Online scams and phishing: how to recognize them

Recognize scam warning signs, verify official channels and act quickly if you have already clicked, shared information or paid.

Important information

Percorso Cittadino helps you understand Italian administrative procedures but does not replace public authorities. Before submitting applications or making decisions, always verify the official institutional links provided on this page.

This guide helps you recognize a possible scam, end the contact and protect money, accounts, digital identity and documents through official channels.

The correct actions depend on what has already happened. Urgently blocking an account, card, SIM or credentials comes before collecting evidence and reporting the incident.

Scam prevention at a glance

Reports and personal information
Percorso Cittadino does not receive reports, passwords, OTPs, documents or personal information.
Money involved
Contact the bank, card issuer or payment service provider immediately through an official channel.
SPID, CIE or IO
Secure the service through the relevant official support channel.
Verification
End the contact and independently open the website, app or authenticated area.
Emergency
For danger or immediate intervention, call 112 or 113; online forms are not emergency services.
Last review
Official sources reviewed on 29 July 2026.

Section 1

At a glance: what to do now

End the contact, protect what is at risk and verify only through channels you find independently.

Do not reply, call back or continue the conversation to prove that it is a scam. If money, a card or an account is involved, the first urgent contact is the bank, card issuer or payment service provider through an official channel.

If SPID, CIE or IO is involved, use official support to suspend, revoke or block access as appropriate for the service. For danger or immediate intervention, call 112 or 113.

  1. End the contact

    Do not use links, attachments, QR codes or telephone numbers in the suspicious message.

  2. Block the urgent risk

    Immediately protect the account, card, SIM, email or digital identity involved.

  3. Verify independently

    Open the app already installed or type the official website address yourself.

  4. Preserve and report

    After urgent blocking, preserve evidence and use the appropriate official channels.

Back to contents

Section 2

What happened?

Choose the closest situation: different events require different responses.

You only received a suspicious message

Do not interact. Check the matter independently in the official area and report the message where appropriate.

You opened a link but entered no information

Close the page, do not reopen it, and check downloads, alerts and permissions without assuming that opening it alone stole credentials.

You downloaded or installed something

Do not open the file; end any remote-control session and use another trusted device for sensitive actions.

You shared a password, OTP, PIN or card details

Secure your email and accounts, contact the service involved immediately and check transactions and sessions.

You approved a payment

Contact the bank or payment provider immediately and state accurately whether the transaction was unauthorized or made by you while deceived.

You sent documents, selfies or videos

List what you sent, report the incident and check for possible misuse of your identity and accounts.

Back to contents

Section 3

Stop and verify

The most reliable check starts through a different channel from the one used to contact you.

Urgency and fear reduce the time available to check. Ending a conversation does not make a genuine matter disappear; it allows you to verify it in the official area.

  1. End the communication

    Finish the call or chat without explaining which checks you will perform.

  2. Open the official channel

    Type the website, use a previously verified bookmark or open the installed app.

  3. Check the matter

    Sign in to the authenticated area and check messages, payments or requests.

  4. Contact the organization

    Use details found on the official website, in the app or on the back of the card.

Back to contents

Section 4

Signs of a possible scam

No single sign proves everything, but several signs together require independent verification.

Stop in particular when a communication contains one or more of these elements:

  • Urgency, threats of blocking, penalties or immediate consequences.
  • An unexpected refund, prize, benefit or opportunity.
  • A request for passwords, OTPs, PINs, documents, selfies, banking information or payment.
  • An unexpected link, attachment or QR code.
  • A displayed telephone number, sender, logo or visual design offered as the only proof of authenticity.
  • A request to install an app or grant remote control.
  • An instruction to move money to a supposed safe account.
Back to contents

Section 5

Channels and techniques

Knowing the names helps identify the technique, but the response remains the same: stop and verify independently.

Phishing
Impersonated emails or pages designed to obtain information, credentials or payments.
Smishing
Phishing through text messages or other short messages, often using links and urgency.
Vishing
A fraudulent telephone call using pressure, apparent authority or personal information.
Quishing
A QR code leading to an unverified website or process.
Spoofing
Falsification of caller ID, sender details or the appearance of a service.

Remote control

A false operator asks you to install software so they can view or control the device and guide payments or logins.

Safe account

A scammer claims that money must be moved to another account for protection. End the contact and call the bank through an official channel.

Back to contents

Section 6

Verify the sender, website and app

Reconstruct the official path without using anything supplied in the suspicious communication.

  1. Do not call the received number

    Find the contact on the official website or on the back of your card.

  2. Do not open the link

    Type the domain yourself or use a previously verified bookmark.

  3. Open the app already installed

    Do not install an app suggested by the message or caller.

  4. Check the authenticated area

    Confirm whether the case, notice, notification or transaction actually exists.

  5. Read the complete domain

    The organization’s name appearing somewhere in the address does not prove ownership.

  6. Verify the request

    If you did not start the login, payment or approval, reject it and contact the service.

Sender

Displayed names, telephone numbers and addresses can be falsified or made to resemble official ones.

Website

Check the domain and path; small errors, misleading subdomains and added words matter.

App

Use only an app installed from an official store and opened by you, not from a received link.

Back to contents

Section 7

Messages claiming to be from public authorities

Do not apply absolute rules to every public authority; check the specific organization being impersonated.

A message may contain real personal information, a genuine case reference or correct logos and still be fraudulent.

Do not use links, attachments or telephone numbers from the suspicious communication. Open the authenticated area independently and read the organization’s security alerts.

INPS

INPS does not send text messages or emails with links for obtaining refunds, request documents by email or telephone, or ask for banking information by email or text message. Check MyINPS independently.

Italian Revenue Agency

Check its phishing focus page and open the authenticated area independently. The Agency can legitimately use email, certified email, text messages or telephone calls, so avoid the false claim that it never contacts users.

Back to contents

Section 8

pagoPA, IO and SEND

These services can generate genuine communications; verify them by opening the official channel directly.

pagoPA does not directly email payment requests, but genuine email receipts can be sent after a payment. It is therefore incorrect to say that every email mentioning pagoPA is fraudulent.

IO and SEND can send notifications or courtesy alerts. Treat the message as an alert and verify in the app or website opened independently.

pagoPA

It does not ask for passwords, banking details or card numbers by email or text message. Card details may be requested in an official checkout you started; the direct checkout host is checkout.pagopa.it.

IO

It can send push notifications and email previews. Open the app directly and check the Messages section.

SEND

It can send courtesy alerts by email, text message or IO. Type notifichedigitali.it yourself, sign in with SPID or CIE and check the notification.

  1. Verify the debt

    Check the notice and amount on the creditor authority’s official website or through IO.

  2. Verify the SEND notification

    Sign in at notifichedigitali.it without using the link in the message.

  3. Ask the correct organization for support

    Use service support for technical issues; contact the sending authority about the content of the act.

Back to contents

Section 9

SPID, CIE and digital identity

Distinguish the SPID provider, CIE credentials, physical card and IO access: these are different issues.

SPID and CIE can legitimately request a password or OTP during an official process that you started. The warning sign is a request from someone contacting you or an approval for a login that you did not initiate.

SPID

Contact your Identity Provider immediately and follow its suspension or revocation procedure. Use the current SPID support page rather than telephone numbers copied into this guide.

CIE

Distinguish compromised credentials from theft of the physical card. Use official CIE support without inventing procedures.

IO

For digital identity theft or a lost device, follow official IO support and block access through account.ioapp.it where instructed.

  1. Block the affected access

    Act through the official channel of the provider or service involved.

  2. Change linked credentials

    Secure the email account first, then reused or similar passwords.

  3. Check access and cases

    Review sessions, devices, communications and unrecognized activity.

  4. Report identity theft

    If you suspect a SPID identity was created without consent, contact the Identity Providers and report the facts to the authorities.

Back to contents

Section 10

Banks, cards and bank transfers

The distinction between an unauthorized transaction and a payment made while deceived is essential.

Contact the bank, card issuer or payment service provider immediately using its app, the number on the back of the card or the official website. Block the payment instrument where instructed.

Describe accurately what happened: who initiated the transaction, which codes were used and whether you were deceived by a false operator.

Two situations that must not be confused
SituationFirst actionOutcome
Unauthorized transactionBlock the payment instrument and dispute the transaction under the intermediary’s procedure.The assessment and any refund depend on the facts and applicable rules.
Payment or bank transfer made personally while deceivedAsk immediately whether blocking, cancellation, recall or recovery is still possible.Recovery is not guaranteed and may depend on the status of the transaction.
Back to contents

Section 11

If you clicked, downloaded or allowed remote access

Reduce the device’s exposure without reopening the suspicious content.

Opening a link alone does not necessarily mean that credentials were stolen. The risk increases if you opened files, installed software, granted permissions or entered information.

  1. Close the page

    Do not reopen it to check and do not continue the conversation.

  2. Do not open files

    Leave suspicious attachments and downloads closed.

  3. End remote control

    Disconnect the session and, where necessary, the device’s network connection.

  4. Use another trusted device

    Use it to contact the bank and services and change sensitive credentials.

  5. Check apps, extensions and downloads

    Remove only items that you recognize as having been installed during the suspicious event.

  6. Check permissions

    Review accessibility, device administration, screen sharing and installed profiles.

  7. Update and scan

    Update the operating system and browser and run a scan using trusted tools.

  8. Obtain technical support

    If doubts remain, use trusted support without giving new access to unknown people.

Back to contents

Section 12

Credentials and security codes

Passwords, OTPs and codes have different functions, but every disclosure requires a rapid response.

Secure the email account first, because it can often be used to reset passwords for other accounts.

Password
It may allow repeated access until it is changed and existing sessions are revoked.
OTP
It is temporary but may already have approved a login, change or payment.
PIN and PUK
They protect specific instruments or devices and should be used only in official channels.
MFA and passkeys
They reduce risk, but an approval request you did not start must always be rejected.
  1. Secure the email account

    Change its password and check recent sessions, devices and logins.

  2. Change compromised passwords

    Also update identical or very similar passwords used on other services.

  3. Revoke sessions and devices

    Sign out unknown access and regenerate codes where the service provides this option.

  4. Check recovery settings

    Review the email address, telephone number and other account-recovery details.

  5. Check forwarding and authorized apps

    Remove filters, rules and applications that you do not recognize.

  6. Enable MFA or a passkey

    Use the methods offered by the service after regaining control of the account.

Back to contents

Section 13

If you paid or approved a transaction

Act immediately and explain accurately to the intermediary how the transaction was initiated.

Timing and blocking options depend on the payment instrument and transaction status. Do not wait for a police report before contacting the bank or payment provider.

  1. Contact the intermediary

    Use its app, official website or the number on the back of the card.

  2. Block the payment instrument

    Follow the instructions for the card, account or payment credentials.

  3. Request the correct procedure

    Dispute unauthorized transactions; ask about blocking or recovery for payments made while deceived.

  4. Provide facts and identifiers

    Give the amount, date, beneficiary, receipt, codes and method used by the scammer.

  5. Submit a complaint where necessary

    If the response is unsatisfactory, first use the intermediary’s official complaints procedure.

  6. Consider the next official channels

    After the complaint, check the official requirements for the ABF and a complaint to the Bank of Italy.

Back to contents

Section 14

Documents, selfies and personal information

Reconstruct what you sent and check possible misuse without making false declarations.

Documents, selfies, videos and personal information may be used in attempted identity theft, account opening, or changes to contact and payment details.

  1. Make an inventory

    List the documents, images, videos and information disclosed.

  2. Report the facts

    Contact the authorities promptly and describe what was sent.

  3. Check SPID

    Contact the Identity Providers if you suspect a SPID identity was created without consent.

  4. Check benefits and IBAN details

    Review accounts or payment details connected to public benefits and sensitive services.

  5. Check the SIM

    If the telephone unexpectedly loses network service, contact the mobile operator from another telephone.

  6. Alert sensitive services

    Inform the bank and important accounts if you suspect SIM replacement or identity theft.

Back to contents

Section 15

Preserve evidence

Collect useful information without reopening links or delaying urgent blocking.

Keep readable copies and record the order of events. If evidence is available only by reopening dangerous content, do not reopen it.

  • The original message or email.
  • Sender, telephone number, username, date and time.
  • The URL copied without reopening it.
  • Screenshots and chat history.
  • Call history.
  • IBAN, beneficiary, receipts and transaction identifiers.
  • Name of the remote-control app and permissions granted.
  • List of files, documents, selfies or videos sent.
  • Alerts about logins, account changes or SIM replacement.
  • Case numbers and times of contacts with the bank, provider and authorities.
Back to contents

Section 16

Reporting, PRE-DENUNCIA and filing a police report

These are different tools: use the appropriate channel and do not treat an online alert as an automatic substitute for a formal procedure.

An online report alerts the Italian Postal Police or the organization being impersonated, but it does not replace a formal complaint or querela.

Since 15 June 2026, Denunce Online has experimentally allowed users, in supported cases, to start a PRE-DENUNCIA, or pre-report, for scams and computer fraud.

Online report
An informational alert to the Italian Postal Police or the organization being impersonated; it does not replace a formal procedure.
PRE-DENUNCIA
A pre-report started through Denunce Online that must be formalized in person under the portal’s instructions.
Denuncia or querela
The classification depends on the case and is for the authorities to determine; this guide does not provide personalized legal advice.
  1. Open the portal independently

    Type denunceonline.poliziadistato.it and select the supported case.

  2. Complete the PRE-DENUNCIA

    Enter the required information only in the official procedure.

  3. Choose an enabled office

    Use the current options offered by the portal rather than copied lists.

  4. Formalize it within 48 hours

    Attend in person following the appointment and portal instructions.

Back to contents

Section 17

Related guides

Read about the service involved through the routes already published by Percorso Cittadino.

Back to contents

Section 18

Frequently asked questions

Quick answers to common questions after a suspicious message or transaction.

How can I tell whether a message is genuine?

Do not rely on the displayed sender, telephone number, logo or visual design. End the contact, open the official website or app independently and check the matter in the authenticated area; if you need support, use contact details found on the official website, in the app or on the back of your card.

I only opened a link. What should I do?

Close the page and do not reopen it to check. If you did not enter information, download a file or grant permissions, opening the link alone does not necessarily mean that credentials were stolen; still check downloads, apps, extensions and security alerts.

I shared a password or an OTP. Is the risk the same?

No. A password may allow repeated access until it is changed; an OTP is temporary but may already have approved a login or transaction. Secure your email and accounts immediately, revoke unknown sessions and contact the service involved.

Will the bank always refund money lost to a scam?

No. The assessment depends on the facts and the applicable rules. Contact the bank or card issuer immediately, distinguish an unauthorized transaction from a payment you made while deceived, and follow the dispute or recovery procedure without assuming the outcome.

Is an online report the same as filing a police report?

No. An online report alerts the Italian Postal Police or the organization being impersonated, but it does not replace a formal complaint or querela when one is required. The competent authorities determine which procedure is appropriate in the individual case.

Can I complete a scam report entirely online?

Not through the current experimental Denunce Online procedure. For scams and computer fraud, the portal creates a PRE-DENUNCIA, or pre-report, which must be formalized in person within 48 hours at an enabled office offered by the portal.

What should I do if SPID, CIE or IO is involved?

For SPID, contact your Identity Provider immediately; for CIE, use official support and distinguish compromised credentials from theft of the physical card; for IO, follow official support to block access, including through account.ioapp.it where instructed.

Can pagoPA, IO and SEND send genuine communications?

Yes. Genuine pagoPA receipts, IO push notifications or email previews, and SEND courtesy alerts can exist. Do not use links or contact details from a suspicious message: open the app, the authority’s website or notifichedigitali.it directly and verify there.

What evidence should I keep?

Keep the original message, sender, date and time, the URL without reopening it, screenshots, chats, call records, receipts, transaction identifiers, installed apps, documents sent and case numbers. Do not delay urgently blocking an account, card, SIM or credentials in order to collect evidence.

Can I send the message or my documents to Percorso Cittadino?

No. Percorso Cittadino does not receive reports, passwords, OTPs, documents, screenshots or personal information. Use only the official channels of the competent authority, public body, bank or provider.

Back to contents

Section 19

Official sources

Institutional pages used to verify procedures, precautions and operational channels.

The sources were reviewed on 29 July 2026. Procedures, enabled offices, contact details and digital functions can change, so always reopen the current official page.

For an individual situation, follow the instructions of the competent authority, bank, provider or public body. Percorso Cittadino provides general information only. Some linked institutional pages are available only in Italian.

Back to contents