converted it into digital assets, and sent it to accomplices. The damage from two episodes exceeded 6 million rubles.
My analysis: The acceleration of AI system response is an arms race in real time. While operators improve protection, attackers adapt their schemes to new realities, including cryptocurrency tracking. However, the fact that MTS is betting on comprehensive context analysis rather than just blacklists of numbers inspires cautious optimism. The question is whether other market players will be able to follow this example quickly enough.