THE’National Cybersecurity Agency published two security bulletins three days apart, both on campaigns targeting Italian users. The first, ofSeptember 8describes a campaign of BRT themed smishing which imitates courier non-delivery notices; the second, of September 10tha campaign by phishing via email which reproduces the name and logos of the Company Register and the Chambers of Commerce. The first points to your payment card details and code OTP confirmation, the second to the company data of the person opening the message.
“BRT Courier” themed smishing campaign
Source: ACN
The SMS message closely resembles those that delivery companies actually send when a delivery is not successful, and invites you to connect to a site to book a new delivery. Anyone who follows the link lands on a page that asks to update the delivery address and to re-enter your data. The next step introduces the payment of a handling fee for redeliveryof a modest amount, together with the request for the name of the holder, the card number, the expiry date and the CVV/CVC security code.

Source: ACN
Those who continue with the payment will see a verification animation similar to those of legitimate online transactions, then the request for OTP code received via SMS on the registered device. Once the code has been entered, a second verification screen starts during which, the CSIRT writes, the portal it would seem to simulate a transaction to the detriment of the victim; the bulletin does not indicate which amounts are moved nor how many users have been affected. The CSIRT focuses explicitly on the initial amount: precisely because it is small, it tends to make the initial communication appear truthful and leads those who receive it to pay less attention to the fraudulent mechanism.
“Business register” themed phishing campaign
The second campaign travels via email and is aimed at businesses. The text, written in a uncertain Italianbuilds what the CSIRT calls a emergency operational contextpresenting itself as the third communication with which you are asked to enter or update the data on the indicated portal. The link leads to a page that improperly reproduces the name and logos of the portal Company Register and of Chambers of Commerce.
After sending the data the system redirects the user to legitimate portal of the Company Register, so that the procedure just completed appears authentic. The bulletin does not describe any payment requests: the focus here is on company datanot those on paper. However, the mitigation measures listed in the two documents are the same item by item, including those on payment cards and on alleged deliveries, which in the case of the Business Registry have no confirmation.
Both bulletins give the same advice to anyone who notices that they have entered their data on one of the two pages: contact thebanking institution or the card issuer to evaluate the blocking of the payment instrument and monitor unrecognized transactions. For the rest, the usual recommendations remain, starting from typing the address of the official portals by hand instead of following the links received via SMS or email, and from checking the domain before entering any data. The indicators of compromise of the two campaigns are published in the appropriate sections of the respective bulletins.

