Italian officials alert public to INPS smishing and phishing fraud
The National Institute of Social Security (INPS) does not send SMS messages containing clickable links, nor does it request personal or banking details by phone. Scammers exploit the institute’s name through smishing campaigns that threaten penalties, claim account irregularities, or promise refunds, and direct victims to fake websites that collect identity documents, IBANs and even selfies. Victims are urged to avoid clicking any links, verify communications by logging into the official INPS portal, and report suspicious messages to the Polizia Postale.
A broader wave of phishing attacks targeting banks, postal services, tax authorities, delivery companies and online platforms is also prevalent in Italy. These scams use urgent language, malformed URLs, and requests for passwords or OTP codes. Protection measures include enabling two‑factor authentication, using unique passwords, keeping software updated, and confirming requests through official channels before sharing any data. Anyone who has submitted information to a fraudulent site should change passwords, contact their bank, block cards, and file a complaint with the police.
Entities: Istituto Nazionale della Previdenza Sociale (INPS) · Italian banks · Polizia Postale