Fake letters on behalf of the tax authorities: Ukrainians warned of a new cyberattack

29 October 2025 05:18

A massive distribution of emails posing as official messages from the State Tax Service has been detected in Ukraine. This was reported by the press service of the agency, "Komersant Ukrainian" informs

How the fraudulent scheme works

Attackers send emails with the subject line “Financial audit on the fact of money laundering”, allegedly regarding a certain organization. The text states that the inspection is being conducted by the State Tax Service, and a file with details of the “violations” is attached to the email.

However, opening this file launches a virus program that

  • provides fraudsters with hidden access to the user’s computer;
  • can steal personal data, passwords, and banking information;
  • allows remote control of the device.

What the State Tax Service says

Acting Head of the State Tax Service Lesia Karnaukh emphasized:

“The State Tax Service has nothing to do with this mailing. We ask citizens to be as careful as possible and not to open such messages.”

The tax service also notes that the email addresses from which the letters are sent are not associated with the official services of the State Tax Service.

Why it is dangerous

The emails contain malware. Opening the attached file leads to the launch of a malicious program that creates technical capabilities for hidden unauthorized access to the user’s personal computer.

If it is activated, fraudsters are able to

  • view files on the computer,
  • copy documents,
  • access bank accounts and postal services,
  • block the device or demand a ransom.

In addition, the messages are sent from emails that are in no way connected with the State Tax Service of Ukraine.

Watch us on YouTube: important topics – without censorship

Recommendations of the State Tax Service: how to protect yourself

Do not open attachments in suspicious emails

Do not click on links, even if the letter came from a supposedly known address

Check the authenticity of information through official communication channels

Follow the rules of cyber hygiene – update anti-virus software, use strong passwords and two-factor authentication

Read us on Telegram: important topics – without censorship

Дзвенислава Карплюк
Editor

Reading now