started · updated
Italian SPID Phishing Campaign Targets Millions with Fake Annual Fee
A new phishing campaign is targeting users of Italy’s public digital identity system, SPID. The scheme impersonates official agencies and asks recipients to pay a fictitious annual “SPID fee.” Fake web pages replicate logos and graphics of legitimate portals and use deceptive domains such as spidgov.click/pay. Victims are prompted to enter their fiscal code and credit‑card details, which are then harvested by cybercriminals for fraudulent transactions.
The Computer Emergency Response Team of the Italian Digital Agency (CERT‑AGID) has issued a warning, noting that the campaign is active and could affect tens of millions of Italians who rely on SPID to access public services. The attackers distribute the phishing messages via email or SMS, often referencing recent legitimate cost introductions by SPID providers. Users are advised to avoid clicking links in unsolicited messages, verify any payment request directly with their SPID provider, and report suspicious communications to CERT‑AGID.
Entities
Agenzia per l'Italia Digitale · Bitdefender · CERT‑AGID · Epic Games · Fortnite · Malwarebytes · Roblox · SPID