Phishing Campaign Uses Fake Vehicle-Tax Debt to Impersonate ACI

Summary
CERT-AGID identified a phishing campaign impersonating the Automobile Club d’Italia (ACI) with fraudulent sites that claim victims owe vehicle tax. The sites request tax-code, vehicle, identity, contact, and payment-card details, presenting a simulated €15.87 penalty. CERT-AGID requested takedown of the domains, informed ACI, and shared the indicators with accredited organizations.
Key points
- The fraudulent sites use ACI’s name, logo, and visual style to appear legitimate.
- The scam claims an annual vehicle tax is overdue and warns of penalties and driving restrictions.
- The sites first request the victim’s tax code and vehicle license plate.
- They then collect identity and contact details, followed by full payment-card information.
- The fake payment page displays a €15.87 penalty.
- CERT-AGID requested removal of the domains, notified ACI, and shared campaign indicators with accredited organizations.
Attack Vectors
- Fraudulent websites impersonating ACI and using a fake overdue vehicle-tax claim to elicit personal, vehicle, and payment-card details.
Defensive Notes
- ACI’s official vehicle-tax payment service uses public-administration authentication systems such as SPID or CIE.
- Treat requests for personal or banking data on sites reached through unexpected communications, without digital-identity login, as a possible sign of fraud.
- CERT-AGID requested takedown of the identified domains and shared indicators with accredited organizations.
Tags
PhishingBrand ImpersonationPersonal Data TheftPayment Card Theft
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | acitalia[.]click | CERT-AGID identified this domain as fraudulent phishing infrastructure impersonating ACI. |
| DOMAIN | acitalia[.]info | CERT-AGID identified this domain as fraudulent phishing infrastructure impersonating ACI. |