Malware, Ransomware

Italian organizations targeted by 148 ransomware attacks in first half of 2026

(Adobe Stock)

Italian organizations faced 148 confirmed ransomware attacks in the first half of 2026, with the manufacturing sector being the most frequently targeted. This data, compiled from open-source and social media intelligence, reveals a consistent threat landscape with an average of nearly six claims per week. Attackers also claimed to have exfiltrated over 13,400 GB of data during this period, though detailed volumes were only disclosed in less than half of the reported incidents, as first reported by Security Affairs.

The report highlights that Northwest Italy was the most affected region, accounting for 42.6% of victims. Manufacturing bore the brunt of these attacks, with 59 victims (39.9%), due to the sector's valuable proprietary data, operational technology vulnerabilities, and low tolerance for downtime. LockBit5 and Qilin were the most active ransomware groups, each claiming 21 victims. LockBit5's activity surged in March, aligning with global trends, while Qilin systematically targeted small and medium businesses. June saw a significant spike in claims, largely due to concentrated attacks by groups like Deadlock and Safepay. Common attack vectors included reused credentials, unpatched public-facing systems, and exposed RDP, indicating a reliance on basic exploitation methods rather than sophisticated tradecraft. The disposable nature of many ransomware brands was also noted, with 30 different groups claiming at least one victim, but many appearing only once.

Source: Security Affairs

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Adware

You can skip this ad in 5 seconds