Fake pharmacy refund page steals Italians' card details

The bait is 20.73 euros. A phishing site now circulating in Italy tells visitors they are owed a 19% tax deduction on medicines bought at the pharmacy, dresses the offer in the logos of the Fascicolo Sanitario Elettronico (the national electronic health record), the Ministry of Health, the Department for Digital Transformation and the Ministry of Economy and Finance, and walks them through four screens that finish with their card number and security code.

The campaign was documented by Francesco Tozzi of CERT-AGID, the security team that serves Italy's public administration, in an advisory published on 18 August. Small refund, big ask, and a sum plausible enough that nobody stops to wonder why the state would need a CVV to pay it.

A sum you solve before you can be scammed

The first screen is a security check. It asks the visitor to answer a simple arithmetic question to confirm they are not a robot. CERT-AGID notes it does two jobs at once: it manufactures a reassuring sense of officialdom, and it blocks the automated crawlers that security teams use to find phishing pages. A scanner that has to solve a sum before it can see the fraud is a scanner that usually walks straight past it.

Then it asks politely, twice

Clear the check and an institutional-looking summary announces that the medicine refund request is being processed, at 20.73 euros, corresponding to the 19% deduction, with a Confirm button to finalise the paperwork. The next page, headed as a request to complete your dossier, collects surname, first name, date of birth, postcode, home address, city, telephone number and email address. Only then does the site ask for the payment details: cardholder name, full card number, expiry date and CVV, on the pretext that the money will land within one working week.

A closing receipt page invents a protocol number, sets the status to in processing, invokes the Agenzia delle Entrate (the Italian revenue agency) with a promise of credit inside seven working days, and prints a fake freephone support number.

The card data is only half the haul

CERT-AGID sets out plainly what the combination buys the attackers: fraudulent online transactions using the card, resale of the data through criminal channels, and a complete personal profile to drive follow-up social engineering such as bank vishing or smishing. A stolen card number ages badly on its own. A card number attached to a confirmed name, address, date of birth and mobile number is a working script for the phone call that comes next, and the fake support line printed on that last screen is exactly the sort of number a rattled victim calls back.

Domain takedown started, indicators already shared

CERT-AGID says it has begun its standard process to have the malicious domain taken down, and has pushed the indicators of compromise out to public administrations and to organizations accredited to its IoC feed. The indicator bundle is published with the advisory.

None of this is technically clever, and that is the point. It is the second time this month that Italian users have been worked over with government branding, after CERT-AGID's weekly review found fake state fine notices dominating the country's phishing traffic, and Italy remains one of the more heavily phished targets in our country profile. The lure keeps changing shape. The institutional letterhead does not.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions