
AI-generated summary
Phishing, smishing and vishing are forms of online scams that use electronic communications to deceive victims and obtain sensitive data. In recent months, variants have emerged using the names of public institutions such as the Revenue Agency and the Ministry of Health, as well as sophisticated attacks such as zero-click attacks on WhatsApp.
Phishing is an online scam that uses spoofed emails to steal personal data, credentials and financial information. The messages, apparently sent by banks, companies or well-known services, invite you to act urgently, for example to verify an operation or solve a problem. A link leads to a fake page, similar to the official one, where the victim can unknowingly enter username, password and security codes. Deception can also occur via infected attachments.
For further information: Dark web, 2.5 billion data exposed in 2026. Italy fourth in Europe for compromised emails
Smishing, from the union of "SMS" and "phishing", is a scam that uses text messages to steal personal data and credentials. The SMS, apparently sent from a bank, company or service provider, invites you to click on a link, verify a transaction or provide confidential information. To make it credible, the name of the institute can appear directly. The link leads to a fake page, through which criminals can obtain the data necessary to access the account.
For further information: Scams, how to avoid the most common scams: the handbook with advice from the Carabinieri
Vishing, from the union of “voice” and “phishing”, is a telephone scam with which criminals try to obtain personal data, credentials, security codes or money. The scammer presents himself as a bank or company operator and reports alleged problems, suspicious operations or anomalous accesses, inducing the victim to act quickly. The phone call can follow a fraudulent SMS or email: after clicking on a link, a fake operator contacts the victim to obtain the codes necessary to authorize operations.
Among the many scams that have emerged in recent months there was one that uses the name of the Revenue Agency to deceive taxpayers with the promise of an alleged Irpef refund. Victims receive seemingly official emails or text messages, containing a link that leads to a fake site, where they are asked for personal data, banking information and card numbers. In some cases, a verification using a code received on the phone is also simulated, with the aim of obtaining the credentials necessary to access the account.
In this regard, it should be remembered that the Agency never requests financial data via email or text message. For this reason, to defend yourself it is essential not to click on the links and always verify the sender and web address.
For further information: Revenue Agency, new scam with fake email about tax refund available
Another recent scam concerns WhatsApp: in recent weeks the popular messaging app has been at the center of "zero-click" attacks, which could compromise the account without the user clicking on links or carrying out any action. Criminals exploit vulnerabilities in outdated versions of iOS and WhatsApp to take control of the profile and contact the victim's friends and family, faking an emergency and asking for money.
Apple has already intervened to remedy these security flaws: to protect yourself it is always essential to always update the operating system and application; enable two-step verification and periodically check devices connected to WhatsApp.
For further information: WhatsApp, new wave of 'zero-click' attacks: advice from the Police to defend yourself
Another recent scam was the one that exploited the name of the Ministry of Health to defraud users with a false request to renew their health card. Phishing victims received emails or text messages containing a link that led to a fraudulent site, similar to an institutional one, where they were asked to fill out a form with personal data, sensitive data and payment information. This data can in fact be used by fraudsters for illicit activities, from reselling information to cloning documents.
To defend yourself, it is essential not to click on the links received or enter data on suspicious pages. As with the Tax Office, the Ministry also does not send communications with links to renew the health card.
For further information: Health card renewal scam, the notice from the Ministry of Health: how to defend yourself
A recent case also involved Revolut: hackers obtained the data of around 680 customers by exploiting a previously compromised Italian institutional email address. Posing as a police force, criminals sent seemingly legitimate requests for information to the British fintech as part of a supposed investigation. Because the messages appeared to come from a genuine government domain and passed technical authentication checks, Revolut treated them as mandatory requests from the authorities and provided the requested data. The stolen information included passport data, residential addresses, account numbers and details of customer transactions.
For further information: Revolut, hackers acted with a compromised Italian certified email: data of 680 customers exposed
Much more recent is the smishing scam which uses the name of Nexi to notify victims of a false payment of a large amount, inviting them to intervene immediately to block it. The seemingly official message contains a telephone number or link to use to contact support. Those who follow the instructions are instead put in contact with fake operators, who can ask for credentials, security codes or confirmations via home banking, thus managing to have the operations authorized directly.
The first precaution to take in these cases is not to call numbers or click on links in suspicious text messages. In fact, it is always preferable to check movements via the official app or the company's assistance channels.
The first rule for protecting yourself from scams is not to act under pressure. Banks and card companies do not ask for passwords, OTPs or other credentials via email, SMS or phone calls. In case of suspicious requests, it is therefore better to stop communication and contact the institute through the official contact details.
It is also important not to use links received in dubious messages: to access home banking it is preferable to type the address directly into the browser or use the official app. You should always check the sender, the web address, any errors in the text and the presence of https and the padlock. Operating system, applications and antivirus must be kept updated; It is advisable to use different passwords and enable two-factor authentication.
If you have communicated your credentials, you must change your passwords immediately, especially if you also use them on other services. In case of sharing bank or card data, you must immediately contact the bank via an official number and ask, if necessary, to block the payment instruments. You should not use the contact details provided by the alleged operators. If an unauthorized transaction has been carried out, it is important to promptly inform the bank and consider reporting it to the competent authorities.
For further information: Scams, here comes the guide that helps the elderly defend themselves
AI outlook — possibilities, not facts
Increase in scams that use artificial intelligence to create more convincing communications
Likely · Within months
Increased user adoption of two-factor authentication after awareness campaigns
Possible · Within weeks

Fire Emblem: Fortune's Weave announced for Nintendo Switch 2, a new strategic chapter of the saga in which players will have to travel to the past to change the fate of the world.

Anthropic has launched Claude Opus 5.5, a new AI model for developers that matches the flagship Fable model at a 20% lower price, offering support in programming and complex tasks autonomously.

In 2026, the electric car market sees a significant increase in declared range in the WLTP cycle, with some models exceeding 900 km. The Lucid Air Grand Touring leads the ranking with up to 960 km, followed by the Mercedes-Benz EQS 450+ (919 km) and the BMW iX3 50 xDrive (805 km). The article analyzes the strategies behind these results: large batteries versus aerodynamic and mechanical efficiency.

British Prime Minister Andy Burnham announced that the G20 will develop security standards for artificial intelligence during the British presidency in 2027, alongside a new AI defense partnership with the United States to protect critical infrastructure.

The Me against You site was suspended yesterday afternoon with a technical maintenance message, after the Consumerismo Non Profit association filed an appeal with the Court of Palermo against the company of creators Luigi Calagna and Sofia Scalia, accusing it of unfair practices in the online shop connected to the site and the app, which redirects to Amazon affiliate links without separation from the recreational content for children and pre-adolescents. The controversy follows the controversy over the paid wedding show organized by the same creators at the Unipol Dome in Milan, where tickets ranging from 48 to 110 euros and a 250 euro pass to meet the bride and groom were sold to an audience of paying children.

The Crif Observatory report reveals the exposure of 2.5 billion pieces of data on the dark web in the first half of 2026. Italy is among the most affected countries globally for stolen accounts, phishing and use of infostealer malware.