Warning! Phishing attack!
Cybercriminals are once again sending Ukrainians fake emails claiming that their financial statements do not match the records on file, purportedly on behalf of Nova Poshta, and threatening them with tax audits.
These emails have absolutely nothing to do with Nova Poshta or any other company in the NOVA Group.
Scammers use intimidation tactics: they write about fictitious errors found during an audit, create a sense of urgency, and demand that you open the attachment to make corrections.
To stay safe, follow these simple rules:
- Check the sender's address. Emails from Nova Poshta come only from official domains. Watch out for suspicious changes or spelling errors.
- Do not open emails from unknown senders or click on any links.
- If you've opened a suspicious attachment or clicked on a questionable link, you should change the passwords for your accounts as soon as possible and check to see if you have any other active sessions. If you notice any suspicious activity, end all unknown sessions through your accounts' security settings.
- Enable two-factor authentication for your email, messaging apps, online banking, and other important accounts—this significantly enhances protection against unauthorized access.
- If you receive an email like this, move it to your spam folder and delete it. This will help reduce the risk of it being sent again and protect other users.
Nova Poshta's cybersecurity team is already working to stop this phishing campaign and is collaborating with the relevant authorities and service providers to curb the fraudsters' activities.
Please be careful and follow the guidelines.


