A new wave of cyber fraud is sweeping across Ukraine, with attackers this time targeting trust in one of the country's largest logistics operators — Nova Poshta. Users are mass-receiving fake emails that scare them with fabricated reporting violations and threats of tax audits.
RBC-Ukraine reports this based on an official statement from the company in its Telegram channel. The goal of the campaign is to extract confidential data or infect victims' devices with malware via attachments.
Attack Scenario: Psychological Pressure
Cybercriminals are using a proven social engineering scheme. In emails mimicking official correspondence, recipients are informed of alleged errors in their financial or tax reporting. To force impulsive action, scammers create an artificial sense of urgency.
The scenario unfolds as follows:
- The email contains a threat of an impending tax audit.
- The victim is urged to immediately open an attachment to make "corrections" to documents.
- The tone is oppressive, demanding immediate action without allowing time to verify the information.
Nova Poshta categorically denies authorship of such messages. The company emphasized that neither they nor other enterprises in the NOVA group ever send emails with such content. Official communication with clients is never based on threats or demands to urgently open files.
How to Spot a Fake
The primary indicator of fraud is the sender's address. All official notifications from Nova Poshta come exclusively from corporate domains. Any deviations in the address spelling, the use of free email services, or suspicious domains should raise an alarm.
Company experts and cybersecurity specialists recommend adhering to the following safety rules:
- Do not open emails from unknown senders, even if the subject seems important.
- Do not click on links that seem suspicious.
- Never launch attached files (archives, documents) from unverified emails.
What to Do If You've Already Fallen for It
If a user accidentally opened a suspicious attachment or clicked a link, they must act as quickly as possible to minimize damage. The algorithm of action in such a situation is simple but critical:
- Immediately change passwords for all important accounts (email, banks, social networks).
- Check the list of active sessions in services and terminate all unknown connections.
- Enable two-factor authentication (2FA) for email, banking apps, and messengers.
Upon receiving such an email, it should be immediately marked as spam and deleted. Nova Poshta stated that their cybersecurity division is already actively working to block this phishing campaign, interacting with providers and relevant authorities to limit the scammers' activities.
Context: Digital Platform Update
It is worth noting that Nova Poshta has indeed been actively updating its digital services recently. Earlier, the company announced a gradual phase-out of the first version of its mobile app, which had been in use since 2012. Users are being migrated to a new platform with expanded functionality, and support for the old app will be completely discontinued. However, these technical changes have nothing to do with the distribution of emails threatening tax audits.
The company urges clients to remain vigilant and strictly follow cybersecurity recommendations to avoid becoming victims of scammers.