How Kazakhstan to fight cyber fraud

How Kazakhstan to fight cyber fraud
Фото: El.kz / Artem Churssinov

A five-digit password is still used on the phones of half of Kazakhstan’s population, while fraudsters have long moved on to deepfakes and calls pretending to be relatives. It was discussed by participants at the conference “Cyber Culture as a Standard: Rebuilding the Security Model,” which opened in Astana, El.kz reports.

Why the Government needs an entire month dedicated to security

September has been declared Digital Security Month in Kazakhstan, and the conference marked the launch of the campaign. Supported by the Ministry of Artificial Intelligence and Digital Development of Kazakhstan, the event brought together government agencies, businesses, and cybersecurity experts on one platform.

The organizers plan to cover all regions of the country during the month-long campaign. The first day focused on dialogue between the government and businesses, while the second is intended to demonstrate how cybersecurity and digital hygiene can be explained to ordinary people, including families and children.

The format itself was also noteworthy. Instead of simply presenting dry reports and slides, participants were shown simulations of real attacks on phones and laptops.

Money is being invested in protection, but fraudsters still get through

Vice Minister of Artificial Intelligence and Digital Development of the Republic of Kazakhstan Doszhan Mussaliyev acknowledged an obvious contradiction: the government has been increasing its investment in cybersecurity for years, yet fraud statistics are not declining.

“No matter how strong a system is, even with the latest updates and the best technologies, the human factor always remains. If you deceive the person who has access to critical systems, you can use that person to bypass any security measure,” Doszhan Mussaliyev said.

According to Mussaliyev, telecommunications operators were required to install anti-fraud systems last year, and the National Bank adopted similar measures. However, fraudsters adapt to every new restriction and rely on psychology rather than technology.

How to tell a deepfake from a real call

Journalists asked Mussaliyev whether an ordinary person can recognize a fake. His answer was based on a principle known in the industry as Zero Trust.

“Even if you look closely at a video, you may notice that the facial expressions do not match the voice and that the movements look unnatural. If a bank or a well-known public figure says something, you can always visit their official account and check whether they actually said it,” Mussaliyev explained.

He gave a specific example involving the police. If someone calls claiming to be a law-enforcement officer and asks for personal information, the person should call 102 and check whether such an officer actually exists.

Dark web data leak turns out to be something different

Journalists also raised the issue of a recent publication of Kazakh citizens’ data on the dark web. Mussaliyev stressed that government systems had not been hacked.

“More than five years ago, data was passed to third parties by employees who had login credentials and passwords. These were not government systems. Dark-web sellers combine old data leaks and periodically put them up for sale again, presenting them as a new hack,” Mussaliyev said.

According to him, a criminal case has been opened over the data leak, and the investigation is ongoing.

Mussaliyev added that a similar situation occurred with the case involving the alleged leak of data belonging to 16 million people, which was reported the previous year. He called claims implicating a specific ministry employee inaccurate.

Ministry specialists are investigating such advertisements by approaching sellers while posing as potential buyers. In most cases, he said, what appears to be a sensational offer turns out to be a collection of useless files rather than a genuine database.

What will happen on the 2nd day of the conference

Deputy CEO of MSP Global Zhaslan Kebekpayev said the first day of the conference focused on dialogue with the government, including discussions about challenges related to public procurement of information security solutions.

The second day will focus on ordinary users.

“Cyber hygiene for the public means understanding how to avoid falling for fraudsters’ tricks and how to protect your digital assets, especially the money in your bank cards. Specialists will demonstrate simulated attacks on phones, laptops, and other devices,” Kebekpayev explained.

He noted that the main problem has remained unchanged for many years. Passwords such as “12345”are still used far too often, and no corporate security system can compensate for this kind of individual behavior.

Children, deepfakes, and a fact-checking portal

Kebekpayev also spoke about CitizenSec, a publicly available portal that explains basic digital security rules.

According to him, criminals often exploit people’s trust by impersonating bosses or relatives on calls.

He described as another government initiative the recently adopted decision to restrict social-media access for children of certain ages, which had previously been discussed by the Head of State.

Kebekpayev called reports of data leaks from eGov yet another fake story based on old databases obtained through hacks of third-party services such as online marketplaces.

According to Kebekpayev, ministries are now actively pursuing digitalization and understand their responsibility for protecting citizens’ data. He therefore urged people to verify such claims rather than simply forwarding them.

The second day of the conference will take place tomorrow and will focus on practical training for families and educators. The organizers promise to demonstrate not abstract advice, but real-life attack scenarios that Kazakhstanis encounter every day.

El recommends