Phishing Scam: The Many Traps That Exploit the Name of Italy’s State Police and pagoPA

Phishing Scam: The Many Traps That Exploit the Name of Italy’s State Police and pagoPA
CERT-AGID identified a phishing campaign that abuses the names and visuals of Polizia di Stato and pagoPA to trick victims into paying a fake traffic fine. The fraudulent flow collects vehicle plate data, tax code, email address, and payment card details, while domains containing “poliziadistato” were used to host the fake pages. #PoliziaDiStato #pagoPA #CERTAGID

Keypoints

  • The phishing campaign impersonates Polizia di Stato and pagoPA to make a fake traffic ticket appear legitimate.
  • The attack uses malicious domains containing the string “poliziadistato” but with non-official extensions.
  • The fake site first presents itself as a Polizia Stradale portal for checking violations and driver data.
  • Victims are asked to enter license plate and tax code details, which increases realism and collects personal data.
  • The fraud then shows a fake payment notice with a discounted fine of 42 euros and pressure to pay within 15 days.
  • The flow continues through pages that mimic pagoPA, request an email address, and finally solicit cardholder, card number, expiry date, and CVV.
  • CERT-AGID requested domain takedowns and distributed the campaign’s indicators of compromise to accredited organizations.

MITRE Techniques

  • [T1566.002] Spearphishing Link – The victims are lured to a fraudulent website that impersonates official services and payment pages [‘the site presents itself as a portal…’; ‘the victim is then invited to access a presumed reserved area’]
  • [T1036] Masquerading – The attacker disguises the site as Polizia di Stato and pagoPA to appear trustworthy [‘uses logos and colors traceable to the State Police’; ‘reproduces the graphics of pagoPA’]
  • [T1583.001] Acquire Infrastructure: Domains – Malicious domains are registered/used with “poliziadistato” in the name and a different extension [‘sites are hosted through domain names that contain the word “poliziadistato”’]
  • [T1204.001] User Execution: Malicious Link – The phishing relies on the user following the fraudulent web flow to input sensitive information [‘the chain continues with the request for an email address’; ‘the last screen requests payment card details’]
  • [T1056.003] Input Capture: Web Portal Capture – The fake web forms collect vehicle, identity, contact, and payment details [‘enter the license plate and tax code’; ‘requests the cardholder name, card number, expiry date and CVV’]

Indicators of Compromise

  • [Domains ] phishing infrastructure hosting fake Polizia di Stato/pagoPA pages – domains containing “poliziadistato” with non-official extensions, and other related domains
  • [URLs ] malicious landing and checkout pages used in the fake fine/payment flow – homepage of the fake Polizia Stradale portal, fake pagoPA page
  • [Brand impersonation elements ] visual lures used in the scam – Polizia di Stato logos, pagoPA graphics, Agenzia delle Entrate – Riscossione references
  • [Data fields requested ] victim data collected by the phishing pages – vehicle plate, tax code, email address, cardholder name, card number, expiry date, CVV


Read more: https://cert-agid.gov.it/news/phishing-a-tema-multe-sfrutta-il-nome-della-polizia-di-stato-e-di-pagopa/