A New Wave of Phishing: Why This Time It's Business Accounts Under Attack
In July 2026, PrivatBank officially warned customers about a sharp increase in fraudulent emails disguised as official correspondence from the bank, the tax authority, and other government bodies. Unlike the usual, fairly primitive mass mailings asking you to "confirm your card", this new scheme is far more dangerous: it targets primarily business clients, and its goal is not a single unauthorized charge, but full, hidden access to the victim's computer — and, through it, to the corporate bank account.
How Exactly the Scheme Works
An entrepreneur or accountant receives an email that looks like ordinary business correspondence: a "reconciliation act", a "demand to settle a debt", a "notice from the tax authority about an inspection", or a supposedly official alert from the bank's security service. Attached to the email is a file — an archive disguised as a PDF document. The file name and even the icon look convincing, so the natural reflex of someone who receives dozens of similar emails every day is to open the attachment without a second thought.
The problem is that the archive doesn't contain a document at all — it contains malware. Once launched, it quietly installs itself on the computer and gives criminals remote access: they can see the screen, capture keystrokes, and — most importantly — wait for the moment the employee logs into the online banking system. From there, the fraudsters either initiate transfers themselves or steal the login credentials for later use. PrivatBank stresses that none of these emails have anything to do with the bank — they are entirely the work of fraudsters who forge the logo and style of official correspondence.
Why Business Accounts Are an Easy Target
Personal cards are usually protected by limits, push confirmation of every transaction, and comparatively modest balances. Business accounts are a different story: balances are significantly larger, several employees often have simultaneous access to the online banking system, and transfer decisions are made quickly — "it's just another invoice from a supplier". It is precisely this routine, everyday flow of paperwork that creates ideal conditions for an attack: a busy accountant has no time to check every attached file, and an email styled as coming from the tax authority triggers the urge to "reply in time" rather than suspicion.
An additional risk factor is that many businesses have no dedicated IT specialist or security team able to react quickly to an infection. By the time anyone notices unusual computer behaviour, the attackers have often already studied the online banking system and planned a transfer sized not to raise immediate suspicion.
Not Just Business: Individual Clients Are at Risk Too
While the current wave targets mainly legal entities and sole proprietors, fraudsters regularly use similar tactics against ordinary cardholders. Popular pretexts include a supposedly "approved loan that needs confirming", a "deposit about to expire, click to renew", or a "suspicious transaction, verify your identity via this link". The logic is the same: create urgency and push the person to act without thinking. If you receive an email about a loan you never applied for, or a deposit you don't hold at that bank, it is almost certainly phishing, not a system error.
What to Do If You Receive a Suspicious Email
- Do not open attachments or click links. Even if the file looks like an ordinary PDF, check the extension. Archives (.zip, .rar) or files with a double extension (.pdf.exe) are a red flag.
- Check the sender's address carefully. Fraudsters often use domains that look similar to the real one but with small spelling differences.
- Call the bank using the official number from its website or app — never the number listed in the suspicious email.
- Report the email through the bank's official channels — PrivatBank has a "Report Fraud" feature in Privat24 for Business for exactly this purpose.
- Brief your colleagues. If several people at your company have access to online banking, one warning isn't enough — send instructions to everyone who handles email and finances.
What to Do If the File Has Already Been Opened
If you or a colleague has already run a suspicious file, act immediately, without panicking, but quickly:
- Disconnect the computer from the internet (turn off Wi-Fi or unplug the cable) to stop remote access.
- Call the bank immediately and ask them to temporarily block access to online banking and suspend outgoing transfers.
- Change your banking passwords — but from a different, clean device, not the infected computer.
- Run a full antivirus scan or contact an IT specialist to clean the system.
- File a report with the cyber police — this helps not only you but other potential victims of the same scheme.
How to Choose a Bank That Actually Helps in Situations Like This
Not all banks respond to such reports equally fast. When choosing where to open a personal account or a savings account, pay attention not only to fees but also to how the bank has organised its fraud support: is there a 24/7 hotline, can you instantly block transactions right in the app, does the bank send push notifications for every login attempt from a new device? These seemingly small details often determine whether you manage to stop a transfer in time.
Summary: Vigilance Is Cheaper Than Recovering from an Attack
This new phishing scheme using fake "PrivatBank" and tax authority emails is further proof that fraudsters are becoming ever more inventive, and their main weapon remains human haste and trust in familiar-looking official documents. The core rule is simple: no bank ever sends archives with "important documents" that must be opened urgently. If in doubt, call the bank directly and check. Spending five minutes verifying is far cheaper than spending months afterwards recovering stolen funds and customer trust. Compare banks with reliable account protection on BankSorter.com and choose a partner you can genuinely trust with your finances.