PagoPA lookalike offers a 95 euro refund to steal cards

A fraudulent website dressed in the name, logo and graphics of PagoPA, the platform Italians use to pay public administrations, is promising a 95 euro refund on the TARI waste tax and walking victims through four screens that end with their full card number and CVV. Italy's CERT-AGID says it has identified the malicious sites, begun takedown of the domains and notified the impersonated entity.

The lure is well chosen. TARI is a tax almost every Italian household pays, an overpayment is believable, and a modest refund is not large enough to raise suspicion.

Four screens from a fake case number to a CVV

The landing page shows a notice about a TARI payment made in excess, with a fictitious case number, and a button labelled "Continua con la richiesta" to start the refund. CERT-AGID describes the steps that follow. First the site asks for the victim's codice fiscale (tax code) or identity card number to "consult the case". It then reports a supposed refund of 95.00 euro tied to a 2025 TARI case and an excess payment dated 28 August 2026. The third screen harvests personal details: full name, home address, postcode, municipality, province, region, mobile number and email. The last asks for the cardholder's name, card number, expiry date and CVV.

Together that is a complete identity and contact profile plus everything needed to attempt fraudulent card transactions, and CERT-AGID notes the data can be reused in later targeted phishing.

The same script as the pharmacy refund

The structure mirrors campaigns CERT-AGID has flagged all summer against Italian users, including the fake health-record page offering a 20.73 euro medicine refund in August and the wave of fake state fine notices the same month. Public bodies and payment brands are the constant; the pretext rotates.

A refund does not start with a link asking for your card

Anyone who entered details on such a page should contact their bank and block the card. Unsolicited refund pages that ask for a tax code first and a CVV last are the pattern to distrust, whatever logo they carry. CERT-AGID has shared the indicators with organisations accredited to its IoC feed and published them for download from the original CERT-AGID report, written by Francesco Tozzi.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions