Threat feed liveUpdated — 06.08.2026 10:36 CET100 dossiersMITRE ATT&CK mappingThreat feed liveUpdated — 06.08.2026 10:36 CET100 dossiersMITRE ATT&CK mapping

Unattributed. None of the official sources names a group or originhigh

The refund that takes your money: the Trenitalia-themed smishing campaign

On 23 July 2026 CSIRT Italia published alert AL01/260723 on a smishing campaign abusing the Trenitalia brand. The message promises compensation for a delay and leads to a chain of pages that ask, one piece at a time, for a phone number, full payment card details, a charge described as a «verification fee», and finally the one-time code received by SMS. That last step is the one that matters: the one-time code does not confirm the victim, it validates the transaction being run by the other side. The campaign had already been flagged by the Italian Postal Police on 8 July and detected by CERT-AGID in the first ten days of the month.

The hook is a real thing

The message says your train arrived late and that you are entitled to compensation.

It works for a simple reason: it is plausible. Trains do run late, the right to compensation genuinely exists, and in July a very large number of people in Italy took a train. Whoever receives the text does not need to be naive to bite: they only need to have travelled recently and not quite remember whether they already claimed that refund.

CSIRT Italia describes it this way in alert AL01/260723: «This CSIRT has recently detected a Trenitalia-themed smishing campaign, carried out via SMS, aimed at harvesting the potential victim's payment card details».

Smishing is simply phishing delivered by SMS. The channel changes quite a lot: a text message has no verifiable sender, does not pass through a corporate filter, and arrives on a personal phone — where links are opened with a thumb, while walking.

The chain, step by step

The most instructive thing about this campaign is how gradual it is. There is no single form asking for everything: there is a ladder of requests, each one small relative to the last.

  1. 01
    The phone number
    «Check your compensation» — a detail people give without thinking
  2. 02
    The card details
    a «Transfer to card» page: needed in order to receive the refund
  3. 03
    The one-time code
    the final step, the one that actually authorises something

It starts with a landing page carrying Trenitalia logos and a Check your compensation button, which asks for a phone number. Then a screen appears showing a fictitious credit, and a second button: Claim your compensation. Next comes a page titled Transfer to card, where full payment card details are requested.

Here comes the detail CSIRT reports verbatim, and it is worth re-reading: the victim is asked for «a small amount, described as a "verification fee", supposedly covering non-existent banking and processing costs, as well as confirming that the card is valid».

A small sum to be paid in order to receive a larger refund. It is the same structure as scams promising to recover money already lost: the victim is not buying anything, they are paying the fee on a transaction that, in their mind, is already in their favour.

The last step is the decisive one. CSIRT again: «Finally, the victim is directed to a last page requesting the one-time code received by SMS». A message then reports that verification has expired by timeout — which explains why no refund ever arrives, and gets the page closed without immediate suspicion.

Why the one-time code is the breaking point

It is worth being precise, because it is the only step where the victim actively authorises something.

Card details on their own are rarely enough today: European online payments require a second factor, and that factor is exactly the code the bank sends by SMS. The code does not confirm the identity of whoever types it into a page: it confirms the specific transaction the bank is asking to authorise at that moment.

If that transaction was started by someone else using the details just stolen, the code you are entering authorises their payment. The bank's message usually says so, amount included. It is the line nobody reads, because they are looking at the number.

Hence the practical rule, which extends well beyond this case: a one-time code is to be read, not copied. If the text of the message does not describe the transaction you are making, that code does not go anywhere.

The published indicators

CSIRT Italia publishes four indicators of compromise: the domains trenitalia.ink and trenitaly.cloud, plus the two corresponding URLs. These names imitate the brand using two classic techniques: an unusual extension in place of the expected one, and a single changed letter.

Neither technique requires skill: they require that whoever looks at the address stops at the part they recognise. On a phone screen, where the address bar is short and often partly hidden, that is exactly what happens.

The context, without inflating it

The campaign did not begin on 23 July. CERT-AGID, the incident response team of the Italian Digital Agency, detected it as early as the week of 4-10 July 2026, writing that «the attackers' objective is to obtain users' phone numbers and credit card details». On 8 July the Postal Police published a dedicated notice, opening with the observation that «many readers are reporting» the message. On 23 July the formal CSIRT alert arrived, with the indicators. The entry was then picked up in the Cyber Week bulletin published by ACN on 26 July.

To give a sense of the volume this campaign sits within — and it should be read for what it is, namely general context and not a measure of this specific campaign — CERT-AGID's weekly summaries report 130 malicious campaigns in the week of 4-10 July (98 with Italian targets) and 140 in the week of 25-31 July (94 with Italian targets), with 1,560 indicators distributed in the latter.

4
indicators published
two domains and two URLs, in alert AL01/260723
1
the detail that breaks the chain
the one-time code: without it, card details are not enough
0
victims quantified
no official source publishes figures or losses

What to do

Do not follow the link in the text. If you think you are owed compensation, open the operator's app or website yourself and look for it there. A real refund does not expire in ten minutes.

No legitimate refund is paid for in advance. The «verification fee» is the strongest signal in the whole chain, and it is the one you can spot without knowing anything about computers: someone who owes you money does not ask for yours first.

Read the text of the message containing the code. Not just the number: the bank states what you are authorising and for how much. If it does not match, the code does not get entered.

If you entered your details, call your bank now and block the card. Then keep the text messages you received: they establish the timing of the transactions. Reports go to the Postal Police, which states flatly that you should «never share banking details in reply to messages received by SMS or email».

What we do not know

None of the official sources quantifies victims or financial losses, and none names an actor or origin: the campaign remains unattributed. No official statement from Trenitalia or the FS group on this matter surfaced during this check — the brand is the injured party in the abuse, not the source of this information. Finally, the published indicators are a snapshot taken on 23 July: in campaigns of this kind domains are replaced quickly, and the absence of an address from the list is not proof that a message is genuine.

More dossiers