BLOG ARTICLE

Avviso ufficiale: tentativi di impersonificazione AI-driven a mio nome

Comunicazione di sicurezza pubblica — 28 maggio 2026.

Today I detected a campagna di impersonificazione condotta da soggetti ignoti mediante l’utilizzo di artificial intelligence agents, sending fraudulent emails to companies, professionals and business contacts apparently in my name, requesting payments, bank transfers, changes to IBAN details, or the sending of personal data.

Such communications do not come from me and are in no way authorized.

Disclaimer ufficiale time-stamped

The full formal disclaimer, with statutory references (Arts. 494, 640, 640-ter of the Italian Penal Code + GDPR Arts. 33-34), in a bilingual Italian/English version, is published and independently archived on the Internet Archive Wayback Machine at:

👉 https://mattiacalastri.com/impersonification-disclaimer.html

Canali ufficiali di comunicazione

The only authentic communications coming from me travel exclusively through:

Entrambi i domini ufficiali (mattiacalastri.com and digitalastra.it) are configured with DMARC reject strict + SPF hard fail + DKIM. It follows that it is tecnicamente impossibile to directly spoof senders on these domains to a modern email provider (Gmail, Microsoft 365, Outlook, Workspace). Any communication that imitates my name but comes from a different domain is fraudulent by definition.

What I never do

To make fraudulent emails easier to spot, I declare that I will never contact companies, clients or individuals with:

  • Richieste di bonifico urgente, anticipo, pagamento immediato o cambio coordinate IBAN
  • Richieste di credenziali, password, OTP o codici 2FA
  • Allegati eseguibili o link a portali di pagamento sconosciuti
  • Richieste di buoni regalo, gift card, criptovalute o ricariche
  • “Emergency” communications that demand payment or action within a few hours
  • Requests to transfer the personal data of clients or employees

How to verify the authenticity of a suspicious communication

  1. Do not click any link and do not open any attachment nell’email sospetta.
  2. Verify the actual sender in the email headers (fields Received-SPF, DKIM-Signature, Authentication-Results). If there are no PASS for the official domains, the email does not come from me.
  3. Contact me on an already-verified channel (WhatsApp, phone, direct email). Never reply to the suspicious email directly.
  4. Keep the full email with complete headers as evidence. Do not delete it.
  5. Segnala l’evento al Commissariato di P.S. Online (Polizia Postale).

Iniziative intraprese

  • Publication of the official disclaimer (this document).
  • Notifica diretta multicanale ai contatti professionali noti.
  • Full preservation of the technical evidence (files .eml with headers, logs, screenshots, look-alike URLs) for evidentiary purposes pursuant to art. 234-bis of the Italian Code of Criminal Procedure.
  • Filing of a criminal complaint with the Postal and Communications Police.
  • Notification to the Data Protection Authority pursuant to GDPR Arts. 33-34, where applicable.
  • Takedown procedure against any look-alike domains identified.

Transparency as a defense

I am making the incident public because transparency is the first line of defense against AI-driven impersonation. The more contacts know my authentic channels and my ways of communicating, the less effective any attempt at identity theft will be.

Thank you to anyone who wishes to report anomalies or suspicious attempts to me via one of the official channels listed above.

Mattia Calastri
Founder, Astra Digital Marketing

EXPLORE MY SERVICES

Digital solutions tailored to you.

I customize every digital solution to perfectly meet your needs. With my Full-Stack Marketing service, I position your brand online making it functional and operational in one week!

DIGITAL MARKETING Blog

SEO and AI Strategies for Business.

Discover the ultime tendenze and strategies of digital marketing, SEO and artificial intelligence. Practical tips to grow your business online.