New Phishing Campaign Against INPS: Fake Refund for Recalculation of Tax Contributions

New Phishing Campaign Against INPS: Fake Refund for Recalculation of Tax Contributions
CERT-AGID identified a phishing campaign using INPS branding to steal personal data, payment card details, and push victims into approving unauthorized banking transactions. The attack lures users with a supposed €730 refund tied to a “tax and contribution recalculation” and directs them to a fake site on feedsafepro[.]com that imitates the INPS portal. #INPS #CERT-AGID #feedsafepro

Keypoints

  • CERT-AGID detected a phishing campaign distributed by email that impersonates INPS using its name, logo, and graphics.
  • The message claims the recipient is entitled to a €730 refund due to an “automated recalculation” of their tax and contribution position.
  • The phishing email uses a subject similar to “Protoc. INPS/2026/00489 – Pratica di rimborso approvata” and urges quick action via an “Accedi all’Area Riservata” button.
  • The malicious link leads to feedsafepro[.]com, a domain unrelated to INPS, which hosts a fake multi-step refund process.
  • The site collects identity data, including personal details, tax code, address, email, phone number, and then asks for cardholder, card number, expiry date, and CVV.
  • The final stage shows a fake “Autorizzazione Bancaria 3D Secure 2.2” screen and asks the victim to approve a bank push notification within 60 seconds.
  • CERT-AGID began takedown efforts against the fraudulent domain and shared the indicators of compromise with public administrations and accredited organizations.

MITRE Techniques

  • [T1566.002 ] Phishing: Spearphishing Link – The campaign is delivered through email that urges the recipient to click a button leading to a malicious site (‘Email di phishing con link al sito malevolo’, ‘Accedi all’Area Riservata’).
  • [T1585 ] Establish Accounts / Brand Impersonation – The attackers impersonate INPS by copying its name, logo, and visual style to increase credibility (‘utilizza nome, logo e grafica dell’INPS’).
  • [T1036 ] Masquerading – The fake website mimics the INPS portal and presents itself as a legitimate refund procedure (‘riproduce l’aspetto del portale dell’Istituto’).
  • [T1056.004 ] Input Capture: Credential API Hooking / Web Portal Capture – The page collects extensive personal and payment information through a fabricated multi-step form (‘richiede nome, cognome… numero della carta, data di scadenza e CVV’).
  • [T1098 ] Account Manipulation – The final step attempts to trick the victim into approving a banking action through a push notification, enabling unauthorized transaction authorization (‘approvare una notifica push entro 60 secondi’).
  • [T1556 ] Modify Authentication Process – The criminals seek to make the victim complete strong authentication to authorize a transaction they did not initiate (‘completare l’autenticazione forte richiesta dalla banca per autorizzare un’operazione non autorizzata’).

Indicators of Compromise

  • [Domain ] malicious hosting for the fake INPS refund site – feedsafepro[.]com
  • [URL ] link to fraudulent refund pages – malicious site reached via the “Accedi all’Area Riservata” button
  • [Email Subject ] phishing lure used to impersonate an official refund notice – “Protoc. INPS/2026/00489 – Pratica di rimborso approvata”


Read more: https://cert-agid.gov.it/news/phishing-ai-danni-di-inps-falso-rimborso-per-ricalcolo-contributi-fiscali/