Association News 2 min read

Phishing disguised as Medoc: a Software Ukraine member warns of fake sites

Software Ukraine member Intelekt-Servis has detected a mass phishing campaign and fake websites impersonating Medoc. Why this hurts the whole industry and how to stay safe.

Our member — the Intelekt-Servis group of companies — has detected a mass phishing email campaign disguised as official Medoc communications, along with a series of fake websites imitating the product's official resource.

What is happening

Attackers are sending emails with malicious links and attachments: interacting with them can lead to computer infection or theft of confidential data. The fake sites look similar to the real one but have no relation to the company.

Why this hurts the whole industry

Attacks on a mass-market accounting software brand strike not just one company but trust in Ukrainian software overall. Every successful phishing attempt against a Medoc user undermines business readiness to adopt domestic solutions, feeds the myth that Ukrainian products are "unsafe" and burdens support teams across the sector. Ukraine already learned this lesson in 2017, when NotPetya spread through compromised accounting software updates: the reputational fallout hit the entire market. That is why protecting members' brands is a shared industry concern, not a vendor's private problem.

Consequences for users

Losing accounting credentials is a direct path to compromised financial operations, leaks of employee and counterparty personal data, and stalled reporting at the busiest time.

What to do next

  • Carefully check the sender address and mail domain.
  • Do not open emails from unknown or suspicious senders.
  • Do not follow dubious links or download unexpected attachments.
  • Treat any unexpected email as suspicious by default: verify via the vendor's official site or support.

Prepared by a Software Ukraine member — Intelekt-Servis. Original publication.

Sources & materials

Materials and sources used in this article.

  1. Original publication — intelserv.net.ua