Bank denies credit card client didn't request; trail leads to marketplace

A Novosibirsk resident received a rejection for a credit card from a bank she uses, despite not having applied for one. Contacting the bank revealed the application came from a financial marketplace. A correspondent for NGS.RU found fraudsters were behind the scheme to steal money, and learned how such cases are dangerous and how to protect your data.

«It Was Scary»

Oksana Petrova (name changed at the request of the publication«s subject) came across a message from her bank late one evening, denying her a credit card.

«I do have a credit card with this bank—I keep money on it just in case, but I»ve never used it. And then this message,« the woman said. »At first I thought it was from scammers, as the message contained a link to check application details. But in my email I saw a message from the bank with the same information. That«s when it became scary.»
Oksana concluded her account had been hacked and called customer support. The bank employee said there was no hack, reset her online banking password as a precaution, and informed her the application to the bank had come from the financial marketplace «Sravni.»
Oksana insists she has never used this service or created an account there. The bank advised her to file a police report for fraud, but reassured her: no financial institution can issue a loan without the applicant«s physical presence or at least verification of their personal data, especially if a self-ban is in place, as in Oksana»s case. Most importantly, they reminded her never to share any codes received via SMS.
Oksana tried to log into the marketplace website and easily succeeded using her phone number and a code sent to it, which surprised her.
«Someone created a profile linked to an email I»ve never had or accessed, but with my phone number and first name. There wasn«t even a last name. And there were two applications pending—for 300,000 and 500,000 rubles (approximately $3,300 and $5,600 at current rates). The justification for needing such sums was written as »just money«,» the interviewee said. «That»s when I started shaking. I imagined how many financial institutions the fraudsters could have applied to on my behalf.«
The woman deleted the account, changed her email password as a precaution, and then contacted the marketplace«s support to report the incident.
Minimum Data
The press service of «Sravni» stated they conducted an internal investigation following Oksana«s complaint.
«The investigation found the application was sent not directly through »Sravni,« but via the website of one of the marketplace»s partners,« the company noted.
According to the service«s press service, the application contained a minimal data set: only a first name and phone number. This is insufficient for processing any credit product, »Sravni« emphasized.
«We promptly took action: cooperation with this aggregator was suspended pending stricter application quality control. Despite continuously strengthening personal data protection, the risks of phishing and other fraudulent schemes remain. We remind users to be careful when sharing personal information and to contact support immediately in any suspicious situation,» the company stated.
Service representatives also assured that their specialists constantly work to improve security levels: implementing new monitoring technologies and automated systems to identify potential threats.
«There Is No Universal Method»
Pavel Vernyov, Deputy Head of the Siberian Main Directorate of the Bank of Russia, reminded that the Bank of Russia oversees the work of financial marketplaces in the country. The regulator maintains an official register of such platforms with their website addresses, and all accredited services must ensure personal data protection and payment security.
He stated that obtaining a loan or credit using only a phone number is impossible. Before approval, banks and microfinance organizations are required to conduct additional client identification—requesting passport data, SNILS (the Russian pension insurance number), or information from the Gosuslugi state services portal.
Pavel Vernyov emphasized there is no universal way to fully protect yourself from fraudsters. Often people themselves, unaware of the risks, share confidential information or leave a «digital trail» publicly available, which criminals exploit—for example, by posting photos of bank visits or trips.
«If you are asked for personal data, codes, or a conversation about money starts over the phone, in a messenger, or on social networks, with the caller »switching« between different agencies—you must end the conversation immediately,» he noted.
Since last year, residents of the region can set a self-ban on loans—over 300,000 Novosibirsk residents have already used this option. This can be done through Gosuslugi or an MFC (Multifunctional Center). However, a self-ban only protects against taking out new loans, not against theft of one«s own funds.
An additional security measure is the «second pair of eyes» service, operational in banks since last September. A client can appoint a trusted person to confirm atypical transactions—for example, large transfers or those to unfamiliar recipients. The trusted person does not get access to the account and only confirms specific transactions.
According to Pavel Vernyov, such a mechanism is especially useful for older people and can significantly reduce fraud risks.
«Preparatory Stage»
Sergey Golovanov, a leading expert at Kaspersky Lab, believes this is most likely a popular credit fraud scheme using compromised accounts on financial marketplaces. Criminals gain access to such accounts using information from data leaks or by guessing passwords, then send credit applications to banks on behalf of a potential victim.
«Even if the victim isn»t given the money, for example, due to the need for personal authentication or a self-ban, these actions can still be meaningful for the criminals. They can use such applications as a preparatory stage for a more complex attack based on social engineering (methods and tactics of influence based on psychological manipulation to control a person«s behavior and access their confidential information—Ed.),» warned Sergey Golovanov.
To stay safe, the expert reminded, it«s crucial to follow basic digital hygiene and financial literacy rules: use a unique password for each online service, create complex password combinations, store them in password managers, and update them regularly.
Fraudsters are constantly devising new ways to influence people. Recently, we summarized cybersecurity results in the Novosibirsk region for 2025. It turned out that during this period, attackers began targeting businesses more frequently. Experts also gave a forecast for the next year.





