Mazda CX5
Як зробити цифрову копію себе. Ось відео —>

"You have been credited with UAH 6,500 in aid": how phishing scammers clear the credit limits of Ukrainians under the pretext of the UN and eSupport

The Ukrainian Interbank Association of Payment System Members (EMA) has calculated that phishing under the guise of government payments firmly holds 4th place in terms of the number of appeals to the Cyberpolice.

2 comments
"You have been credited with UAH 6,500 in aid": how phishing scammers clear the credit limits of Ukrainians under the pretext of the UN and eSupport

The Ukrainian Interbank Association of Payment System Members (EMA) has calculated that phishing under the guise of government payments firmly holds 4th place in terms of the number of appeals to the Cyberpolice.

Despite the supposedly positive dynamics — in 2024, victims filed 17,183 applications, and in 2025 the number dropped to 9,407 — the problem has not disappeared. The scheme has simply mutated. Today, the fake «NATO aid» has become a launching pad for more complex hacker combinations.

A dev.ua journalist delved into the court registry of 2026 to understand how this deception pipeline works and why even IT-literate users are still being led to it.

Anatomy of a Scheme: From Click to Zero Balance

The scheme works like a coordinated pipeline, where most processes are automated by fraudulent software.

Targeted advertising — Fake site or bot — Collecting logins/passwords — bot banking automatically withdraws cash

Hook: Sponsored advertising is launched in the Facebook, TikTok or Telegram feed. Triggers always hit pain points: «Payments for IDPs», «Warm Spring Program», «Aid from the NATO Fund».

Transition: The link leads to a perfect copy of «Actions» or the authorization page of a popular bank (Privat24, monobank, etc.).

Execution: To «receive the money,» the victim manually enters their username, password, and financial number. At this point, the fraudulent script intercepts the data, simultaneously initiates a login to the real bank application, and sends the victim a request for an SMS code or push confirmation. The person thinks they are confirming the receipt of funds, but in fact they are approving the hacker’s entry into their wallet.

Finale: Fraudsters raise credit limits to the maximum in seconds and reduce everything to zero.

What’s in the court registry? Here are real-life cases

Court rulings issued in early 2026 clearly show the scale of the disaster and the geography of the crimes.

Case No. 1. Phishing caught up in Poland (17,500 UAH stolen)

From the decision of the Skoli District Court of Lviv Region dated April 23, 2026

The victim was working in Poland. While scrolling through Facebook, he saw an advertisement for assistance from «Warm Spring» in the amount of 6,500 UAH. The man believed it, because in the winter he had already received legal state «Winter Support». Just a couple of hours before that, his pension had arrived on his card — over 16,000 UAH.

He followed the link, entered his card details and financial phone number. The site assured him that the funds would be sent through «Diya». Suspecting something was wrong, the man checked his real banking: 17,500 hryvnias, along with the remaining personal funds, disappeared in one minute.

How the Cyber ​​Police Work: The operatives established the movement of funds. The money was «transferred» to a transit card, and from there to an account in a bank whose name is not disclosed. The court gave the Cyber ​​Police access to the bank secret of the «drop» (the owner of the receiving card): investigators are extracting IP addresses, IMEI devices, and video from ATM cameras where cash was withdrawn.

The case is being investigated under Part 4 of Article 190 of the Criminal Code of Ukraine (fraud through electronic and computer equipment, up to 8 years in prison).

Case No. 2. Telegram trap «TechSupport» (75,230 UAH stolen)

From the decision of the Zvyahelskyi City District Court of Zhytomyr Region dated February 19, 2026

Here, the attackers took a different route and disguised the phishing as a Telegram bot from the supposedly official «eSupport tech support.» They promised to pay UAH 6,700.

The victim trusted the bot, gave her access to her account, and the scammers stole not only her own money, but also her entire available credit limit. The total loss was 75,230 hryvnias.

How the Cyber ​​Police Work: Specialists accessed the IP addresses from which the woman’s online banking was accessed. The court allowed the police to «shake» the Internet provider to obtain the MAC addresses of routers, phone numbers, and the exact coordinates of the points from which the hackers were operating.

Red flags of fraud: how to recognize a scam and protect your money (tips from the EMA Association)

To avoid becoming a victim of scammers who promise fake cash payments, always pay attention to basic security rules. Remember that official websites of government agencies and foundations in Ukraine always end in .gov.ua (for example, diia.gov.ua or msp.gov.ua).

And this is an example of a phishing site

If you see strange links like diia-support.site, unicef-vypomoga.org.ua, or э-поддрымка.com, close the tab immediately. Always carefully check the URL of the site, because even the smallest difference can make a difference: for example, services like diia.gov.me or privat-24.s3dx.site are fakes created to steal data.

In addition, the state and international donors (UN, Red Cross) never launch targeted advertising on social networks (Facebook, TikTok) with promises to distribute money, and the aid itself is never issued through Telegram bots — all real online services are available exclusively on the portal or in the official Diya application.

To receive legitimate payments, the state only needs your IBAN (international account number starting with UA). No payment requires entering online banking passwords, CVV codes, or SMS confirmation codes from the bank.

If, when you go to a site, your browser or antivirus displays a message on the red screen «Warning! This resource poses a threat», under no circumstances should you try to bypass this protection using a VPN — this is a 100% fraudulent site.

Finally, immediately stop any communication if you are asked to download and install a file with the .apk extension, enable screen sharing, or attach a bank card to your smartphone in order to «get help.»

These are classic signs of dangerous modern schemes designed to empty your accounts — be vigilant and defeat any insidious contrivances of scammers!

Try your hand at fighting cyberthieves — defeat the insidious scammer Nadiya E. Let this be your first test.

What to do if you have forgotten and entered data?

  1. Instant call to the bank: The hotline number is on the back of each card. Request to block accounts, application and account. Or do it yourself, through the bank’s mobile application.
  2. Application to the Cyberpolice: Screenshot everything (correspondence, website, advertising) and submit the form on the website cyberpolice.gov.ua.
  3. Notify EMA: File a complaint through the " Report an Incident " service so that the phishing domain is blocked as soon as possible at the provider level.

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
Николай Погиба
Николай Погиба IT - Technologies , Спеціаліст
0

Добррго дня!
Дякую за працю, за Ваші прекрасні статті, дописи, інформування.

Николай Погиба
Николай Погиба IT - Technologies , Спеціаліст
0

Добррго дня!
Дякую за працю, за Ваші прекрасні статті, дописи, інформування.