---
title: "«Happy Letters» from the Tax Office: Ukrainians Warned of New Phishing Scheme Stealing Data"
description: "Gosspestsvidz and the STS have warned Ukrainians about a mass mailing of phishing emails in the name of the tax office: criminals use official attributes and links to steal personal and payment data."
date: 2026-08-21T00:52:02.000Z
lang: en
url: https://xab.info/en/posts/happy-letters-from-tax-office-phishing-scheme-warning-en
tags: [phishing, gns-ukraine, cybercrime, email-scam, data-theft]
publisher: "XAB.info"
---

# «Happy Letters» from the Tax Office: Ukrainians Warned of New Phishing Scheme Stealing Data

![Hacker in a hoodie at a computer — illustration of the tax authority phishing scheme stealing Ukrainians' data](https://xab.info/media/2026/08/21/fishing-pisma-ot-nalogovoj-shema-moshennikov/fishing-pisma-ot-nalogovoj-shema-moshennikov-1.webp)

## 🎯 Key Points

- Criminals are mass-mailing phishing emails impersonating the State Tax Service of Ukraine.
- The emails contain links to third-party resources designed to steal personal and payment data.
- The STS recommends not clicking on suspicious links and verifying information on the official website.
- Sources differ on the date the scheme was recorded: March 2026 (minfin) versus the August context (RBK-Ukraine).

A new wave of phishing attacks has been recorded in Ukraine, where cybercriminals are sending emails impersonating the State Tax Service (STS). This was reported by RBK-Ukraine, citing the press service of «Gosspestsvidz». According to the department, fraudsters deliberately use the name and visual attributes of the tax authority to make the message appear official and gain the recipient's trust. The goal of such mailings is to attract the recipient's attention and prompt them to take specific action, most often — clicking on an embedded link.

### Mechanics of the Phishing Attack

The key element of the scheme is links embedded in the body of the email. Users are invited to click them «to review information» or «to fulfill certain requirements». In practice, however, these links lead to third-party resources created solely to steal confidential information. Primarily, this concerns personal data and payment details, which criminals subsequently use for unauthorized transactions. It is important to understand that even a perfectly formatted email imitating an official document does not guarantee its authenticity — visual similarity is easily reproduced.

### STS Recommendations: How Not to Become a Victim

The State Tax Service urges citizens not to click on suspicious links in emails and to carefully verify any information allegedly coming from government bodies. If a message raises doubts, it is recommended to independently visit the official STS website to clarify the information or contact the service through its official communication channels. The tax authority also emphasizes: never disclose confidential data to strangers or enter it on resources whose authenticity is uncertain. Before opening a link, it is advisable to check the sender's address and the website URL it leads to: typos, unusual domains, or demands to urgently provide personal information are typical markers of a fraud scheme.

### Contradictory Data

Cross-referencing sources revealed a discrepancy in the chronology of the event. The main text and the context from RBK-Ukraine tie the warning to the current period — August 2026, when law enforcement agencies were simultaneously exposing related fraud schemes. At the same time, a material from minfin.com.ua describing a mass mailing of phishing emails allegedly from the tax office is dated March 17, 2026. Thus, the same scheme is either recorded as resumed in August or was initially described back in March. The XAB.info editorial office notes this contradiction: the exact start date of the mailing is not consistent in the provided sources, and both versions are presented openly.

### Context: A Growing Wave of Fraud Schemes

Phishing in the name of the tax office is not an isolated phenomenon. According to available data, in August, law enforcement exposed call centers that attracted people to fake investment platforms and gained access to their accounts. In the preceding month, the police reported a new scheme targeting education enthusiasts and online courses: users were offered to download a «certificate», but instead of a document, a malicious virus was downloaded to the device. The combination of these episodes indicates a systematic tactic by criminals who combine social engineering, forgery of official documents, and malware to extract financial and personal data from citizens.

## 🔍 Fact-Check Verification

- [Ukrainians Warned of New Scheme by Criminals Impersonating the Tax Office](https://www.rbc.ua/ukr/news/ukrayintsiv-poperedili-novu-shemu-vid-shahrayiv-1787272832.html) - Первичный источник: фишинг от имени ГНС, ссылки на сторонние ресурсы, рекомендации не переходить по ссылкам и проверять данные на официальном сайте.
- [«Happy Letters» from the «Tax Office»: Criminals Mass-Mail Phishing Messages](https://itc.ua/news/pysma-schastya-ot-nalogovoj-moshennyky-massovo-rassylayut-fyshyngovye-soobshhenyya/) - Подтверждает факт массовой рассылки фишинговых сообщений под видом налоговой службы.
- [Ukrainians Are Massively Receiving Phishing Emails Allegedly from the Tax Office](https://minfin.com.ua/2026/03/17/170168294/) - Описывает ту же схему, но материал датирован 17.03.2026, что не согласуется с августовским контекстом основного текста — зафиксировано как противоречие в датах.

## ❓ FAQ

### Q: How to recognize a phishing email from the tax office?
**A:** Check the sender's address and the website URL in the link: typos, unusual domains, and demands to urgently provide personal data are markers of fraud. An email that looks official does not guarantee authenticity.

### Q: What to do if an email raises doubts?
**A:** Do not click on links in the email. Independently visit the official STS website or contact the service through official communication channels to verify the information.

### Q: What data are criminals trying to steal?
**A:** Primarily personal and payment data, which criminals extract via third-party resources linked in phishing emails.