Fake emails and sites imitate INPS to steal personal and card data. Here’s how it works, what signals should alarm you and what to do if you’ve already clicked
Be careful of the promise of an INPS refund of 730 euros. A new phishing campaign is underway. The alarm was raised by CERT-AgID, the Computer Emergency Response Team of the Agency for Digital Italy, which identified fake emails and sites built to copy the name, logo and graphics of the social security institution. Falling for the scam means giving the scammers your personal details and access to your payment card.
How the 730 euro fake INPS refund scam works
It all starts with an email that simulates an official communication from INPS. The message announces a credit of 730 euros, for an alleged automatic adjustment between what was paid and what is due in 2025. The figure is also not random, but was chosen precisely to make one fall into a trap. In fact, it recalls the tax return, Model 730, which millions of Italians fill out every year. This way everything is more “emotionally” credible. A false protocol number appears in the subject, while the text talks about a refund procedure already approved and a very close deadline for requesting the sum. Rush is the other psychological element that pushes victims to click without thinking
The email and the fake site: the signs to recognize phishing
If you observe carefully, however, there is no shortage of warning signs. The sender’s address does not correspond to an official INPS domain and the text often opens with a generic “Hello customer”, without the user’s name: the Institute’s actual communications are personalized and have a different tone. By clicking on the “Access Reserved Area” button you will be directed to a site that reproduces the graphics of the INPS portal, but which is located on a domain foreign to the Institute. Furthermore, unlike the real INPS portal, here access is not required via SPID, CIE or CNS, which are the only digital identification systems provided by real INPS services. Once you enter the fake portal, you are asked for your personal data (name, surname, tax code, date of birth, residential address, municipality, province, postal code, e-mail and telephone number) and payment card data (holder, number, expiry date and CVV code). To make everything even more credible and “reassure” the victims, the screen shows false references to protected connections and a fictitious summary of the practice linked to the 2026 Model 730.
The final trap: the fake banking authorization via app
The most dangerous step is the last one. After entering all the data, a fake verification screen appears, labeled ‘3D Secure 2.2 Bank Authorization in progress” and you are asked to open the banking app and confirm within a minute, with the excuse of having to verify the identity of the refund beneficiary. In reality, that notification does not confirm any refund, but authorizes a payment that the scammers have just arranged using the data they just stole. The push notification actually comes from your bank’s authentic app. It is therefore almost impossible to notice of the deception by following the normal security checks. The app is the real one, the request looks like it always does. It is the operation you are about to authorize that is fraudulent, not the channel on which the request arrives.
How to protect yourself from the INPS refund scam
How to defend yourself if you receive the email?
- Do not click on links in unsolicited emails that promise INPS refunds or credits, even if they seem official.
- Always check the site domain: INPS only uses its official portal and requires access via SPID, CIE or CNS, never credit card forms.
- Never enter your payment card details on pages reached via links received via e-mail.
- Approve a push notification from your bank only if you have just arranged an in-person transaction. This is the real and only security barrier against this type of scam.
- If in doubt, check your position directly on the INPS websiteby logging in with your digital credentials, without going through external links.
Anyone who has already entered their data or approved a suspicious notification should immediately contact their bank to block the card and the operations in progress, and report the incident to the Postal Police.



