AI Phishing Attacks Exploit a Fake “Health Ticket Refund” from the Ministry of Health

AI Phishing Attacks Exploit a Fake “Health Ticket Refund” from the Ministry of Health
CERT-AGID identified a phishing campaign using the Ministry of Health’s name and branding to trick victims into revealing personal data and payment card details through a fake €278.26 refund notice. The fraudulent emails spoof the sender [email protected] and direct users to malicious pages that collect identity, contact, and card information for further abuse. #CERT-AGID #MinisteroDellaSalute #fondisanitari.gov.it

Keypoints

  • The phishing campaign impersonates the Italian Ministry of Health using its name and graphics.
  • Victims receive an email with the subject “Hai diritto a un rimborso” claiming a €278.26 reimbursement for a supposed double payment of a health ticket.
  • The sender address [email protected] is spoofed to make the message appear to come from public administration.
  • The malicious site guides victims through four steps to harvest fiscal code, date of birth, personal contact details, address, and card data.
  • The payment card form requests cardholder name, card number, expiration date, CVV, and notes that 3-D Secure is required.
  • Collected information can be used for unauthorized card transactions and future smishing, vishing, or banking phishing campaigns.
  • CERT-AGID asked for the malicious domain to be taken down and shared IOCs with public administrations and accredited organizations.

MITRE Techniques

  • [T1598.001 ] Phishing for Information: Spearphishing via Email – Used to deliver the fraudulent reimbursement message through email impersonating the Ministry of Health [’email che utilizza il nome e le grafiche del Ministero della Salute’]
  • [T1036.005 ] Match Legitimate Name or Location – The sender identity and branding were made to look official by spoofing a public administration address [‘Il mittente [email protected] viene falsificato attraverso tecniche di spoofing’]
  • [T1585.001 ] Establish Accounts: Social Media Accounts – Not mentioned
  • [T1566.002 ] Phishing: Spearphishing Link – Victims were urged to click a button that led to a malicious website [‘cliccare su un pulsante “Conferma i tuoi dati” che lo conduce al sito malevolo’]
  • [T1078 ] Valid Accounts – Not mentioned
  • [T1110 ] Brute Force – Not mentioned
  • [T1005 ] Data from Local System – The site collected extensive personal and payment data entered by the victim [‘inserire codice fiscale e data di nascita’; ‘nome e cognome, indirizzo email, numero di cellulare’; ‘numero della carta, data di scadenza e CVV’]

Indicators of Compromise

  • [Email address ] spoofed sender used in the phishing email – [email protected]
  • [URL/domain ] malicious website hosting the fraudulent refund pages – malicious domain (download available via IoC link)
  • [Email subject ] lure used to entice victims – “Hai diritto a un rimborso”
  • [Monetary amount ] fake reimbursement amount shown to victims – €278.26
  • [Button text ] call-to-action leading to the phishing site – “Conferma i tuoi dati”
  • [Card data fields ] payment data requested on the fake form – cardholder name, card number, expiration date, CVV


Read more: https://cert-agid.gov.it/news/phishing-ai-danni-del-ministero-della-salute-sfrutta-un-falso-rimborso-ticket-sanitario/