Menu
Browse

Cyber Incident Victim: Sapienza

Date:

Feb 2026

Location:

Italy

Summary

La Sapienza University, Europe's largest by in-campus students, was hit by a ransomware attack attributed to the pro-Russian group Femwar02, which encrypted data and took IT systems offline, causing significant disruptions. The incident forced the university to suspend online services and prompted an ongoing response to restore operations.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On February 6, 2026, La Sapienza University was targeted by a ransomware attack. The attack was attributed to the pro-Russian hacker group Femwar02. La Sapienza is recognized as Europe's largest university by the number of students physically present on campus. The incident was reported in a cybersecurity news outlet on the same date. The report indicated that the university's IT infrastructure was affected. The ransomware operation resulted in the encryption of data stored on affected systems. As a consequence, the university's online services were disrupted. The attack prompted the institution to take its IT systems offline. The disruption affected administrative and academic functions reliant on digital platforms. No further details about the attack vector or ransom demand were disclosed in the source.

Cyber Incident Image

The source material does not provide information on any ransom payment or negotiation. It also does not describe specific containment measures taken beyond taking systems offline. No timeline for restoration of services is mentioned in the available text. The report does not indicate whether data backups were available or utilized. The incident is noted as part of a series of ransomware attacks affecting educational institutions. The attribution to Femwar02 aligns with observed patterns of pro‑Russian cyber activity. The university's status as Europe's largest by in‑campus enrollment amplified the impact of the outage. The abstract concludes that the attack caused significant disruptions with IT systems offline and data encrypted. No additional technical indicators of compromise are supplied in the source. Consequently, the narrative is limited to the facts presented in the article abstract.

Sources
Sources available to members
1 source