Suspicious
Phishings targeting Intesa San Paolo
Suspicious and active websites
Phishings targeting Intesa
Suspicious and active websites
Historical record. phishunt is not tracking any active Intesa San Paolo phishing site right now; the 15 entries below are from the 365-day archive (sites taken down, cleaned up, or otherwise inactive). Use them for retrospective analysis, not as a current threat-feed signal.
| First seen | URL | IP | Cert | Detail |
|---|---|---|---|---|
| 2026-07-28 | http://intesa.banca-rs.com |
45.74.61.10 | - | View → |
| 2026-07-26 | https://servizio-intesasanpaolo.com |
27.254.134.22 | - | View → |
| 2026-07-07 | http://intesassanpaolo.dash-area-clienti.com |
188.114.97.3 | - | View → |
| 2026-04-29 | https://intesasanpaolo-proteggi-la-mia-carta.netlify.app |
35.157.26.135 | DigiCert Global G2 TL… | View → |
| 2026-03-27 | https://areaclienti-intesassanpaolo.auth-login-dashboard.com/8ppkev7j… |
188.114.97.3 | WE1 | View → |
| 2026-03-27 | https://areaclienti-intesassanpaolo.auth-login-dashboard.com/8ppkev7j… |
188.114.97.3 | WE1 | View → |
| 2026-03-16 | https://intesassanpaolo.area-client-id7526700.com |
172.67.219.138 | WE1 | View → |
| 2025-11-12 | https://cintesa.com |
76.223.105.230 | Go Daddy Secure Certi… | View → |
| 2025-11-02 | https://teak.intela.dev |
5.161.106.156 | - | View → |
| 2025-11-01 | https://intesa-trevia-8.com |
188.114.97.3 | WE1 | View → |
| 2025-10-30 | https://intesa-pluvo-7.com |
172.67.186.91 | WE1 | View → |
| 2025-10-17 | https://nbhgfdtr.justns.ru/s/intesadima/iy/fr/conto/ |
46.17.40.77 | - | View → |
| 2025-10-17 | https://ww9.intepsa.com |
208.91.196.152 | - | View → |
| 2025-10-12 | https://intesa-dumb.com |
193.105.134.76 | R13 | View → |
| 2025-09-20 | https://studio--intesa-sanpaolo-onmwz.us-central1.hosted.app |
- | - | View → |
AIHow to verify a real Intesa San Paolo URL
- Legitimate Intesa San Paolo URLs always end in
intesasanpaolo.com(e.g.www.intesasanpaolo.com,account.intesasanpaolo.com). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like.xyz/.top/.vip— is not Intesa San Paolo. - The padlock icon proves TLS is active, not that the site is safe. Free DV certificates are issued to attackers in minutes; every active site listed above has a valid TLS certificate.
- If you got the link from email, SMS, or social media, do not click it. Open
intesasanpaolo.comfrom your browser bookmark or type the domain manually. - Real Intesa San Paolo pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.