In short: From 13 September 2026, a new two-stage phishing scheme has been targeting Russian taxpayers: victims first receive a paper letter supposedly from the Federal Tax Service (FNS) demanding correction of a tax declaration, then get an email with a link to a fake taxpayer personal account. Credentials entered on that page go straight to the fraudsters. The scheme was flagged by senator Artyom Sheykin and confirmed by Vedomosti, Anti-Malware.ru, and Kommersant.
What happened
On 13 September 2026, Federation Council senator Artyom Sheykin reported the new scheme to RIA Novosti. Vedomosti, Anti-Malware.ru, Kommersant, and eanews.ru all covered it. The attack stands out by combining two channels — physical mail and digital phishing — to lower the victim's guard. For a broader look at how modern phishing works, visit our privacy and security blog.
How the attack works
The attack lands in two consecutive steps.
Step 1: the paper letter. Fraudsters mail physical envelopes styled as official FNS correspondence. The letter demands the recipient correct a tax declaration or submit documents confirming expenses. The official tone, agency logo, and business language create urgency: something must be done, or there will be consequences.
Step 2: the email notification. Some time later, an email arrives at the same address claiming that a new notice has appeared in the recipient's taxpayer personal account, with a link to view it. Because the “tax letter” already arrived and the subject is now live, the email looks like a logical next step — not random spam, but the expected follow-up.
The link leads not to the real lkfl.nalog.ru but to a copy: the personal-account interface is reproduced closely enough to fool an unprepared user. Credentials entered there go straight to the attackers' server. With access to an FNS or Gosuslugi account, fraudsters can retrieve income certificates, SNILS numbers, property records, and in some cases sign documents with the victim's electronic signature.
Why this scheme is so effective
In 2026, phishing impersonating the FNS and Gosuslugi became the single most effective lure for attacks on Russian users, accounting for 43% of successful phishing attacks on employees, according to Kommersant. Standard phishing is often spotted when it arrives out of nowhere. The paper letter solves that problem: it builds a cover story, primes trust in advance, and makes the digital trap psychologically convincing.
As senator Sheykin warned: “The sender’s name, agency logo, and official letter style guarantee nothing.”
If you received similar letters and clicked suspicious links, we recommend checking whether your data was compromised — see our article on extortion schemes leveraging data leaks in Russia.
What happens to stolen credentials
Access to an FNS or Gosuslugi account gives fraudsters far more than just a login and password. These platforms allow retrieval of income certificates, property records, and in some cases submission of legally binding documents. Stolen credentials are frequently used to take out loans in the victim's name or sold on dark-web marketplaces.
In 2026, cybersecurity researchers note that government-portal credentials are becoming increasingly valuable to criminals precisely because legally significant actions flow through them. According to DLBI, more than 100 million rows of Russians' personal data entered public circulation in Q2 2026 alone — much of it fuelling exactly these social-engineering schemes.
How to protect yourself
Never follow links from tax or government-service letters. If a letter asks you to check something in your personal account, open a browser and type the address manually: lkfl.nalog.ru for the FNS or gosuslugi.ru for Gosuslugi. Do not copy the link from the letter.
Check the address bar. A legitimate FNS personal account always sits on nalog.gov.ru or lkfl.nalog.ru. Any deviation — a changed character, an extra hyphen, a different top-level domain — is a sign of a fake.
Enable two-factor authentication. Even if an attacker captures your login and password, 2FA via SMS or an authenticator app adds another barrier. Instructions are available on both portals in the profile settings section.
Use a VPN on public networks. When you access your personal account from a café, airport, or hotel, your traffic can be intercepted on the same Wi-Fi network. LiMP VPN encrypts your connection and hides your data from third parties on the network; with a no-logs policy, the service keeps no record of your sessions. See pricing — a protection plan costs far less than the aftermath of a stolen Gosuslugi account.
When in doubt, call directly. The official FNS helpline is 8-800-222-22-22 (free within Russia). If the letter is genuine, the inspectorate will confirm it by phone.
Sources
- Anti-Malware.ru — Paper letter, digital trap: Russians lured to a fake FNS site (14 September 2026)
- Vedomosti — Federation Council: scammers send letters posing as tax authority (13 September 2026)
- Kommersant — Scammers begin sending letters from the FNS (13 September 2026)
- EAN — Scammers begin sending Russians paper letters from tax authority (13 September 2026)
