< Back to situation

[REVISION HISTORY]

Italy phishing, physical & SPID fraud – Aug/Sept 2026

Updated 15 times since CLSTR started tracking revisions of this situation.

What changed

2026-09-04 21:14 UTC → 2026-09-06 10:37 UTC · added removed

The Italian crackdown on digital and physical fraud continued through early September 2026, characterized by increasingly sophisticated impersonation of state institutions and targeted attacks on vulnerable populations. A major phishing campaign has been identified targeting SPID users, where criminals demand a fictitious annual “SPID fee” via deceptive domains to harvest fiscal codes and credit card data. Scammers are also exploiting legal fears by impersonating the Ministry of the Interior, the Rome Tribunal, and the Polizia di Stato. The Polizia Postale has issued specific warnings regarding fraudulent emails that use official logos, headers, and the signatures of high-ranking officials. These messages mimic official notifications, summons, or judicial acts, falsely accusing recipients of viewing illegal content. In early September, new digital threats emerged involving WhatsApp and SMS. Attackers are hijacking WhatsApp accounts or impersonating known contacts to request urgent financial assistance for supposed banking issues. assistance. Simultaneously, CSIRT Italia flagged SMS phishing campaigns mimicking municipal communications, such as unpaid speeding fines, using the branding of services like SEND and pagoPA. Further impersonation schemes have targeted tax and social security systems. CERT-AgID identified a specific scam involving fake TARI (waste tax) refunds using refunds, where fraudulent websites that mimic the PagoPA interface. Additionally, in interface to steal tax codes, identity card numbers, and credit card details, including CVV codes. In the Pisa region, fraudulent SMS and web portals are impersonating impersonate the National Social Security Institute (INPS) to steal identity documents and payment information under the guise of urgent data updates or refunds. Authorities emphasize that official entities do not send direct links updates. Newer social engineering tactics have also been reported, such as a case in Camerino where a victim was targeted by a fake payment alert via SMS or email SMS, followed by a phone call from an individual posing as a member of the Carabinieri. The scammer convinced the victim to request sensitive data. transfer funds to a “secure account,” resulting in a loss of over 30,000 euros.

Versions

  1. 2026-09-06 10:37 UTC Italy phishing, physical & SPID fraud – Aug/Sept 2026
  2. 2026-09-04 21:14 UTC Italy phishing, physical & SPID fraud – Aug/Sept 2026
  3. 2026-09-03 14:09 UTC Italy phishing, physical & SPID fraud – Aug/Sept 2026
  4. 2026-08-26 16:08 UTC Italy phishing, physical & SPID fraud – Aug 2026
  5. 2026-08-26 06:55 UTC Italy phishing, smuggling & SPID fraud – Aug 2026
  6. 2026-08-25 12:22 UTC Italy phishing, smuggling & SPID fraud – Aug 2026
  7. 2026-08-25 07:02 UTC Italy phishing, smuggling & SPID fraud – Aug 2026
  8. 2026-08-24 13:34 UTC Italy phishing, smuggling & SPID fraud – Aug 2026
  9. 2026-08-22 11:40 UTC Italy phishing, smuggling & SPID fraud – Aug 2026
  10. 2026-08-21 06:15 UTC Italy phishing, smuggling & SPID fraud – Aug 2026
  11. 2026-08-16 09:24 UTC Italy phishing, smuggling & SPID fraud – Aug 2026
  12. 2026-08-10 14:12 UTC Italy phishing, smuggling & SPID fraud – Aug 2026
  13. 2026-08-04 15:46 UTC Italy phishing, smuggling & SPID fraud – Aug 2026
  14. 2026-08-03 12:22 UTC Italy fraud, phishing & smishing crackdown – Aug 2026
  15. 2026-08-02 07:15 UTC Italy fraud, phishing & smishing crackdown – late July 2026
  16. 2026-07-25 22:21 UTC Italy fraud, phishing & crime crackdown – late July 2026

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.