False TARI refund of 95 euros: the PagoPA clone asks for the CVV

Written by Jason Miller

The CERT-AGID has identified a series of sites that reproduce the name, logo and graphics of PagoPA to steal personal data and payment card information. The pages announce a refund for a payment of the TARI made in excess and invite you to complete an online procedure to confirm your identity and indicate your credit details. The opening screen displays a fictitious case number and a “Continue with request” button.

The procedure consists of four steps. The first presents itself as a consultation of the practice and asks for the Tax ID code or your identity card number; the second returns the outcome, i.e. a refund of 95.00 euros referring to a TARI case from the year 2025 and a dated overpayment August 28, 2026. The third collects name and surname, residential address, postal code, municipality, province, region, mobile number and email address.

The initial announcement talks about accreditation details, but the final form asks for something else: name and surname of the owner, credit card number, expiration date and CVV. These are the data needed to attempt an online payment, not to receive one. The three-digit security code authorizes a debit and has no function in a refund procedure.

Whoever completes all the steps delivers in a single session a personal profile complete with address, mobile phone and email, together with the card details. CERT-AGID notes that the combination is sufficient both to attempt fraudulent operations and to fuel subsequent targeted phishing campaigns. Knowing a person’s residence and contact details makes the message they receive the next time much more credible.

The agency has started activities for the disposal of malicious domains identified and informed the body concerned. The indicators of compromise, i.e. the technical elements that allow defense systems to recognize and block fraudulent pages, were shared with the organizations accredited to the IoC flow and made public. However, the press release does not indicate through which channel the victims arrive on the pages, whether by email, SMS or messaging.

Jason Miller

I'm Jason Miller, and I've been passionate about technology and storytelling for over a decade. As a lead writer at Herald Editorials, I strive to bring clarity and creativity to complex tech topics. When I'm not writing, you'll find me exploring the latest gadgets or hiking in the great outdoors.