In 2025, CERT-UA processed 5,927 cyber incidents — 37.4% more than in 2024. Of these, 1,727 were phishing cases, compared with 843 the year before. This data reflects the number of incidents processed, not the total number of all attempted attacks on Ukrainian business and government institutions.
In the global Verizon 2026 DBIR report, the human element was present in 62% of the breaches examined. This is a broader category than phishing: it also covers social engineering, errors, and the use of compromised credentials. In phishing simulations, the median click-through rate for mobile vectors — voice calls and text messages — was 40% higher than for email.
Why the first 48 hours matter
The 48-hour period is a practical horizon for organising urgent action, not a statutory deadline and not a guaranteed threshold for recovering funds. At least three processes unfold in parallel after a compromise: the attacker entrenches themselves in the system, digital logs may be overwritten, and funds may move between accounts. Technical, financial, and legal response should therefore not be carried out sequentially, one after another.
The FBI IC3's 2025 report records 24,768 complaints of business email compromise (BEC), with reported losses exceeding $3.046 billion. That year, the US Recovery Asset Team initiated 3,900 Financial Fraud Kill Chain procedures and reported blocking 58% of the total amount of the reported theft attempts. These results cannot automatically be extrapolated to Ukraine or treated as a guarantee of recovery; they merely confirm the critical importance of immediate contact with the bank and full documentation of the transaction.
Key clarification. No reliable source confirms a universal rule under which the chances of recovering funds automatically fall to a specific percentage after 24 or 48 hours. The outcome depends on the type of transfer, the jurisdictions involved, how quickly the matter was reported, the remaining balance, and the specific banks' procedures.
An approximate timeline for the first 48 hours: 0–2 hours — isolating affected systems, recording the time of detection, activating the response plan, and contacting the bank if funds have already been transferred; 2–6 hours — preserving logs, emails, and payment documents, blocking compromised sessions, and making an initial assessment of scope; 6–24 hours — notifying CERT-UA and law enforcement, and checking regulatory, contractual, and insurance deadlines; 24–48 hours — in-depth forensic analysis, assessing any personal data leakage, and documenting decisions and a safe recovery plan.
Step 1. Contain the incident without losing evidence
The affected device or network segment must be isolated, but decisions to power down, wipe, or reimage a system should be coordinated with an incident-response specialist: such actions can destroy volatile memory, logs, and other non-persistent artefacts. CERT-UA recommends preserving disk copies, event logs, network data, and other traces of the incident before restoring operations.
In particular, it is worth: recording the exact date and time the incident was discovered, together with the time zone; preserving the original suspicious email in .eml or .msg format together with its full headers; exporting logs of sign-ins, mail-rule changes, OAuth grants, and administrator actions; preserving payment orders, invoices, the recipient's details, and correspondence with the bank; working from copies, calculating checksum hash values where possible, and keeping a log of everyone who accessed the materials.
The purpose of these steps is to ensure the reproducibility and integrity of the materials. Hashing on its own does not make a file admissible evidence, but together with a documented chain of custody, the manner of extraction, and storage, it helps confirm that the data has not been altered. An overall response model should cover detection, response, recovery, and subsequent improvement of procedures.
Step 2. Regain control of accounts
Changes should be made from a trusted device that was not used during the compromise. Changing just one password may not be enough if the attacker has created forwarding rules, connected a third-party application, or retained an active session token.
It is necessary to: forcibly terminate active sessions and revoke access tokens; change the passwords of compromised and related privileged accounts; enable multi-factor authentication, preferably phishing-resistant; check mail-forwarding rules, mailbox delegation, filters, and OAuth applications; and review any changes to payment templates, trusted recipients, and contact details.
Step 3. Contact the bank immediately
If a payment has already been executed, the sending bank should be notified immediately through an official channel, with a written request to initiate a recall or another available procedure for stopping the funds. Provide the full transaction details, amount, time, purpose of the payment, recipient details, and an explanation of the fraud method used. Ask that the report be logged and that you be given a reference number.
It is necessary to distinguish between an unauthorised transaction and a payment that an authorised person confirmed themselves under the influence of deception. This can change the legal assessment, the appeal procedure, and the allocation of liability. The mere fact of fraud does not automatically obligate the bank to reimburse the full amount; what matters is the Law of Ukraine “On Payment Services,” the contract, the authentication method used, and the actual sequence of events.
In parallel, check the notification deadlines under your insurance policy and any obligations under contracts with clients, suppliers, or payment partners. Notification should be factual and measured: premature conclusions about the cause or scope of the incident can complicate later settlement.
Step 4. Notify CERT-UA and law enforcement
A cyber incident can be reported to CERT-UA at incidents@cert.gov.ua or through the contact details on its official website. CERT-UA is the national response team within the State Service of Special Communications and Information Protection: it helps investigate and contain an incident and provide recommendations, but it does not replace the pre-trial investigation authority.
Where there are indications of misappropriation of funds or unauthorised interference, a report should be filed with the National Police or its cyberpolice unit. The classification depends on the method of the attack and its consequences: depending on the circumstances, Article 190 of the Criminal Code of Ukraine (fraud) and Article 361 of the Criminal Code of Ukraine (unauthorised interference) may, among others, apply. The final classification should not be determined automatically merely from the name given to the incident.
Special notification and cooperation rules apply to certain entities — critical infrastructure operators, banks, and providers of payment or financial services. For example, banks notify the National Bank of Ukraine of significant cyber incidents under the procedure established by NBU Board Resolution No. 24. An obligation to notify the State Financial Monitoring Service does not arise merely from the fact of a phishing attack: it must be separately assessed whether the financial transaction is one that is subject to reporting under financial monitoring legislation.
If personal data has been compromised
The GDPR does not apply simply because some of those affected are “EU residents.” The territorial scope of the Regulation under Article 3 must be checked. Where the GDPR applies, the controller must notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the risk is high, the affected individuals must be notified without undue delay.
The current Law of Ukraine “On Personal Data Protection” does not establish a general 72-hour deadline comparable to Article 33 of the GDPR. Draft Law No. 8153 was adopted in its first reading on 20 November 2024 and, as of the date of this material, is being prepared for its second reading. Its provisions cannot be presented as current law, although it is advisable to take them into account when building internal procedures.
What to preserve for legal work
For subsequent legal work, it is worth preserving: a chronology of events with the exact time of each action and the person who performed it; the original emails, full headers, and domain/DNS data; authentication, VPN, cloud-service, mail-gateway, and security-tool logs; bank statements, payment instructions, records of phone calls, and the bank's responses; disk images or other forensic copies, hash values, and a log of the transfer of materials; contracts with the bank, insurer, IT contractors, and counterparties; and all notifications sent to CERT-UA, the police, regulators, affected individuals, and partners.
Conclusion
After a phishing attack, the first priority is not finding someone to blame within the company, but managed damage limitation. In the first hours, systems must be isolated, digital traces preserved, control over accounts restored, the bank contacted, and the required notification recipients identified — all at the same time.
There is no universal percentage of fund recovery or a single algorithm that fits every incident. The outcome depends on the technical picture, the type of payment, the jurisdictions involved, the affected company's status, and its contracts. The practical 48-hour benchmark should therefore be used as a deadline for mobilising the team, not as a promise of a particular result.
Disclaimer. This material is of a purely informational nature, does not constitute individual legal or technical advice, and does not guarantee the recovery of funds. The course of action depends on the circumstances of the incident, contracts, jurisdictions, and the regulatory requirements in force at the time of the event.
Sources: State Service of Special Communications — CERT-UA processed 5,927 cyber incidents in 2025; Verizon 2026 Data Breach Investigations Report; FBI Internet Crime Complaint Center — 2025 IC3 Annual Report; CERT-UA — how to restore a company's operations after a cyberattack; CERT-UA — when and how to report a cyber incident; Law of Ukraine “On the Basic Principles of Ensuring Cybersecurity of Ukraine”; Criminal Code of Ukraine, Articles 190 and 361; NBU Board Resolution of 25.02.2025 No. 24; Regulation (EU) 2016/679 (GDPR), Articles 33 and 34; Law of Ukraine “On Personal Data Protection”; Draft Law No. 8153 record card; NIST SP 800-61 Rev. 3.

