{"id":426207,"date":"2026-10-10T13:38:52","date_gmt":"2026-10-10T13:38:52","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=426207"},"modified":"2026-10-10T13:38:52","modified_gmt":"2026-10-10T13:38:52","slug":"bonus-vacanze-tax-agency-document-upload-scam","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/bonus-vacanze-tax-agency-document-upload-scam\/","title":{"rendered":"Bonus Vacanze Scam: Fake Tax Agency Pages Collect IDs, Payslips and Selfies"},"content":{"rendered":"<p>A holiday bonus appears on a website dressed like Italy&#8217;s tax agency. Familiar service links and recognizable login choices make the offer look surprisingly ordinary.<\/p><div id=\"mwtad463101510\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Then one option takes the process in a different direction. The Bonus Vacanze scam deserves a closer look before you prepare any paperwork.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1280\" height=\"900\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/bonus-vacanze-tax-agency-document-upload-scam-capture.png\" alt=\"Captured fake Bonus Vacanze eligibility page requesting identity card, health card and payslip uploads\" class=\"wp-image-426208\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/bonus-vacanze-tax-agency-document-upload-scam-capture.png 1280w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/bonus-vacanze-tax-agency-document-upload-scam-capture-300x211.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/bonus-vacanze-tax-agency-document-upload-scam-capture-1024x720.png 1024w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><\/figure>\n<div id=\"mwtad1666502473\" class=\"gas_fallback-ad_309746-ad_309685-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>The holiday-bonus page is collecting an identity package<\/h3>\n<p>This is a confirmed phishing campaign impersonating Agenzia delle Entrate and Agenzia delle entrate-Riscossione. The false holiday-bonus application leads people into providing sensitive documents.<\/p><div id=\"mwtad2907989659\" class=\"gas_fallback-ad_381396-ad_309685-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p><a href=\"https:\/\/cert-agid.gov.it\/news\/falso-bonus-vacanze-dellagenzia-delle-entrate-ruba-dati-personali\/\" target=\"_blank\" rel=\"noopener\">CERT-AGID&#8217;s September 16, 2026 investigation<\/a> documents the deceptive portal and the manual document-upload route behind its offer.<\/p>\n<p>We independently captured the document page on October 10. The image above shows the live form, including separate identity-card, health-card, and payslip upload areas.<\/p>\n<p>No documents were submitted for this investigation. A visible form establishes what the page asks for, not whether a particular victim&#8217;s files were retained or misused.<\/p><div id=\"mwtad2637075115\" class=\"gas_fallback-ad_309686-ad_309685-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The legitimate agencies are being impersonated. Their names and designs are used to create confidence in a site outside their authentic service.<\/p>\n<h3>Real links help make the false portal convincing<\/h3>\n<p>CERT found genuine institutional links mixed into the fake website. This lets someone click around and encounter real official material while remaining inside a deceptive journey.<\/p>\n<p>The reported SPID and CieID options can redirect to authentic identity-provider or government authentication pages. Their presence does not authenticate the separate document-upload option.<\/p><div id=\"mwtad4059582435\" class=\"gas_fallback-ad_381401-ad_309685-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>That distinction is the campaign&#8217;s important trick. A real destination reached from one button cannot certify every other button on the page that sent you there.<\/p>\n<p>The malicious branch is presented as another way to access the service. It asks for records that can support identity misuse rather than simply confirming a holiday discount.<\/p>\n<div id=\"mwtad3989063860\" class=\"gas_fallback-ad_381404-ad_309685-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>The evidence does not establish that the authentic identity providers stole passwords. It establishes a deceptive portal using genuine routes to make its own collection process believable.<\/p>\n<h3>Stop before submitting documents through the alternate route<\/h3>\n<ul>\n<li>A working official link does not prove the surrounding website belongs to the tax agency.<\/li>\n<li>The option labeled Altro leads into a manual document process in the reported campaign.<\/li>\n<li>The captured page requests front and back images of identity and health cards, plus a payslip.<\/li>\n<li>CERT also documents later selfie and contact-information requests; we did not test those stages with personal data.<\/li>\n<li>If records were uploaded, treat the situation as document exposure even when no money changed hands.<\/li>\n<\/ul>\n<p>Verify any benefit through the agency&#8217;s official route before preparing files. The page offering the benefit should not be your only evidence that it exists.<\/p>\n<div id=\"mwtad1344321906\" class=\"gas_fallback-ad_309747-ad_309685-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What the Captured Upload Page Actually Shows<\/h2>\n<p>The form is headed Verifica idoneit\u00e0, an eligibility check. Below it, instructions tell the visitor to upload documents to access the service.<\/p>\n<p>Two card sections sit beside each other. Each separates front and back, making the request look organized and more precise than a generic contact form.<\/p>\n<p>The identity-card section is labeled Carta d&#8217;identit\u00e0. The health-card section uses Tessera sanitaria. Both can expose identifying information from documents people normally keep private.<\/p>\n<p>A lower Busta paga area requests a payslip issued within the last three months. The bottom of the panel contains a prominent Continua button.<\/p>\n<p>These details matter because the form normalizes a collection of unrelated records as one administrative check. Completing it means assembling a useful package for the recipient.<\/p>\n<p>The official-looking header does not explain who receives those files. A logo can be copied without giving its original owner control of the copied website.<\/p>\n<p>You should also notice what is missing from this observation. We did not verify file processing, upload validation, or any action performed after real records arrive.<\/p>\n<p>There is no basis here to claim an AI system checked the documents. The scam is established by the deceptive identity and collection path without that additional allegation.<\/p>\n<div id=\"mwtad1711352773\" class=\"gas_fallback-ad_309748-ad_309685-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the Bonus Vacanze Scam Works<\/h2>\n<h3>Step 1: A familiar benefit name brings the reader to a copied agency site<\/h3>\n<p>The campaign uses a holiday-bonus application as its pretext. People encounter an apparent tax-agency service, rather than a stranger openly asking for private documents.<\/p>\n<p>A benefit application gives the paperwork a purpose. The reader is encouraged to think about qualifying for support, so the document request can seem less unusual.<\/p>\n<p>Before considering eligibility, verify the offer itself. An agency name in an email or page heading is only part of what the sender wants you to believe.<\/p>\n<p>Use current information reached through the agency&#8217;s own website. Searching for the benefit name alone may also surface older material that does not authenticate a new application.<\/p>\n<h3>Step 2: Genuine links make casual checking seem successful<\/h3>\n<p>A visitor may try a few navigation items to see whether the website works. If those items lead to official pages, the copied site can appear reassuring.<\/p>\n<p>That check is incomplete. It confirms only the destination of the selected link, not the ownership of the page containing it.<\/p>\n<p>Imagine an unrelated website linking to a real government guide. The guide stays genuine, but the linking website does not become an authorized application service.<\/p>\n<p>The same principle applies here. Track where you are at the moment information is requested, particularly when moving between pages or returning after another login.<\/p>\n<h3>Step 3: Familiar login choices make the alternate option seem acceptable<\/h3>\n<p>The reported page displays SPID and CieID alongside Altro. A person without the preferred login method may see the third option as a convenient fallback.<\/p>\n<p>A page can exploit that practical need. Someone wanting to finish the application may appreciate any route that avoids resolving a genuine authentication difficulty.<\/p>\n<p>Do not treat a workaround as authorized merely because it sits beside recognizable sign-in buttons. Verify whether the genuine agency offers that method for that service.<\/p>\n<p>If an official sign-in worked on another branch, assess that session separately. Do not assume it approves a different website&#8217;s request for document photographs.<\/p>\n<h3>Step 4: Eligibility becomes a series of document requests<\/h3>\n<p>The alternate path gathers records under an apparent qualification check. A sequence of screens can make each additional item feel like another normal requirement.<\/p>\n<p>The captured form already asks for multiple records. CERT&#8217;s investigation documents further selfie, phone-number, and email collection in later stages.<\/p>\n<p>Stop if the process asks for more than you can justify through the authentic service. Having completed earlier fields is not a reason to surrender the remaining ones.<\/p>\n<p>An uploaded identity card should not be followed by a selfie simply because the site says the application is almost finished. Extra information can increase the exposure.<\/p>\n<h3>Step 5: The application leaves the attacker with reusable records<\/h3>\n<p>Document disclosure can matter even without a card payment. The information may be useful for impersonation attempts or fraudulent applications made elsewhere.<\/p>\n<p>CERT identifies financing and loan fraud as potential consequences. That is a risk assessment, not proof that every set of uploaded records has produced a loan.<\/p>\n<p>The immediate task is to identify which files left your control. Do not wait for a suspicious bill before taking the disclosure seriously.<\/p>\n<p>Nor should you assume deleting the browser history removes those files. Local cleanup and protecting against misuse of submitted documents solve different problems.<\/p>\n<div id=\"mwtad1931213715\" class=\"gas_fallback-ad_318930-ad_309685-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>The Real Historical Bonus Does Not Authenticate a New Offer<\/h2>\n<p>Bonus Vacanze is a recognizable name because Italy previously had a genuine holiday-benefit program. Criminals can reuse that recognition in a false contemporary application.<\/p>\n<p>The agency&#8217;s <a href=\"https:\/\/www1.agenziaentrate.gov.it\/web_app_entrate\/bonus_vacanze.html\" target=\"_blank\" rel=\"noopener\">historical guide<\/a> describes applications made in 2020 and use through the end of 2021, with the application handled through IO.<\/p>\n<p>An older genuine guide is therefore context, not authorization for the website described here. Its existence does not establish that this document-collection process is legitimate.<\/p>\n<p>When checking any new benefit claim, find the actual current announcement, eligibility rules, and application route through the responsible institution.<\/p>\n<p>Check the date as carefully as the title. Search results can place material from different years near one another without explaining which offer you are investigating.<\/p>\n<p>If someone shares an old official page as proof, ask whether it describes the present request. A real historical program and a false current application can coexist.<\/p>\n<p>This article does not determine your eligibility for any current public support. It identifies a documented counterfeit collection route that should not receive your documents.<\/p>\n<h2>The Domain Check to Make Before Any Upload<\/h2>\n<p>CERT&#8217;s <a href=\"https:\/\/cert-agid.gov.it\/wp-content\/uploads\/2026\/09\/phishing_AdE_bonusvacanze.json\" target=\"_blank\" rel=\"noopener\">published campaign indicators<\/a> identify agenziaentrate-gov[.]com and bonusvacanze-entipublici[.]com. The copied institution words are part of the disguise.<\/p>\n<p>The captured upload page was on agenziaentrate-gov[.]com\/pages\/caricamento-documenti. This is a specific observed address, not a claim that every related scam uses it.<\/p>\n<p>Do not click a suspected address to investigate your exposure. Preserve it from the message or existing screenshot and use it when reporting.<\/p>\n<p>A certificate or padlock concerns the connection to that domain. It does not establish that the tax agency operates the site or approved the form.<\/p>\n<p>The full address matters at the upload stage, even if an earlier screen was genuine. Recheck after navigation instead of carrying trust forward from another tab.<\/p>\n<p>If the page becomes unavailable, keep the incident record. Disappearance is not proof that your data was deleted, nor a reason to assume every similar domain is fraudulent.<\/p>\n<h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li>\n<p><strong>List every record you uploaded.<\/strong> Include document type, front or back, payslip period, selfie, and any contact details supplied.<\/p>\n<p>Keep a private copy of this list. It helps distinguish the actual exposure from later requests that you saw but did not complete.<\/p>\n<\/li>\n<li>\n<p><strong>Preserve the message and website address.<\/strong> Note the date, route into the form, and any confirmations or errors displayed after submission.<\/p>\n<p>Do not reopen the site to produce better evidence. Use records already available and avoid sending the same files again.<\/p>\n<\/li>\n<li>\n<p><strong>Report the document theft or suspected misuse.<\/strong> Explain that records were supplied to a website impersonating the tax agency.<\/p>\n<p>Ask the appropriate Italian reporting authority what documentation it needs. Keep the report reference and follow its guidance concerning exposed identity documents.<\/p>\n<p>Do not promise yourself that a report automatically cancels every possible misuse. Its value includes establishing the timeline and supporting further protective action.<\/p>\n<\/li>\n<li>\n<p><strong>Contact the relevant document issuer when advised.<\/strong> Explain which document was exposed and ask whether reporting, replacement, or another measure is appropriate.<\/p>\n<p>A copied document creates a different issue from a missing physical card. Describe both accurately rather than assuming the procedures are identical.<\/p>\n<\/li>\n<li>\n<p><strong>Monitor financial and identity-related correspondence.<\/strong> Treat unfamiliar applications, credit communications, or account changes as matters requiring verification with the real organization.<\/p>\n<p>If a bank or lender contacts you about an application you did not make, use independently obtained contact details and provide your incident reference.<\/p>\n<\/li>\n<li>\n<p><strong>Protect credentials only where they were actually exposed.<\/strong> If a password was entered into a counterfeit page, change it through the genuine service.<\/p>\n<p>If your only authentication occurred on a verified provider&#8217;s page, do not automatically describe it as stolen. Ask the provider about any unexplained activity.<\/p>\n<\/li>\n<li>\n<p><strong>Investigate files or software downloaded during the visit.<\/strong> A Malwarebytes scan can help when there is an unwanted installation or suspicious device behavior.<\/p>\n<p>AdGuard can reduce some future exposure to malicious advertising and risky destinations. Neither tool removes documents already held by a recipient or prevents every impersonation attempt.<\/p>\n<\/li>\n<li>\n<p><strong>Be cautious about follow-up contacts quoting your records.<\/strong> A caller knowing your employer, document details, or phone number still needs independent verification.<\/p>\n<p>Decline requests for additional selfies, fees, or authentication codes until the genuine organization confirms the purpose through its own route.<\/p>\n<\/li>\n<\/ol>\n<h2>Prepare One Clear Exposure Note<\/h2>\n<p>Keep the essential information together: the offer, entry link, upload date, files sent, contact details entered, and any sign-in or payment action.<\/p>\n<p>Separate observations from guesses. For example, writing that a selfie was uploaded is useful; writing that every bank account was hacked without evidence is not.<\/p>\n<p>If you only selected files but are unsure whether they uploaded, explain that uncertainty. It may matter because different forms process files at different moments.<\/p>\n<p>Also record what you stopped before doing. Support staff should not have to infer that a later request was completed simply because it appeared on screen.<\/p>\n<p>This note can shorten stressful conversations with several organizations. It keeps the response focused on protecting your records instead of repeatedly reconstructing the whole website.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<h3>Is the tax agency running the Bonus Vacanze scam?<\/h3>\n<p>No. The confirmed campaign impersonates legitimate agencies. The deceptive websites and their document requests are the subject of this warning.<\/p>\n<h3>Does a real SPID redirect make the entire portal safe?<\/h3>\n<p>No. An authentic destination reached through one link does not authenticate the original site or its separate manual document-upload route.<\/p>\n<h3>What does the captured form request?<\/h3>\n<p>It visibly requests front and back identity-card and health-card images, plus a recent payslip. CERT separately documents later selfie and contact-information requests.<\/p>\n<h3>Was the original Bonus Vacanze program real?<\/h3>\n<p>Yes. Official historical guidance describes the earlier program. That history does not establish that this newer website or application process is legitimate.<\/p>\n<h3>Can this matter if I never paid anything?<\/h3>\n<p>Yes. The documented collection targets identity records. Their exposure can support later misuse even without an immediate payment or card charge.<\/p>\n<h3>Will antivirus recover my uploaded identity documents?<\/h3>\n<p>No. Device security tools address the device. Submitted documents require reporting, appropriate issuer guidance, and monitoring for attempts to misuse the information.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>The Bonus Vacanze scam makes a document-harvesting route look like another government service. Genuine links elsewhere on the page help that disguise, but do not authenticate it.<\/p>\n<p>Verify the offer before uploading anything. If you already shared records, document the exposure and act on the identity risks rather than waiting for a payment problem.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A holiday bonus appears on a website dressed like Italy&#8217;s tax agency. Familiar service links and recognizable login choices make the offer look surprisingly ordinary. Then one option takes the process in a different direction. &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Bonus Vacanze Scam: Fake Tax Agency Pages Collect IDs, Payslips and Selfies\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/bonus-vacanze-tax-agency-document-upload-scam\/#more-426207\" aria-label=\"Read more about Bonus Vacanze Scam: Fake Tax Agency Pages Collect IDs, Payslips and Selfies\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":426208,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-426207","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/426207","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=426207"}],"version-history":[{"count":1,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/426207\/revisions"}],"predecessor-version":[{"id":426209,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/426207\/revisions\/426209"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/426208"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=426207"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=426207"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=426207"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}