If you receive a message on your email telling you to put your position in order within 48 hours by downloading an attachment and/or paying a certain sum of money in Bitcoin or some other cryptocurrency. All this to hide the visit that, according to the cyber criminals, you would have made to an unspecified «website you shouldn’t have»: it is with these textual words that the body of the crime that would have triggered the sanction against you is defined. In reality, behind these communications – apparently from the Ministry of the Interior – there is no real sanction, but it is just yet another phishing attempt orchestrated by a group of cybercriminals to steal data or money from less careful Internet users. To defend yourself, you must ignore the message and not interact with what it contains, whether it be links, attachments or instructions of some kind to follow.
How the scam works
The text simulates an official communication from the Ministry of the Interior or the Court of Rome, addressing the victim as «Connection holder» and citing the violation of a phantom Law 231/2025 (obviously non-existent). To consult the alleged report, the message invites you to open a link to a PDF file uploaded to Google Drive.
And this is where the trap set by the bad guys is triggered. The choice of Google Drive as a means to convey the hacking attempt is not accidental. Since it is a domain familiar to most people and which enjoys an excellent reputation, it manages to bypass anti-spam filters, which in fact do not block it, and above all it can reduce the prejudice of potential victims of the attack who, judging the address as safe, lower their guard.
But what happens if, gripped by the fear of having “done something”, you rush to download the attachments in the folder? It is very likely that in this way you will install an infostealer on your device, a spy software capable of automatically stealing passwords saved in the browser, banking data and cryptocurrency wallets. In other cases, you could come into contact with a carefully constructed web page, which could push the victim to provide personal data, such as identity card or credit card data, or SPID credentials, thus perpetrating real identity theft.
Interestingly, the scammers, pretending to be the authority appointed by the Ministry to find violators of the law in question, explicitly ask you to reply to the message using exclusively the “Reply” function and not by calling or going to a counter. Obviously, any public authority cannot prevent a free citizen from showing up in person, sending a registered letter, etc. And this represents a big wake-up call.
There are other signs that should make you suspicious. These include the lack of a specific reference to your person (no name and surname is indicated in the email, but it is an email sent to a generic person), the sender’s address comes from the Greek domain @sch.gr and not from a @giustizia.it or @gov.it type domain, as one would expect in these cases. And then, an offense like the one reported in the fake email in question cannot be delivered via ordinary email but, inevitably, requires sending via PEC (Certified Electronic Mail).
Cert-AgID, the IT emergency response center of the Agency for Digital Italy, has also identified an even more aggressive variant of the scam, based on sextortion: a form of digital extortion in which the victim is blackmailed with the threat of spreading alleged intimate or embarrassing content. In this version, the criminals claim to have infected the victim’s computer with malware and recorded their history on adult sites along with webcam footage, telling the potential victim to pay $2,000 in Bitcoin to remedy the situation.
What to do if you receive such a message
Now that it is clear what the scam consists of, you may already have understood how you should defend yourself. Ignoring the message, therefore not clicking on any links and not downloading any attachments. Point. You shouldn’t even reply to the email (for example to tell the scammers that you will report the incident), since the simple fact of replying would confirm to the bad guys that the mailbox is active and monitored, giving them the incentive to try new scams in the future, perhaps changing the nature of the messages with some topic that could catch you off guard.
What if you had already fallen into the trap and only discovered it now, reading this article? In this case, immediately do an antivirus scan to check that you have not installed malware, change the password of the accounts that may have been compromised due to the incident (e.g. that of your e-mail box, that of the SPID, etc.) and report the incident to the Postal Police.








