Users in Azerbaijan become targets of sophisticated phishing attacks

Users in Azerbaijan become targets of sophisticated phishing attacks

Fərid Əlizadə · Texnologiya ·

Why emails now look real and how to protect yourself

Interest in using digital services in Azerbaijan has sharply increased – from online shopping to corporate document management. Along with this, the number of social engineering attacks has also risen: attackers imitate business correspondence, send QR codes, fake invoices, delivery information, or even voice messages on behalf of "bank employees". Phishing has become more sophisticated, aggressive, and most dangerously, more convincing.

As experts note, modern attacks rely less and less on mass phishing emails, replacing them with more targeted attacks, meaning personalized, visually appealing and well-designed messages that use correct signatures, logos, business correspondence styles, and even mimic internal company emails.

"We observe a continuous increase in attacks where cybercriminals use not only fake emails but also QR codes, voice messages, and fake payment or login pages. Social engineering remains the primary tool – manipulation that incites people to emotional actions urgently, without verification, with the possibility of risk or loss of access," says Roman Dedenko, a social engineering expert at Kaspersky.

Users who actively participate in online shopping, negotiations, tenders, or receive a large number of emails are particularly vulnerable to these attacks. The more digital connections you have, the higher the risk of becoming a target.

"We also observe an increase in the number of fraud schemes in Azerbaijan. Attackers are increasingly combining social engineering with technological tricks such as QR codes, voice messages, or simulated business correspondence. It is important for users to remember: the more real an email appears, the higher the risk of it being phishing. For reliable protection, not only technical solutions but also digital awareness is crucial. It is important to check the sender, avoid clicking on links in unexpected emails, and use multi-factor authentication only through official channels," notes Mushvig Mammadov, Kaspersky's official representative in Azerbaijan.

How to identify phishing, even if the email looks perfect.

Pay attention to:

  • unexpected emails marked as "urgent";

requests to update passwords, pay accounts, or confirm delivery;

  • attached files in unfamiliar formats (.iqy, html, zip, xlsm);
  • links that appear legitimate but lead to pages with a different domain;
  • emails supposedly from colleagues or management, but with different domain addresses.

How to protect yourself: Kaspersky experts' recommendations

  • Always check the sender's address, even if the email looks official.
  • Never click on links in unexpected emails – enter the address manually.
  • Use multi-factor authentication activated only through official applications or websites.
  • Install security solutions with anti-phishing features (Kaspersky Premium, Kaspersky Plus).
  • Undergo cybersecurity training – this is the most effective way to prevent human error.