Tuesday, May 26, 2026
Today's Edition

EveryNews

Stories that matter, signal over noise

Finances

Attack on the NBU online store: personal data at risk, payment details secure

The National Bank’s online store for numismatic products has temporarily suspended operations due to a cyberattack on a contractor. We explain what data may have been leaked, why finances were not affected, and what ordinary users should do.

Tetiana Suchkova-Ladik

By Tetiana Suchkova-Ladik

February 19, 2026 · 2 min read

Attack on the NBU online store: personal data at risk, payment details secure
Фото: НБУ / Instagram

Briefly: why this matters

A potential leak of contact information of buyers from the National Bank of Ukraine’s online store complicates life for millions of Ukrainians who are used to ordering online. Financial details, according to the NBU, were not compromised, but this does not remove the risk of phishing and social engineering.

What happened

The online store selling the National Bank’s numismatic products temporarily suspended operations due to a cyberattack on a contractor company. According to official information, the attackers may have gained access to users’ personal data — names, phone numbers, e‑mails and delivery addresses. The NBU emphasizes that the system architecture was designed to isolate contractors from critical banking systems, and this prevented intrusion into the regulator’s services.

“Potentially, the attackers could have accessed personal information of the online store’s users, namely: first/last name, phone number, e‑mail, delivery address for numismatic products. Financial data — payment card details and other confidential information related to banking operations — were not compromised.”

— Press Service of the National Bank of Ukraine

Consequences: what is real and what is potential

Real: contact details may end up in the hands of fraudsters and become the basis for targeted phishing — emails, SMS or calls impersonating delivery services or the bank. Potential: direct access to clients’ funds, based on current information, is ruled out.

The NBU has already warned clients that its employees do not send messages asking to confirm payment details, do not call requesting card details, and do not ask to pay for orders by alternative methods. Trend analysis in the sector confirms: after incidents at the contractor level the number of fake mailings that impersonate legitimate services increases.

What users should do right now

Step-by-step security: check card statements; do not follow suspicious links; do not give information over the phone; change passwords in personal accounts if necessary; enable SMS/Push notifications for transactions. If you receive a suspicious message — verify the information through the official channels of the NBU or your bank.

Context and conclusion

The incident coincides with other cyberattacks in the financial sector: on February 18 A‑Bank reported an attack that affected some customer accounts. Cybersecurity experts point out that attacks on contractors are one of the most common routes for breaches. This underscores that the security of state services depends not only on internal policies, but also on partners’ standards.

The NBU example shows two important conclusions: a system architecture with isolation works, but preventing phishing is everyone’s responsibility. Now the question for the market and the regulator is: will this incident be enough to standardize requirements for contractors and reduce the risk of recurrence?

Related

Latest

Business

EU Against Google: Why the Latest Fine Could Change More Than Previous Ones

# European Regulators Target Google Again — This Time Over Digital Markets Act Violations. What's Behind the Accusations and Why It Matters Beyond the Corporation European regulators have renewed their scrutiny of Google, this time focusing on alleged violations of the Digital Markets Act. The charges underscore Brussels' increasingly aggressive stance on big tech monopolies and what officials say are anticompetitive practices. The accusations center on how Google leverages its dominance across multiple digital services — from search to advertising to mobile platforms — to disadvantage competitors. Regulators claim the company is using its market power in ways that stifle innovation and limit consumer choice. The case carries significance far beyond Google itself. It signals how the EU is attempting to enforce its landmark Digital Markets Act, legislation designed to curb the gatekeeping power of tech giants. A potential penalty could set precedent for how other large technology companies face similar scrutiny. For consumers and smaller tech firms, the outcome could reshape the digital landscape by creating more room for competition. For Google, fines and operational restrictions could fundamentally alter its business model in Europe, the world's most stringent regulatory market. The case also reflects a broader geopolitical divide, with the EU pursuing a regulatory approach that contrasts sharply with the lighter-touch oversight favored in the United States.

May 26, 2026