Fake tax bonus site copies Italy's SPID login screen

Published

A phishing site impersonating Italy's tax agency is dangling a holiday bonus, and it does not stop at a login box. CERT-AGID says the fraudulent page is built out across several sections and reproduces the authentication step users would expect, including SPID and CieID, the national digital identity schemes Italians use to sign into public services. The agency calls it unusually polished compared with the campaigns it normally sees.

The find leads CERT-AGID's weekly review of malicious activity aimed at Italy, published by Matteo Cavallaro on 18 September. The site borrows the name, logo and look of both Agenzia delle Entrate and Agenzia delle Entrate-Riscossione, its collections arm, and uses a supposed Bonus Vacanze claim as the pretext. The payoff is personal data, not a malware install.

Why rebuilding the login screen is the tell

SPID and CieID are how Italians prove who they are to the state, so a page that walks a visitor through that flow is borrowing the most trusted moment in the whole interaction. CERT-AGID does not say what the simulated login captures. What it does establish is effort: someone spent real time making the fake feel like the real sequence.

Refunds and fines carried the week

CERT-AGID logged 191 malicious campaigns over the week, 158 aimed at Italian targets and 33 generic ones that hit Italy anyway, and shared 1,498 indicators of compromise with its accredited bodies. Twenty themes were in play. Refund lures led with 46 Italian phishing campaigns, mostly abusing Agenzia delle Entrate, plus one impersonating the social security institute INPS. Fines came next with 42, every one arriving by email or SMS posing as an unpaid penalty and leaning on the branding of SEND and PagoPA, the state notification and payment platforms. Banking lures accounted for 25 more, naming Klarna, Intesa Sanpaolo, PayPal, Nexi and Poste Italiane.

Several income tax refund campaigns went after codice fiscale and card details, and one variant asked instead for an IBAN and bank data before staging a fake SMS second-factor check. A separate run abused the Fascicolo Sanitario Elettronico, the national electronic health record, telling recipients the FSE app was about to be blocked unless they confirmed their details.

Ten malware families, two of them on phones

Remcos ran in an Italian campaign delivered by a link to a ZIP archive and in six generic ones using assorted archive attachments. AgentTesla, FormBook and Guloader each managed three campaigns on order, price and document themes. AsyncRat arrived through a malicious JS script link, Grandoreiro through ZIP downloads on an invoice lure, and MassLogger in a ZIP attachment. ScreenConnect, a legitimate remote access product, rode payment and document lures. The two mobile entries matter most: BingoMod in an Italian campaign and RatHat in a generic one, both spread by SMS carrying links to malicious Android APK files.

Open the app, never the message

The defence is unglamorous and unchanged. Reach a refund, a fine or a health record through the official app or an address you typed yourself, never through a link somebody sent you. A refund that needs your card number is not a refund, and a bonus that needs a second factor confirmed by SMS is collecting one, not checking one. On Android, the moment you are asked to install an APK from a text message the conversation is over. CERT-AGID sends its 1,498 indicators to accredited bodies rather than publishing them, so the weekly summary is the narrative record.

Italy keeps drawing this exact class of brand abuse. Last week the same team flagged a fake business register site hunting company IBANs, and in August a phishing kit that ran AI checks on the ID documents it stole, a trend our Italy profile tracks. The lure rotates every week. The login screen is the part that keeps getting better.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Detection coverage

Read the full analysis on IntelFusions