Fraudulent call centers are attacking Ukrainians: how to recognize a scam and not lose money

post-img

3 min to read

In Ukraine, fraudulent call center activity continues to be recorded. Criminals call citizens on behalf of banks, law enforcement agencies, mobile operators or government agencies and try to gain access to money and personal data under various pretexts.

In just one week in August 2026, the National Police, together with the Security Service of Ukraine and the Prosecutor General’s Office, conducted 411 searches and shut down 94 fraudulent call centers. Law enforcement officers discovered 1,794 equipped workplaces, and 26 suspects were reported suspicious.

How telephone scammers work

Most often, the scheme begins with a regular call. The person is informed of an allegedly suspicious debit of funds, an attempt to apply for a loan, blocking of an account or other “urgent problem”.

After that, the scammers try to get a code from SMS, bank card details, a password from a banking application or convince them to install a program for remote access to the device. In some cases, a person is asked to transfer money to a so-called “safe account” on their own.

One of the main signs of fraud is psychological pressure and the demand to act immediately. If the interlocutor does not give time to check the information or insists that the person not end the call and call the bank on their own, the conversation should be terminated.

What data cannot be reported over the phone

Bank employees should not demand from the client:

PIN code of a bank card;
CVV/CVC code;
one-time passwords and codes from SMS;
login and password for online banking;
access codes to the banking application;
secret words and other data to confirm payments.

Also, you should not send photos of your passport or ID card, RNOKPP, electronic signature data or provide remote access to your phone or computer to third parties.

Increased liability for fraudulent call centers

On September 16, 2026, the Verkhovna Rada adopted Law No. 4986-IX, which supplemented the Criminal Code with norms on electronic communication fraudulent organized groups.

The creation or management of such a group is punishable by 7 to 12 years of imprisonment with confiscation of property.

Knowingly participating in the activities of a fraudulent group or facilitating it is punishable by 5 to 10 years of imprisonment, and intentionally involving other people is punishable by 3 to 5 years. In the event of a repeated commission of such a violation, the punishment may be from 5 to 10 years of imprisonment.

What to do if the data has already been transferred to fraudsters

If a person has reported the PIN code, CVV, one-time password, or login data to the banking application, you must immediately contact the bank via the official number or application.

If there is a risk of losing control over the SIM card, you should contact your mobile operator. If unauthorized persons have access to your email or other accounts, you should change your passwords and end all unauthorized sessions.

If the money has already been debited, you should notify your bank and contact the police or Cyber ​​Police. The law provides for a period of 90 calendar days from the moment the funds were debited to notify the payment service provider of an improper payment transaction.

At the same time, it is important not to delete SMS, correspondence and call information. It is worth saving phone numbers, screenshots, bank statements, receipts, account details of fraudsters and other digital evidence.

Without an author