Section

Cybersecurity in Kazakhstan

Data leaks, fraud schemes, personal data protection and corporate security — without panic, with concrete step-by-step instructions.

Stories in section22+
FormatNews and guides
FocusData security
China’s GLM-5.2 matches Claude Opus in selected cybersecurity tests

China’s GLM-5.2 matches Claude Opus in selected cybersecurity tests

Open-weight model GLM-5.2 reached results comparable to selected Claude configurations in two security evaluations. Researchers caution that the finding applies only to specific tasks.

Section topics

Leaks and personal data protection

What to do if your data is leaked; Kazakhstan's Personal Data Law; citizen rights.

Phishing and banking fraud

Calls from "security service", transfers via Kaspi, deepfakes. What to do right now.

Corporate security and IS audit

Kazakhstan IS audit requirements, pentests, trade secret protection, incident response.

Latest stories

Practical guides

Editorial standard

The section is built as an editorial index: fresh stories, clear navigation, verifiable sources and short explanations without promotional noise.

  • We separate news from opinion and do not present forecasts as facts.
  • We link to primary sources, documents, research and official company pages.
  • We explain technical terms in plain language without marketing fog.
  • For Kazakhstan, we highlight regulation, service availability and practical usefulness.

FAQ

What to do if you sent money to fraudsters via Kaspi?
Basic actions: contact the bank as soon as possible through its official number or app, block the card if needed, and file a police report with transfer details. Also submit a request to the bank about the disputed transaction. Recovery depends on the transaction status, bank rules and decisions of competent authorities. Check current terms in official sources: this answer is for general information only and is not legal, financial, medical or other professional advice.
How to check if your data has leaked in Kazakhstan?
There are no government services in Kazakhstan to check leaks by IIN. Use international services like haveibeenpwned.com (by email) and dehashed.com. If data has leaked — change all passwords, enable 2FA, replace EDS via eGov. Check current terms in official sources: this answer is for general information only and is not legal, financial, medical or other professional advice.
What's the penalty for spreading personal data in Kazakhstan?
Under the Code of Administrative Offences, fines for individuals — up to 60 MCI, for officials — up to 200 MCI, for legal entities — up to 1,000 MCI. Under the Criminal Code (Art. 147) for illegal collection or distribution — up to 3 years of imprisonment. Check current terms in official sources: this answer is for general information only and is not legal, financial, medical or other professional advice.
Who has the right to demand an IIN in Kazakhstan?
IIN may be requested by government bodies providing services, banks opening accounts or issuing credit, notaries and medical institutions. Private companies — only with legal grounds (e.g. an employment contract). If a private organization asks for an IIN, clarify the legal basis and purpose of data processing. Check current terms in official sources: this answer is for general information only and is not legal, financial, medical or other professional advice.
What is social engineering in plain language?
Social engineering is manipulating a person into giving fraudsters money, passwords or data themselves. A call from the "bank security service", an email from the "boss", a fake login page — that's social engineering. According to Kazakh bank statistics, 80% of fraud cases are exactly social engineering. Check current terms in official sources: this answer is for general information only and is not legal, financial, medical or other professional advice.
Scroll to Top