The US Department of Justice announced the seizure of 41 domains that hacker groups associated with the FSB used fishing attacks on Russian opposition and journalists. At the same time, the IT Microsoft Corporation filed a civil lawsuit about blocking another 66 domains associated with the same groups.
The US Ministry of Justice emphasized that they acted in close coordination with Microsoft to "drive away Russian intelligence agents from the network infrastructure, which they used for attacks on people, companies and government around the world." The Ministry of Justice in his press release focuses on the protection of these American citizens-employees of the intelligence community, Pentagon, the State Department, arms manufacturers, and Microsoft mentions the NPOs, researchers and journalists.
According to Microsoft, from January 2023 to August 2024, hackers attacked 30 different organizations - journalists, NPOs and research groups.

Examples of phishing letters. Screenshots: Microsoft
In August, Citizenlab at the University of Toronto and the American organization Access Now published an investigation about a large -scale campaign for hacking electronic mails of Russian activists and employees of international NGOs, whose work is connected with Russia. They showed how hackers associated with the FSB sent backup letters with allegedly working files, introduced themselves as familiar and colleagues and colleagues of colleagues The victims, so that they trusted in the well -known (or alleged) story of communication to letters.
How to protect yourself from phishing
1. Set up two -factor authentication. Yes, hackers can deceive the victim to enter the code, but this is the first, most basic step. For organizations in the risk zone, postal services have special programs for enhanced protection against forgery.
2. Check all the addresses of incoming letters. They received a letter that they did not wait - copy his address and check if there was already a correspondence with him. No? Then it makes sense to clarify the person himself whether he sent you a letter - of course, not in the mail, but in another way.
3. Do not open links. Google and Microsoft have built-in viewers, they will show PDF files without loading the contents. But if you click on a potentially dangerous link inside the document, these companies will no longer be able to protect you.
4. Do not log in anywhere, except for the site itself. Threw to another login page? Close.
5 . Use password managers. They safely store complex passwords and can enter passwords automatically, checking that the form is asking for a genuine site.
6. See “Preview of the Honged PDF ”? This does not happen, do not open.
7. Do you think that they are trying to hack you? Contact the Access Now , they will help confirm or refute your suspicions.