Centro apskaita
UAB Centro apskaita
Get a Quote
Back to news

VMI and Sodra Warn Businesses and Accountants: Cyber Fraud on the Rise

VMI and Sodra report an increase in phishing SMS and emails claiming fake fines or tax debts. Institutions never send active payment links via messages.

C
UAB Centro apskaita
September 2, 20262 min read17
VMI ir „Sodra“ įspėja buhalterius bei įmones: suaktyvėjo kibernetiniai sukčiai

The State Tax Inspectorate (VMI) and the State Social Insurance Fund Board (Sodra) have registered an intensified wave of cyberattacks. Residents and company representatives are receiving fraudulent SMS messages and emails warning them of alleged administrative fines, delayed social insurance contributions, or tax arrears. These messages contain fake links or QR codes.

Clicking the provided links redirects users to spoofed websites mimicking state institutions or commercial banks. Cybercriminals use these fake portals to steal e-banking login credentials and electronic signature confirmations (PIN1 and PIN2). Both VMI and Sodra emphasize that official institutions never send active internet links or specific fine and debt amounts via SMS, nor do they request identity or payment card details.

Accountants and finance personnel must strictly adhere to security protocols: upon receiving any message regarding a supposed fine or tax debt, it is strictly prohibited to execute payments or click on links provided in the SMS or email. Instead, you must manually check your company's actual tax status by logging into the official platforms via a secure web browser. For VMI, this is done in the "Mano VMI" system (under "Apskaitos kortelė" or "Mokesčiai ir baudos"), and for Sodra, in the policyholders' portal at draudejai.sodra.lt. Individuals with corporate signature rights (Smart-ID, Mobile-ID) must never approve any operations or authentication requests (PIN1 / PIN2) unless they have actively initiated the login or payment instruction themselves on the official system.

Official institution websites can be identified by their domain structure. VMI's official domains always use www.vmi.lt or end in .vmi.lt before the first forward slash, and official emails end in @vmi.lt. Sodra's official portals are www.sodra.lt, draudejai.sodra.lt, and gyventojai.sodra.lt, with emails ending in @sodra.lt. Fraudulent links often end in .com, .net, .org, .info, .online, or contain additional hyphens.

If you spot suspicious messages, phishing websites, or fall victim to fraud, report cyber incidents to the National Cyber Security Centre (NKSC) via email at cert@nksc.lt or by calling 1843. Incidents are also recorded by VMI (duomenu_sauga@vmi.lt) and Sodra (info@sodra.lt).

C

UAB Centro apskaita

September 2, 2026

Back to news

Leave the accounting worries to professionals

Save time and avoid mistakes.

Learn more