Post

Experts from the “Call Back Yourself” project explained how to protect yourself from cybercriminals

Experts from the “Call Back Yourself” project explained how to protect yourself from cybercriminals

Published on: 2026-09-02

Source: Moscow Government – Правительства Москвы –

An important disclaimer is at the bottom of this article.

At the beginning of the business season, experts from the capital project “Call Back Yourself” spoke about the importance of digital hygiene in the workplace. To avoid losing personal data or compromising corporate information, it is worth remembering how to create and store passwords, recognize phishing, use chatbots with generative artificial intelligence (AI), set private settings on social networks, and use Russian security certificates.

“By analogy with regular hygiene, which protects the body from diseases, digital hygiene reduces the risks of becoming a victim of fraudsters, computer viruses, or information leaks. It is a simple set of everyday rules and technical measures for protecting personal data on the internet, which should become a habit. It is especially important to follow them in the context of artificial intelligence development, as this technology makes attackers’ attacks more sophisticated: neural networks generate error-free emails, forge colleagues’ or managers’ voices, and also analyze correspondence leaked online or social networks to choose the perfect moment and tools for fraud,” said Valentina Shilina, project manager of ‘Call Back Yourself’ in the capital.

Department of Information Technology.

Digital hygiene implies several rules that must be strictly followed both in the workplace and in everyday life.

Secure password and mobile phone protection

The first rule of digital hygiene is creating secure passwords. Today they are required in all services—from your work laptop to cloud data storage. It’s important to remember not to use the same code everywhere, because if it’s stolen by attackers, they will gain access to all accounts at once. Furthermore, you should separate accounts: use personal email and messenger for private correspondence, and corporate ones for work purposes. The password should be at least 12 characters long and stored in special programs — password managers — or on a physical device with restricted access. Detailed rules on how to secure passwords are collected in special instruction.

In addition, it is always necessary to maintain security at an appropriate level mobile phone: install and update antivirus software, spam blockers, and caller ID blockers timely. The «Call Back Yourself» project reminded that criminals gain access to phones through fake emails and SMS messages containing links to malicious software. Fraudsters may impersonate tech support personnel and, under the pretext of detecting a phone hack, ask to dictate an SMS code or install a “service” application for remote access. To protect against attackers, users should check the sender’s address, never disclose confirmation codes, only open trusted applications, and communicate with tech support exclusively through official channels. More information on how to protect yourself can be found on the project’s website. “Call me back yourself”.

You should always remain vigilant when opening links from emails, social networks, SMS, or advertisements. Clicking on them can lead to a phishing site created by fraudsters to steal data and money. A fake link can be recognized by the following signs: the address differs from the real one by one or more characters, there are extra subdomains, the https protocol and lock icon are missing in the address bar. Experts from the “Call Back Yourself” project recommend additionally verifying who holds the site’s security certificate. To do this, click on the lock icon in the address bar, go to the certificate properties, and check the “Issued to” field. If it indicates a private individual rather than an official organization, this is a sure sign of a fraudulent site. Information on how to recognize phishing and protect yourself from it is collected in special instruction.

If the user has confirmed that the address is official but the browser shows a “Connection is not secure” notification instead of the website, then a Russian security certificate will be needed to continue working — a digital document that encrypts data being transmitted and confirms that it is protected from interception. Such certificates can be installed independently or the user can use the “Yandex Browser,” which supports them by default. A detailed instruction, as well as links to download the certificates and the browser, are posted on a special page of the portal. mos.ru.

Working with artificial intelligence and social networks

One of the familiar tools that city residents use for work purposes is chatbots with generative artificial intelligence.

Experts from the “Call Back Yourself” project remind that corporate information should not be uploaded to public neural networks: business plans, customer databases, budget projects, development strategies, logistics schemes, contract terms. Such data is intellectual property or a commercial secret of the company. When uploaded to a neural network, they can be used to further train the model, and subsequently any user may obtain fragments of these documents. This can lead to data theft and legal consequences.

Internal AI tools operating within a secure environment should be used for processing corporate information to eliminate the risk of commercial data becoming publicly accessible. An alternative could be local neural networks with open source code deployed directly on the device or on the company’s internal server. Such models operate completely offline, data does not leave the organization’s perimeter, and the open source code allows for a security audit.

Privacy settings on social networks and messengers can also reduce the risk of data loss. To do this, you can limit profile visibility by setting it to “Friends Only,” block messages from strangers, and enable two-factor authentication. Additionally, you should not post documents, screenshots, or photos with any commercial information, or geotagged images from the office on social networks. Such digital traces allow fraudsters to identify the workplace, position, and create a story that the user is likely to believe.

Experts of the “Call Back Yourself” project remind that personal accounts in messengers and social networks should not be used for work correspondence or sending documents. For this purpose, one must use corporate counterparts that have additional protection against hacking. For the same reason, it is not recommended to send corporate data and financial information if the device is connected to public Wi-Fi, for example in a cafe, rather than to the office network.

Information project “Call me back yourself” created in 2022 by the Moscow Government in conjunction with the Main Directorate of the Ministry of Internal Affairs of the Russian Federation for Moscow. It helps city residents protect themselves and their loved ones from telephone and internet fraud. The project website contains memos and expert recommendations, schedules of in-person and online events, recordings past webinars, which are also available on the social network page “VKontakte” and on the channel in Rutube.

The main components of the “Call Back Yourself” project are simple and understandable expert advice, relevant stories, and a convenient format. The events analyze real stories of victims, highlight scammers’ techniques, and also explain how to behave properly in such situations.

Support for the development and implementation of Russian IT solutions aligns with the objectives of the national project “Data Economy and Digital Transformation of the State” and the regional project of the city of Moscow “Domestic Solutions.” More about Russia’s national projects and the contribution of the capital can be found at special page.

The mos.ru portal is the core of the capital’s digital ecosystem. Today, it hosts over 460 services and utilities that help solve almost any issue online. In a convenient digital format, you can pay bills, check your child’s grades and school schedule, submit meter readings, book a veterinary appointment for your pet, buy tickets for plays and concerts, and much more. To ensure reliable access to important digital services, experts recommend using the “Yandex Browser” or installing certificates on your device. Ministry of Digital Development, Communications and Mass Media of Russia.

Get the latest main news quickly in the official Moscow city channels on messengers “Max” and “Telegram”.

Please note; This information is raw content obtained directly from the source of information. It is an accurate report of what the source claims and does not necessarily reflect the position of MIL-OSI or its clients.