Phishing Campaign Uses Fake Vehicle-Tax Debt to Impersonate ACI

· Original article ↗

Summary

CERT-AGID identified a phishing campaign impersonating the Automobile Club d’Italia (ACI) with fraudulent sites that claim victims owe vehicle tax. The sites request tax-code, vehicle, identity, contact, and payment-card details, presenting a simulated €15.87 penalty. CERT-AGID requested takedown of the domains, informed ACI, and shared the indicators with accredited organizations.

Key points

  • The fraudulent sites use ACI’s name, logo, and visual style to appear legitimate.
  • The scam claims an annual vehicle tax is overdue and warns of penalties and driving restrictions.
  • The sites first request the victim’s tax code and vehicle license plate.
  • They then collect identity and contact details, followed by full payment-card information.
  • The fake payment page displays a €15.87 penalty.
  • CERT-AGID requested removal of the domains, notified ACI, and shared campaign indicators with accredited organizations.

Attack Vectors

  • Fraudulent websites impersonating ACI and using a fake overdue vehicle-tax claim to elicit personal, vehicle, and payment-card details.

Defensive Notes

  • ACI’s official vehicle-tax payment service uses public-administration authentication systems such as SPID or CIE.
  • Treat requests for personal or banking data on sites reached through unexpected communications, without digital-identity login, as a possible sign of fraud.
  • CERT-AGID requested takedown of the identified domains and shared indicators with accredited organizations.

Tags

PhishingBrand ImpersonationPersonal Data TheftPayment Card Theft

Indicators of compromise

TypeIndicatorContext
DOMAINacitalia[.]clickCERT-AGID identified this domain as fraudulent phishing infrastructure impersonating ACI.
DOMAINacitalia[.]infoCERT-AGID identified this domain as fraudulent phishing infrastructure impersonating ACI.

MITRE ATT&CK

Countries