CERT-AGID identified a phishing campaign that abuses the names and visuals of Polizia di Stato and pagoPA to trick victims into paying a fake traffic fine. The fraudulent flow collects vehicle plate data, tax code, email address, and payment card details, while domains containing “poliziadistato” were used to host the fake pages. #PoliziaDiStato #pagoPA #CERTAGID
Keypoints
- The phishing campaign impersonates Polizia di Stato and pagoPA to make a fake traffic ticket appear legitimate.
- The attack uses malicious domains containing the string “poliziadistato” but with non-official extensions.
- The fake site first presents itself as a Polizia Stradale portal for checking violations and driver data.
- Victims are asked to enter license plate and tax code details, which increases realism and collects personal data.
- The fraud then shows a fake payment notice with a discounted fine of 42 euros and pressure to pay within 15 days.
- The flow continues through pages that mimic pagoPA, request an email address, and finally solicit cardholder, card number, expiry date, and CVV.
- CERT-AGID requested domain takedowns and distributed the campaign’s indicators of compromise to accredited organizations.
MITRE Techniques
- [T1566.002] Spearphishing Link – The victims are lured to a fraudulent website that impersonates official services and payment pages [‘the site presents itself as a portal…’; ‘the victim is then invited to access a presumed reserved area’]
- [T1036] Masquerading – The attacker disguises the site as Polizia di Stato and pagoPA to appear trustworthy [‘uses logos and colors traceable to the State Police’; ‘reproduces the graphics of pagoPA’]
- [T1583.001] Acquire Infrastructure: Domains – Malicious domains are registered/used with “poliziadistato” in the name and a different extension [‘sites are hosted through domain names that contain the word “poliziadistato”’]
- [T1204.001] User Execution: Malicious Link – The phishing relies on the user following the fraudulent web flow to input sensitive information [‘the chain continues with the request for an email address’; ‘the last screen requests payment card details’]
- [T1056.003] Input Capture: Web Portal Capture – The fake web forms collect vehicle, identity, contact, and payment details [‘enter the license plate and tax code’; ‘requests the cardholder name, card number, expiry date and CVV’]
Indicators of Compromise
- [Domains ] phishing infrastructure hosting fake Polizia di Stato/pagoPA pages – domains containing “poliziadistato” with non-official extensions, and other related domains
- [URLs ] malicious landing and checkout pages used in the fake fine/payment flow – homepage of the fake Polizia Stradale portal, fake pagoPA page
- [Brand impersonation elements ] visual lures used in the scam – Polizia di Stato logos, pagoPA graphics, Agenzia delle Entrate – Riscossione references
- [Data fields requested ] victim data collected by the phishing pages – vehicle plate, tax code, email address, cardholder name, card number, expiry date, CVV