Of the 118 malicious campaigns Italy's government CERT tracked in the week to August 14, the single most popular theme was not an invoice, a delivery or a password reset. It was a fine. CERT-AGID recorded 42 Italian phishing campaigns built on the promise of an unpaid penalty, almost all of them wearing the branding of SEND, the state digital notification platform, or PagoPA, the state payments platform.
That is more than a third of the country's entire week of malicious activity spent on one lure.
The weekly summary from CERT-AGID, compiled by Matteo Cavallaro, breaks the week into 118 campaigns: 85 aimed squarely at Italian targets and 33 generic ones that reached Italy anyway. The agency extracted 1,662 indicators of compromise from them and pushed those to its accredited public bodies. Twenty-two distinct themes were in play, and 29 brands were impersonated across the phishing set.
A fine is a deadline with a payment page attached
The reason the fines theme works so well is structural rather than clever. A citizen who receives a penalty notice expects it to arrive through a government channel, expects it to carry a deadline, and expects the next step to be a payment. SEND and PagoPA supply all three expectations for free. A handful of smaller runs used the names of the Polizia di Stato and ATAC, Rome's public transport operator, for the same effect.
Banking lures came a distant second with 11 phishing campaigns, aimed at customers of Klarna, Intesa Sanpaolo, Mooney and Poste Italiane, and the same theme did double duty carrying malware. A third cluster of 11 campaigns, 9 of them Italian, targeted account renewals at domain and hosting providers including Aruba, Squarespace and WIX, along with the Ministry of Health and SPID, Italy's digital identity system. Hosting credentials are worth more than they look, because a compromised Italian site becomes the next campaign's infrastructure.
Eleven malware families, mostly inside archives
CERT-AGID counted 11 malware families for the week. FormBook led with eight generic campaigns themed around prices, invoices, contracts and deliveries, distributed in RAR, ZIP and Z archives. Remcos appeared in two Italian campaigns using legal and order pretexts plus four generic ones, arriving as ZIP links, VBS files, RAR, XLS and GZ. AgentTesla ran four generic campaigns, XWorm three, and GuLoader two Italian ones. PhantomStealer, SnakeKeylogger and MassLogger filled out the order and banking themes.
The Android side moved separately. GoldDigger, Kimwolf and SpyNote each ran generic banking campaigns delivered by SMS, with links to malicious APK downloads rather than attachments. That channel does not care what an email gateway thinks.
Two items from the same week are worth reading alongside this one: the agency also flagged a new INPS themed smishing kit that runs an AI model to check the identity documents victims upload, and the XSS2Shell flaw in WordPress that picked up public proof of concept code after its technical details were published.
Go to the source, never the link
For anyone operating in Italy, the defensive advice this week is unglamorous and specific. Treat any fine notice that arrives by SMS or email as unverified until it has been checked inside the official SEND or PagoPA app, opened independently rather than through the message. The same rule covers renewal warnings from a hosting provider: log in through a bookmark, not through the mail. Organizations should feed CERT-AGID's published indicators into their blocklists, since the 1,662 shared this week are already tied to campaigns that hit Italian targets. Italian firms are being pressured from more than one direction at the moment, as the recent run of extortion claims against the country's industrial base shows, and our Italy country profile tracks both threads.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.