Lyce · Hybrid Watch

hw_683f6edd6cd4a22f

Pro-Russian hackers target nearly 20 Italian government websites in coordinated campaign.

The Italian cybersecurity agency reported that a pro-Russian hacker group had launched distributed-denial-of-service (DDoS) attacks on approximately 20 Italian institutional websites, including transport, banking and public service portals. The geography of the attack spans multiple regions within Italy rather than a border or maritime zone, emphasising how internal infrastructure is targeted. The dynamics suggest the adversary is using volume and persistence to degrade institutional resilience, impose cost and force diversion of defensive resources. Although no physical sabotage or kinetic strike was publicly confirmed, the sheer number of websites and sectors affected place this firmly in the hybrid-warfare category rather than mere criminal hacking. The timing and choice of targets indicate a deliberate strategy of destabilising service infrastructure in a NATO/EU member state. The link to Russian-linked actors highlights how Italy is within the cross-hairs of hybrid-threat vectors beyond the obvious frontline states.

Occurrence
2025-02-17
Publication
2025-02-16T23:00:00Z
First observed
2026-09-24T06:09:10.079Z
Review status
Not assessed
Countries
IT
Updated
2026-09-27T23:56:59.668Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2025-02-16T23:00:00Z

    The Italian cybersecurity agency reported that a pro-Russian hacker group had launched distributed-denial-of-service (DDoS) attacks on approximately 20 Italian institutional websites, including transport, banking and public service portals. The geography of the attack spans multiple regions within Italy rather than a border or maritime zone, emphasising how internal infrastructure is targeted. The dynamics suggest the adversary is using volume and persistence to degrade institutional resilience, impose cost and force diversion of defensive resources. Although no physical sabotage or kinetic strike was publicly confirmed, the sheer number of websites and sectors affected place this firmly in the hybrid-warfare category rather than mere criminal hacking. The timing and choice of targets indicate a deliberate strategy of destabilising service infrastructure in a NATO/EU member state. The link to Russian-linked actors highlights how Italy is within the cross-hairs of hybrid-threat vectors beyond the obvious frontline states.