Global Scam IntelligenceDaily updates on global scam news and tactics
Back to home
PhishingPublished: August 24, 2026Italy

Italian Healthcare Ticket Refund Phishing Scam: How to Recognize and Avoid It

A phishing campaign impersonating Italy's Health Ministry is circulating, offering a €278.26 refund for duplicate healthcare ticket payments. The scam collects personal information and credit card details through a fake refund process. Authorities have identified and are taking action against the malicious domain.

Overview of the Scam

Italy's CERT-AgID (National Cybersecurity Agency) has reported a phishing campaign impersonating the Health Ministry. The fraudulent emails promise a €278.26 refund for duplicate healthcare ticket payments, using the subject line "You are entitled to a refund."

How the Fraudulent Email Works

Sender Spoofing

  • The email appears to come from "rimborso@salute.gov.it" (Health Ministry refund service), but the address is forged using technical spoofing techniques
  • The message is designed to look official and government-backed

Message Content

  • Claims to notify the recipient of a "verified" refund following health payment checks
  • Contains a "Confirm Your Data" button that redirects to a malicious website

The Four-Step Phishing Process

The scammers have created an elaborate fake refund procedure with four stages:

Stage 1: Service Access Verification

  • Request for Tax ID (Codice Fiscale) and date of birth

Stage 2: Refund Display

  • Shows a fake refund request with "Duplicate Healthcare Ticket Payment" as the reason
  • Displays a reference code and €278.26 marked as "ready for credit"

Stage 3: Personal Data Collection

  • Full name
  • Email address
  • Mobile phone number
  • Complete residential address (including city, province, and postal code)

Stage 4: Payment Card Details

  • Cardholder name
  • Card number
  • Expiration date
  • CVV security code
  • The page falsely claims 3D Secure compliance is required and prepaid cards are not accepted, adding false legitimacy

How Criminals Use the Stolen Information

Once collected, the compromised data enables criminals to:

  1. Commit Card Fraud: Attempt unauthorized transactions using the stolen card information
  2. Sell Personal Data: Trade the collected names, addresses, emails, and phone numbers to other criminals
  3. Launch Multi-Vector Attacks: Use the same individual's information for:
    • Smishing attacks (SMS phishing)
    • Vishing attacks (phone-based phishing)
    • Banking fraud and credential theft

Critical Fact: The Government Does Not Issue Direct Refunds

The Italian Health Ministry does not provide direct email-based refund services for healthcare tickets. If you believe you are owed a refund:

  • Contact your local health authority (ASL) directly
  • Or reach out to your local hospital (Azienda Ospedaliera)

Warning Signs to Recognize

Red Flags Specific to This Scam:

  • Unsolicited refund notification for a payment you don't recall making
  • Pressure to act quickly ("Confirm immediately")
  • Sender's email address that appears official but may have slight variations
  • Requests for sensitive personal and financial information
  • Hyperlinks that don't match the claimed sender's domain

General Phishing Indicators:

  • Spelling or grammar errors
  • Generic greetings ("Dear user" instead of your name)
  • Links that redirect to unfamiliar websites
  • Requests to download attachments or enable macros

How to Protect Yourself

  1. Never Click Embedded Links: If you receive such an email, do not click links within it
  2. Verify Independently: Contact your health authority directly using phone numbers or websites found through independent research—not from the email
  3. Never Share Card Details via Email: Government agencies never request payment card information through email
  4. Report to Authorities: Forward phishing emails to your email provider's abuse team and report them to national cybersecurity agencies
  5. Check Bank Statements: Monitor your bank and credit card accounts for unauthorized activity
  6. Use Multi-Factor Authentication: Enable two-factor authentication on your financial accounts where available

Official Response

CERT-AgID has taken the following actions:

  • Requested removal of the domain hosting the phishing pages
  • Notified the Italian Health Ministry
  • Issued public warnings about the campaign

Source: macitynet.it

Share