CSIDB logo
Threat actor

LulzSecITA

Attribution profile

Type
Activist
Location
Italy
Known incidents
2 incidents
First seen
2019-11-05
Last seen
2019-11-05
Updated
2026-08-01 02:09
Aliases
3 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

LulzSecITA, also known as LulzSec Italia or LulzSec Italy, is an Italian hacktivist collective that has operated under several aliases while maintaining a clear national focus. The group has been linked to Anonymous Italia in joint actions, most notably the coordinated operations carried out on 5 November 2019, and it describes itself as a activist entity rather than a criminal or state‑sponsored outfit. Public statements and attributions in open‑source reporting consistently place its activity within Italy, targeting Italian institutions and organizations.

The collective’s publicly stated objectives center on exposing perceived security failures and protesting inadequate privacy or data‑protection practices, rather than pursuing financial gain or espionage. In the November 2019 campaign with Anonymous Italia, LulzSecITA framed the exfiltration of identity documents, financial records and communications from entities such as the Abruzzo and Puglia regional environmental agencies, professional orders, government offices and the telecom provider Lyca Mobile as a demonstration of insufficient safeguards. Similar motivations were expressed when the group disclosed personal data of discharged military personnel, citing protest against excessive defense spending, and when it claimed to have compromised Italian universities to highlight weak cybersecurity practices in academia. In each case the actors emphasized that their intent was to reveal vulnerabilities, not to profit from the stolen data.

Regarding tactics, techniques and procedures, the sources describe the group’s reliance on exploiting unspecified vulnerabilities in target systems, obtaining credentials that were sometimes stored in plaintext, and then using social‑media platforms—particularly Twitter—to publicize the breaches and pressure victims into acknowledging the incidents. No specific malware families, exploit kits or custom tooling are mentioned in the available material; the group’s approach appears to rely on vulnerability discovery, credential harvesting and public disclosure as primary means of pressure. Their operations have included the November 2019 multi‑sector intrusion that yielded approximately 5.4 GB of data, the February 2020 claim of compromising universities in Basilicata, Naples and Rome, the May 2024 disclosure of patient data from Milan’s San Raffaele hospital after a Twitter alert went unanswered, the September 2018 release of military veterans’ personal information, and a 2016 claim of compromising the primodominio.it domain and leaking 150 000 user credentials. Each of these actions was presented publicly as a protest against perceived institutional negligence in protecting data.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB