In the past few hours the CERT-AGID reported a phishing campaign that reproduces the name, logo and graphics of theINPS to steal personal data and payment card details. The attackers announce the recipient a credit of 730.00 eurospresented as the result of an “automated recalculation” of his contribution and tax position. The figure seems to have been chosen on purpose, because it coincides with the number of the declaration form that the fraudulent pages recall shortly afterwards.
The phishing email that imitates an INPS communication – Source: CERT-AGID
The email has a subject that imitates an Institute protocol number and announces an approved refund procedure, with reference to an excess of payments for the tax period 2025. The recipient is invited to request the sum within a very short deadline, using the button “Log in to the Reserved Area”. The link does not lead to the Institute portal but to a site hosted on the domain feedsafepro(.)comwhich reproduces its appearance.
The first page of the fake portal asks for ten personal details: name, surname, tax code, date of birth, residential address, municipality, province, postal code, email and telephone number. The second goes to the payment card and asks for the owner, number, expiration date and CVV. On the same screen references to protected connections appear, TLS 1.3, PCI-DSS And GDPRas well as a fictional summary of the practice associated with the Model 730 of 2026: the reassuring repertoire serves to bring the victim to the next step without suspicion.

The fake refund confirmation page – Source: CERT-AGID
Once the entry is completed, the site displays a screen entitled “3D Secure 2.2 Banking Authorization in progress” and asks you to open your bank’s app and approve a push notification within 60 seconds. The pretext is the verification of the identity of the refund beneficiary. The requested confirmation is actually thestrong authentication with which the bank validates an operation that the owner never ordered.
The push notification comes from the bank’s authentic app, and the checks that the user has learned to do no longer have anything to rely on: the app is the real one, the confirmation request is the same as always. The operation that the confirmation authorizes is fraudulent, not the channel on which the request travels. The 60 seconds imposed by the fake page narrow the margin to notice this.
CERT-AGID has started activities for the disposal of the domain hosting the fraudulent pages and has informed the Institute. The indicators of compromise were shared with the Public Administrations and with the organizations accredited to the IoC flow. In the meantime, the only defense that the campaign tries to circumvent is valid: approving a push notification only when it confirms an operation just arranged in person.

