Trenitalia, the pseudo-refund scam: our editorial staff is also among the targets of fake SMS

A SMS that appears to come from Trenitaliainside which we find a refund ready to be redeemed and the usual link to open. Three elements are enough to trigger one of the most insidious scams of the summer, based on the real inconvenience caused by delays and problems of the last period, and which therefore sounds plausible. We know this from direct experience, given that even our editorial team’s cell phones have received, in recent days, messages identical to the ones we are talking about, as you can see in the screenshot below:

@Greenme editorial team

A proven scam

The CERT-AGID (an acronym that stands for Computer Emergency Response Team of the Agency for Digital Italy, the structure that deals with information security and cybersecurity for the public administration) has identified a smishing campaign that exploits the Trenitalia name to steal personal data from users. Deceptive SMS messages invite you to click on a link under the guise of a false refund linked to a train delay. The attackers’ goal is to steal users’ phone numbers and credit card details. The link, explains the organisation, leads to a page which faithfully reproduces the official Trenitalia graphics and informs the victim that, due to the alleged delay, the recovery of an amount of 15 euros. The typosquattingi.e. domains that imitate the official one with an added letter or an anomalous extension, designed to deceive less attentive glances. Once entered into the mechanism, users are first asked for their telephone number, then their complete credit card details and finally the payment of a small “verification fee” (in the variants identified, just 1.50 euros) presented as necessary to unlock the accreditation.

The CERT-AGID weekly bulletin relating to the period 4-10 July frames the phenomenon in a broader context, given that in the monitored week alone the body counted 130 malicious campaigns at a national level, almost three quarters of which (98) were specifically constructed to target Italian users and companies. On the front of the contrastCERT-AGID has already requested the registrar to decommission the identified malicious domain and has directly warned Trenitalia of the ongoing threat. In the meantime, the indicators of compromise have been distributed to the organizations accredited to the institution’s IoC flow, so as to speed up the blocking of campaign replies.

How to recognize the fake

Trenitalia never sends refund communications via SMS links that refer to domains other than its official website or company app. Compensation for delays, when due, can be requested exclusively through official channels, such as the trenitalia.com website, the FS app, or physical branches.

No institution ever requests a “verification fee” to provide a refund, a case which in itself already represents a clear indication of the scam in progress. Anyone who receives a suspicious message should avoid clicking, ignore the text and report it through the Postal Police portal (commissariatodips.it), which collects citizens’ reports and feeds ongoing investigations, or to CERT-AGID itself. The rule that always applies, and which is too often forgotten just when the message seems harmless: never open links contained in SMS, messages or emails before making sure that they lead to a verified official site.