LulzSec Italy
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
LulzSec Italy, also known as LulzSecITA, LulzSec ITA and LulzSec Italia, is a hacktivist collective based in Italy. The group operates under the broader Anonymous umbrella and has collaborated with Anonymous Italia on several operations. Public sources describe it as an Italian‑language activist outfit that uses social media, particularly Twitter, to announce and amplify its actions. No public attribution to a state sponsor or criminal consortium has been made; the collective is presented as an independent activist entity.
The collective has repeatedly targeted Italian organizations across multiple sectors, including healthcare, higher education, telecommunications, government administrations, financial institutions, military veterans’ associations and political parties. Geographic focus appears to be confined to Italy, with incidents reported in Milan, Basilicata, Naples, Rome, Veneto, Piedmont and Emilia‑Romagna. Stated objectives include exposing alleged weaknesses in security controls, protesting government policies such as defense spending limits and labor‑market regulations, and demanding better working conditions for temporary workers. In some operations the actors explicitly said their goal was to demonstrate security failures rather than to profit financially or to defraud individuals.
Recurring techniques involve exploiting web application vulnerabilities, notably SQL injection vectors such as the payload index.html?idpg= used to extract databases from a political party’s site. The group has taken advantage of poorly protected credentials, referencing instances where user names and passwords were stored in plaintext on compromised systems. After gaining access, they exfiltrate data and publish the dumps on file‑hosting services like MEGA, announcing the releases via Twitter and often accompanying them with hashtags such as #StayTuned or #NessunDorma. Their activity also includes website defacement and distributed denial‑of‑service (DDoS) attacks, as seen in earlier operations against regional government portals linked to the Trans Adriatic Pipeline project. No specific malware families or custom tooling are mentioned in the open sources; the emphasis is on leveraging existing vulnerabilities and social‑media amplification.
Representative operations include the 2024 breach of Milan’s San Raffaele hospital, where patient names, tax codes, email addresses and passwords were leaked and the actor threatened further releases unless the institution acknowledged the incident. In 2019 the collective, together with Anonymous Italia, compromised the Italian telecom provider Lyca Mobile, publishing identification documents, telephone records and credit‑card data while stating the intent was to highlight security gaps rather than to commit fraud. The 2016 #NessunDorma campaign saw LulzSec Italy and Anonymous Italia infiltrate numerous job‑seeking portals, exfiltrating millions of records and publishing them on MEGA to press for a higher minimum wage and mandatory health insurance for temporary contracts. Earlier, in 2015, an affiliated Anonymous cell claimed Operation OpBankDump against Intesa Sanpaolo and Unipol Banca, extracting database dumps that the banks said originated from an external provider and were therefore unusable for fraud. These examples illustrate the group’s pattern of targeting Italian entities, using web‑based exploits to obtain data, and leveraging public disclosures to advance activist messages.
Incidents
Attributed incidents are available to members.
0 incidents