The phone rings. A notification arrives. “New email”, it says on the display. I open, read, stare at the screen for a few seconds. The message was sent by Giorgia Meloni. Or at least that’s how it seems. I check, the email address coincides with the official one: meloni_g@camera.it. The test worked. Meloni’s email is not an isolated case, including addresses of the Government, Prosecutor’s Office, institutions, high officials of the State they can be cloned.
What allows this is a vulnerability discovered by the computer scientist Andrea Mavillawhich allows you to clone government emails. Together with him we conducted a series of tests with different directions. Among these: Government, Senate, Chamber of Deputies, Ministry of the Interior, the email of Nicola Gratteri, the Naples Prosecutor’s Office and the Rome Prosecutor’s Office. Also the institutional addresses of Certified Email (PEC) are exposed.
For years, hackers have been trying to clone emails to steal money or data from users using spoofing techniques. What is surprising, however, is that this new vulnerability also concerns institutional addresses that have to do with the security and with matters of national interest. What we have conducted, therefore, are not simple tests, but the demonstration that a critical flaw exists in the system.
Which cities are most affected by hackers attacking home security cameras: analysis

FANPAGE.IT | The test email from the address meloni_g@camera.it
Institutional emails are at risk: the spoofing attack
“At the moment, there is a serious vulnerability affecting our country, especially institutional and governmental addresses. It is possible to create a email exactly identical to the official one“, explained Mavilla to Fanpage.it. We are faced with a case of email spoofing, it is a type of cyber attack that implements various strategies to falsify the identity (from the English spoof).
“This kind of spoofing though it is very insidiousbecause the email is replicated without any difference. If authentication controls are not properly set up or enforced, an attacker can send messages that appear as coming from a legitimate domain“, added Mavilla. “There is no need to compromise the account: it can be exploited the absence or misconfiguration of rules that authenticate the sender.”
What we discovered when testing cloned emails
We conducted several tests (to do them we used standard email authentication testing and header analysis techniques, without disclosing exploits or touching third-party content or mailboxes) to check the vulnerability. It was possible to send emails by cloning addresses of the Government, the Prosecutor’s Office, the Constitutional Court, “at the moment all public and private domains are affected”.
But how is it possible that even government and institutional policies are vulnerable? As Mavilla explains, this happens when the infrastructure is fragmented across multiple vendorswith non-uniform DNS and policies, legacy systems legacy and incompletely centralized governance of security configurations.
There is currently no evidence that this flaw was exploited by third parties. However, it was verified that the conditions for spoofing were present and realistically exploitable.

FANPAGE.IT | The text of a test email for cloned addresses
Because some domains are more exposed
During our testing we encountered some exceptions. For example, Gmail has blocked some incoming messages on its system, reporting the email or marking it as spam. However, it doesn’t work the other way around. In fact, we had no problems sending emails cloning gmail addresses.
“Domains that are more at risk they have no set control rules, or they only have them “half” (they check but do not block anything), which allow too many different servers to send emails in their name, they do not use digital signatures that allow the authenticity of the email to be verified, they accept all incoming emails, even suspicious ones and they rely on too many different suppliers without clear coordination”, explained Mavilla. “These conditions, combined, make spoofing technically possible without compromising your account”.
What are the risks of cloned emails
If even institutional emails can be cloned, if even PEC addresses are vulnerable, more risk scenarios open up. First of all, the theft of sensitive information. For example, you could clone the power of attorney’s email to ask the lawyers of the suspects for documents and documents for the ongoing investigations. Or, clone the address of the Ministry of Defense to send an email to a detachment on a mission to obtain information on weapons.
Not only that. As Mavilla explains, it can lead to “spear-phishing, payment scams (business email compromise), the spread of malware, ransomware, data theft, reputational damage e legal responsibilities for failure to adopt adequate controls.”
How to reduce institutional email spoofing
The first fundamental step is centralize servicesavoiding displacing them between different suppliers, “fragmentation in fact creates inconsistencies and weak points in security configurations. Once management has been brought back under a single control, it is necessary to thoroughly review all email authentication settings – DMARC, SPF and DKIM – bringing them into real enforcement and not leaving them only in monitoring mode.”
There is then the organizational themeit is necessary to periodically train staff against phishing, carry out real simulations and define rapid response procedures.
“Tests have also been carried out with American government bodies and with the CIA, and all this does not happen, precisely because the protocols they use in other countries they are very rigid compared to oursand above all certain entities have the management of the domains in their own hands, and is not given to third parties like we do.“
When we talk about government domains, we cannot place the blame solely on the IT administrator or the provider “the responsibility lies with whoever is in charge of the country’s IT security”, only by combining centralized governance, solid configurations and security culture can the risk be concretely reduced.

FANPAGE.IT | Tests on cloned emails

