A sophisticated phishing campaign targeting Italy’s Portale dell’Automobilista — the official driver and vehicle services portal of the Ministry of Infrastructure and Transport — is actively hitting thousands of Italian users. Cybercriminals have cloned the legitimate government website so convincingly that the fraudulent version is appearing among the top organic results on Google, deceiving unsuspecting users at scale.
How the Attack Works: The Portale dell’Automobilista Clone Site
This campaign exploits a well-known technique called clone phishing. Attackers meticulously replicate the visual interface of the official portal, producing a result that is virtually indistinguishable from the real thing to an untrained eye.
The Deceptive Domain and the HTTPS Certificate
The malicious site operates under domains such as ilportaledellautomobilista.net — differing from the legitimate address only in the top-level domain, which should be .it. To make matters worse, the fake site carries a valid HTTPS certificate, which leads users to assume the connection is secure. However, the presence of a padlock icon does not in any way guarantee a site’s authenticity.
The clone’s homepage mirrors the original almost perfectly. Most internal links are non-functional — with one critical exception: the login and registration sections, which are fully operational and specifically engineered to harvest any credentials entered by victims.
Google Indexing as a Distribution Vector
One of the most alarming aspects of this campaign is that the clone site ranks among the top organic results on Google. Users searching for the portal through a search engine naturally click on the first result they see, placing implicit trust in Google’s algorithm — and that trust becomes a vulnerability in itself.
Public reports of this activity date back to at least early 2023. The campaign remains active, and new clone domains continue to be identified on a rolling basis.
What Data Is Stolen and What Risks Do Victims Face
The primary objective of this attack is straightforward: stealing usernames and passwords. More specifically, criminals are after SPID credentials — login details for Italy’s national digital identity system (Sistema Pubblico di Identità Digitale).
The Consequences of SPID Credential Theft
The Portale dell’Automobilista serves millions of registered users. Once attackers obtain stolen credentials, they can log into the legitimate portal and access sensitive personal and administrative data belonging to victims — including driving licences, vehicle registration documents, and personal registry information.
But the risks run far deeper than that. SPID is the gateway to dozens of Italian public administration services. A criminal in possession of stolen SPID credentials could commit identity fraud, request official documents, or even claim tax benefits in a victim’s name. The potential damage extends well beyond the theft of a single password.
Who Is Behind the Attack
No public attribution to specific criminal groups has been established at this time. Sources broadly describe those responsible as cybercriminals specializing in credential theft. The absence of attribution, however, should not breed complacency. Campaigns of this nature require only moderate technical expertise yet consistently produce significant harm for victims.
How to Protect Yourself from This Phishing Campaign
Prevention remains the most effective defence against attacks of this kind. There are clear, practical steps every user should take.
Always Verify the Domain Before Entering Your Credentials
The golden rule is to manually check the browser’s address bar before typing anything. The official domain is exclusively ilportaledellautomobilista.it. Any variation — however minor — should raise an immediate red flag. It is also strongly advisable to access public administration portals by typing the URL directly into the browser, rather than relying on search engine results.
Report Fake Domains and Update Your Credentials Immediately
If you suspect you have entered your credentials on a fraudulent site, act without delay. Change your password immediately on the official portal. If your SPID credentials may have been compromised, contact your SPID Identity Provider as a matter of urgency.
Clone domains can be reported through Google Safe Browsing, which helps accelerate their removal from search indexing. CERT-AGID also provides official channels for reporting phishing campaigns of this nature.
Ultimately, user awareness remains the single most important line of defence. Organizations should train staff regularly on recognizing phishing attempts, and CISOs must actively monitor for potential exposure of corporate credentials linked to public digital services.
Sources
- CERT-AGID – Falso sito Il Portale dell’Automobilista online cattura le password inserite
- Libero Tecnologia – Attenti al finto Portale dell’Automobilista, vi ruba lo SPID
- Al Volante – Portale dell’Automobilista, sito clone cattura credenziali
- Reddit r/ItalyInformatica – Phishing Portale Automobilista
- CERT-AGID Original Source
Source: Original Article
Phishing campaigns like this attack on the Portale dell’Automobilista highlight just how critical timely threat intelligence sharing between public and private organizations truly is. IsacChain enables ISACs and public administration bodies to securely exchange indicators of compromise and malicious domains, with full traceability guaranteed by blockchain verification and automated NIS2 compliance workflows. A platform of this kind could have significantly accelerated the reporting and takedown of clone domains, reducing the impact on victims. Discover how IsacChain can help your organization at www.isacchain.com