Health Card Phishing: Active Campaign Targeting Italian Citizens in 2026

Phishing Tessera Sanitaria: Campagna Attiva in Italia nel 2026

A new phishing campaign themed around Health Card renewal is actively targeting Italian citizens. Fraudsters are impersonating the Italian Ministry of Health to steal personal and banking data. The official alert was issued in the final weeks of April 2026.


How the Scam Works

The Fraudulent Emails

Victims receive an email that appears entirely official. The sender mimics the Ministry of Health, complete with institutional logos and branding. The message urges recipients to click a link to renew or replace their Health Card.

The tone strikes a careful balance — urgent yet reassuring. This is a textbook social engineering technique. The goal is to lower the recipient’s guard before they have time to think critically.

The Fake Website

Clicking the link lands the user on a counterfeit portal designed to closely replicate official government pages. To an untrained eye, it looks entirely legitimate.

The real trap, however, is the data entry form. Victims are asked to submit full personal details, identity document information, and — in some variants of the campaign — banking credentials. The result is a highly valuable data package handed directly to cybercriminals.


Risks for Victims

Data Theft and Identity Fraud

The stolen information can be exploited in multiple ways. First, it is sold on dark web data markets. Second, it enables identity document cloning.

Banking credentials, meanwhile, open the door to unauthorized account access. The damage to victims can be both financial and reputational. Recovering a stolen digital identity is a lengthy and resource-intensive process.

A Strategically Chosen Target

It is worth understanding why the Health Card makes such an effective lure. Every Italian citizen holds one. Almost anyone could plausibly believe they need to renew it.

This campaign exploits a need that feels routine and universal. There is no need to target a specific demographic — attackers simply blast millions of emails and wait for the most vulnerable recipients to take the bait.


Institutional Response and Operational Advice

The Ministry of Health’s Clarification

The Ministry of Health has issued a clear and unambiguous public warning. The institution states that it never sends emails containing links for Health Card renewal. It also does not request personal data through non-institutional online forms.

CERT-AGID has confirmed and amplified the alert, classifying the campaign as active and ongoing at a national scale. Multiple Italian media outlets and official institutional social channels have widely disseminated the warning.

What to Do If You Receive the Email

The recommended actions are straightforward and should be communicated to users immediately:

  • Never click any links contained in the suspicious email.
  • Do not enter any personal or banking information into the form.
  • Delete the message from your inbox immediately.
  • Report the email as phishing to your mail provider.

Anyone who has already submitted their data must act urgently. Contact your bank without delay. Filing a report with the relevant authorities is also strongly advised.

Indicators to Watch

For security teams, several red flags are worth analyzing. The sender’s address does not match the Ministry’s official domain. The destination URL is not a verified .gov.it domain. The message artificially creates a sense of urgency.

IT managers and CISOs should evaluate implementing updated anti-phishing filters. Email gateway rules must be configured to block identified fraudulent domains. That said, end-user awareness training remains the single most effective long-term defense.


Conclusion

The Health Card phishing campaign is yet another demonstration of how cybercriminals exploit themes rooted in everyday life. The choice of a healthcare topic is no coincidence — it generates trust and disarms the psychological defenses of potential victims.

The response must therefore work on two levels. Technologically: filters, domain blocks, and active monitoring. Culturally: continuous end-user awareness and education. Only an integrated approach can meaningfully reduce the effectiveness of these campaigns.

IsacChain will continue to monitor the evolution of this threat.


Sources:

Source: Original article


Campaigns like the Health Card phishing wave highlight the critical need for rapid, verified threat intelligence sharing between public and private sector organizations. IsacChain enables the secure distribution of indicators of compromise related to active phishing campaigns, while simultaneously delivering automated NIS2 compliance for obligated entities. Every piece of shared data is certified through blockchain-based verification, ensuring the integrity and full traceability of information. Discover how IsacChain can help your organization at www.isacchain.com