CERT-AGID identified a phishing campaign using INPS branding to steal personal data, payment card details, and push victims into approving unauthorized banking transactions. The attack lures users with a supposed €730 refund tied to a “tax and contribution recalculation” and directs them to a fake site on feedsafepro[.]com that imitates the INPS portal. #INPS #CERT-AGID #feedsafepro
Keypoints
- CERT-AGID detected a phishing campaign distributed by email that impersonates INPS using its name, logo, and graphics.
- The message claims the recipient is entitled to a €730 refund due to an “automated recalculation” of their tax and contribution position.
- The phishing email uses a subject similar to “Protoc. INPS/2026/00489 – Pratica di rimborso approvata” and urges quick action via an “Accedi all’Area Riservata” button.
- The malicious link leads to feedsafepro[.]com, a domain unrelated to INPS, which hosts a fake multi-step refund process.
- The site collects identity data, including personal details, tax code, address, email, phone number, and then asks for cardholder, card number, expiry date, and CVV.
- The final stage shows a fake “Autorizzazione Bancaria 3D Secure 2.2” screen and asks the victim to approve a bank push notification within 60 seconds.
- CERT-AGID began takedown efforts against the fraudulent domain and shared the indicators of compromise with public administrations and accredited organizations.
MITRE Techniques
- [T1566.002 ] Phishing: Spearphishing Link – The campaign is delivered through email that urges the recipient to click a button leading to a malicious site (‘Email di phishing con link al sito malevolo’, ‘Accedi all’Area Riservata’).
- [T1585 ] Establish Accounts / Brand Impersonation – The attackers impersonate INPS by copying its name, logo, and visual style to increase credibility (‘utilizza nome, logo e grafica dell’INPS’).
- [T1036 ] Masquerading – The fake website mimics the INPS portal and presents itself as a legitimate refund procedure (‘riproduce l’aspetto del portale dell’Istituto’).
- [T1056.004 ] Input Capture: Credential API Hooking / Web Portal Capture – The page collects extensive personal and payment information through a fabricated multi-step form (‘richiede nome, cognome… numero della carta, data di scadenza e CVV’).
- [T1098 ] Account Manipulation – The final step attempts to trick the victim into approving a banking action through a push notification, enabling unauthorized transaction authorization (‘approvare una notifica push entro 60 secondi’).
- [T1556 ] Modify Authentication Process – The criminals seek to make the victim complete strong authentication to authorize a transaction they did not initiate (‘completare l’autenticazione forte richiesta dalla banca per autorizzare un’operazione non autorizzata’).
Indicators of Compromise
- [Domain ] malicious hosting for the fake INPS refund site – feedsafepro[.]com
- [URL ] link to fraudulent refund pages – malicious site reached via the “Accedi all’Area Riservata” button
- [Email Subject ] phishing lure used to impersonate an official refund notice – “Protoc. INPS/2026/00489 – Pratica di rimborso approvata”