CERT-AGID identified and disrupted a fraudulent website impersonating ARERA to trick users into revealing personal and financial data through a fake refund tied to the social water bonus. The site used typosquatting and a staged flow that led victims from a phone-number check to a bogus credit card verification page. #ARERA #CERT-AGID #bonussocialeidrico
Keypoints
- CERT-AGID identified a fraudulent site that copied the name and logo of ARERA.
- The scam used the social water bonus as a lure, presenting it as a real refund opportunity.
- The first page asked users to enter their phone number to check eligibility for the benefit.
- Victims were then shown a fake available amount of €100,93 and a practice summary.
- The final step requested “credit card verification,” collecting cardholder name, card number, expiration date, and CVV.
- The malicious domain was taken down, and the relevant entity was informed.
- IOC information related to the campaign was distributed through the CERT-AGID feed to accredited organizations.
MITRE Techniques
- [T1036 ] Masquerading – The site impersonated a trusted public authority by copying its name and logo to appear legitimate (‘the fraudulent site reproduces the name and logo of ARERA’).
- [T1583.001 ] Acquire Infrastructure: Domains – The attack relied on a malicious domain created to host the fake ARERA pages (‘the malicious domain was shut down’).
- [T1566.002 ] Phishing: Spearphishing Link – Users were guided through a deceptive web flow intended to capture sensitive data via a fake eligibility check and payment form (‘inviting the user to enter their phone number’, ‘verification of the credit card’).
- [T1056 ] Input Capture – The site solicited personal and payment details directly through web forms to harvest sensitive information (‘name, card number, expiration date and CVV are the requested information’).
- [T1621 ] Multi-Factor Authentication Request Generation – The fake verification step induced the victim to submit additional sensitive payment information under the guise of processing a payout (‘to be able to receive the amount’).
Indicators of Compromise
- [Domains] fraudulent ARERA-lookalike site – the malicious domain used for the scam, and the related takedown notice
- [Web Pages / URLs] fake bonus water page and credit card verification page – the homepage imitating ARERA’s bonus section, and the subsequent payment verification page
- [Amounts] fake payout amount shown to victims – €100,93
- [Organizations] impersonated and responding entities – ARERA, CERT-AGID
Read more: https://cert-agid.gov.it/news/phishing-ai-danni-di-arera-utilizza-il-tema-bonus-sociale-idrico/