Global Scam IntelligenceDaily updates on global scam news and tactics
Back to home
PhishingPublished: August 6, 2026Italy

Fake Italian Court Order Email Scam Spreads: Personal Data Theft via Google Drive Links

Italy is experiencing a surge in phishing emails impersonating government authorities and courts. Scammers pose as the Ministry of Interior and Rome District Court, using Google Drive links to trick victims into downloading files that steal personal data, banking credentials, and SPID digital ID information. The emails employ official-looking formatting and vague accusations of online violations to create urgency.

Scam Overview

This phishing scam impersonates the Italian Ministry of Interior and Rome District Court. The sender's email address is linked to a Greek school network domain (@sch.gr), a clear red flag. The attack aims to steal personal identification data, banking information, SPID digital ID credentials, and potentially install information-stealing malware on victims' devices.

How the Scam Works

Email Format

  • Uses the Italian Republic's official emblem and protocol numbers
  • Subject line references "Ministry of Interior – Central Directorate for Territorial Services"
  • Body claims to be from "Rome District Court"
  • Makes vague accusations of unspecified online violations linked to the victim's IP address
  • Cites non-existent "Law 231/2025, Article 44-bis" (resembling the real Legislative Decree 231/2001 to create confusion)
  • Generic salutation like "Connection Account Holder / Citizen" instead of using the victim's name
  • Contains threatening language: "If you do not respond within 48 hours, further procedures will be initiated"

Technical Methods

  • PDFs are not sent as attachments but hosted on Google Drive links Google's domain has a strong reputation with spam filters and appears trustworthy to users, allowing the emails to bypass security checks
  • Clicking the link redirects to pages requesting personal data, identity documents, SPID credentials, email passwords, or credit card information
  • In some cases, what appears to be a PDF is actually an executable file, compressed archive, or link to malicious sites
  • These infostealer programs harvest saved browser passwords, session cookies, and account authentication data

Warning Signs

Sender Address Red Flags

  • Verify the sender's email domain—legitimate Italian agencies use official domains like giustizia.it
  • Legally valid notices are sent via PEC (certified email), not standard email
  • The presence of @sch.gr or other non-institutional domains is a major warning sign

Organizational Inconsistencies

  • The email mixes different government bodies in one message: subject mentions Ministry of Interior, signature claims Rome District Court, body references a non-existent Cyber Security Department
  • Real official communications clearly identify the sending agency and its jurisdiction

False Legal References

  • "Law 231/2025" does not exist; scammers modify or confuse real law numbers to add credibility
  • Real legal documents cite actual, verifiable legislation

Poor Language and Vague Accusations

  • Fragmented sentences and awkwardly pasted administrative terminology
  • Accusations are extremely vague: "you visited a website you should not have visited"
  • Legitimate legal notices are written professionally and specify the exact violation

Prevention and Response

If You Receive This Email

  • Do not open attachments or click links
  • Do not reply to the sender (confirmation that the address is active makes you a target for future attacks)
  • Take a screenshot of the email header
  • Prepare to report it to authorities

If You Clicked the Link

  • Immediately run a full antivirus scan with an up-to-date program
  • Change all major passwords: email, online banking, Google, social media, and work accounts
  • Enable two-factor authentication where available
  • Check recent account access logs in security settings

If You Entered Banking or Card Information

  • Contact your bank or card issuer immediately to block the payment method

If You Entered SPID Credentials

  • Notify your SPID provider at once
  • Follow the identity provider's security recovery procedures

Where to Report

  • Polizia Postale (Italian Postal and Communications Police): Submit reports through the online Commissariat portal (Commissariato di PS online) for telematic fraud and phishing campaigns
  • Alert family members, colleagues, and those unfamiliar with email security about this ongoing campaign

Source: webnews.it

Share