In recent months, Italy has recorded a worrying increase in cyber attacks targeting ordinary citizens. A particularly sophisticated case was recently analyzed by CERT-AgID, the cybersecurity team of the Agency for Digital Italy. It involves an adaptive phishing campaign that exploits citizens’ trust in government institutions.
According to CERT-AgID’s analysis, towards the end of 2025, a particularly insidious phishing campaign was identified. Cybercriminals created fake websites and sent fraudulent emails impersonating Italian government entities, including the Presidency of the Council of Ministers and the Revenue Agency. The goal was to induce users to enter their banking credentials and personal data on counterfeit portals. The peculiarity of this campaign lies in the use of Telegram bots for the immediate exfiltration of stolen data. At the moment, no specific actor responsible for these attacks has been identified.
The importance of this incident should not be underestimated. This type of attack represents a concrete threat to the security of personal and financial data of Italian citizens. The use of government identities gives the attacks a credibility that significantly increases the likelihood that victims will fall into the trap. Furthermore, the use of technologies such as Telegram bots for data exfiltration demonstrates the constant evolution of tactics used by cybercriminals.
To protect against these attacks, both companies and individual users should adopt some precautions. It is essential to always verify the authenticity of communications received from alleged government entities, carefully checking the sender’s email address and the URL of websites before entering any personal data. It is advisable to access official portals directly by typing the address in the browser bar, rather than clicking on links received via email. Additionally, enabling two-factor authentication on online services can provide an additional layer of protection.
- Key points to remember:
- Adaptive phishing attacks are targeting Italian users through false communications from government entities
- Criminals use advanced technologies such as Telegram bots to quickly steal personal and banking data
- Verifying the authenticity of communications and directly accessing official portals are the main recommended preventive measures
Sources:
https://cert-agid.gov.it/news/analisi-di-phishing-adattivo-spoofing-e-esfiltrazione-tramite-telegram/
https://www.plenglish.com/news/2025/12/16/italy-faces-increase-in-cyberattacks/
https://www.agid.gov.it/en/news/annual-report-cyber-attacks-published-cert-agid
Source: CERT-AgID