CSIDB logo
Incident

Sapienza

Incident posture

Attack window
Feb 2026
Location
Italy
Status
Unknown
CIA posture
Available to members
Updated
2026-08-27 00:55

Linked entities

Victim
Sapienza
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Feb 2026
Discovered
Undetermined
Disclosed
Apr 2026
Resolved
Pending

Summary

La Sapienza University, Europe's largest university by on‑campus enrollment, suffered a ransomware attack attributed to the pro‑Russian group Femwar02, which encrypted data and took its IT systems offline. The incident disrupted teaching, research, and administrative operations, forcing the suspension of online services and campus network access. Recovery efforts involved isolating affected systems, restoring backups, and coordinating with cybersecurity experts to mitigate further damage.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On February 6, 2026, La Sapienza University in Italy experienced a ransomware attack that forced its IT systems offline. The attack was attributed to the pro‑Russian cyber group Femwar02, according to the university’s reporting. La Sapienza is noted as Europe’s largest university by the number of students studying on campus. The ransomware encrypted data across the institution’s networks, rendering critical services inaccessible. As a result, the university reported significant disruptions to its academic and administrative operations.

The incident was first disclosed in a public notice dated February 6, 2026, and later summarized in a library outage report published on April 2, 2026. No further details about the attack vector, the extent of data exfiltration, or the timeline for system restoration were provided in the source material. The university’s status as Europe’s largest in‑campus student population underscores the scale of the potential impact. The attribution to Femwar02 links the incident to a pro‑Russian threat actor active in the ransomware landscape. The encrypted state of the data and the offline IT systems constitute the primary consequences described in the available reports.

Sources

Sources available to members: 1 source.

CSIDB