CSIDB logo
Incident

Scuola IMT Alti Studi Lucca

Incident posture

Attack window
May 2022
Location
Italy
Status
Historical
CIA posture
Available to members
Updated
2025-10-19 00:00

Linked entities

Victim
Scuola IMT Alti Studi Lucca
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
May 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A pro-Russian hacking group known as Killnet conducted distributed denial-of-service attacks against multiple Italian institutions, including the parliament, military, and National Health Institute, causing temporary website disruptions. The group claimed responsibility via Telegram, framing the incident as "military cyber exercises" targeting countries supporting Ukraine, while downplaying its severity compared to prior attacks on Romania. Italy's Senate confirmed no lasting damage occurred due to rapid technical intervention. The attacks aligned with Killnet's pattern of targeting NATO members providing aid to Ukraine, as the group issued threats suggesting future offensives against nations opposing Russian aggression. Microsoft had previously warned of potential escalation in Russian-aligned cyber operations against countries supplying military assistance to Ukraine.

Motives

Detailed motive labels are available to members.

3 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On May 11, 2022, a pro-Russian hacking group known as Killnet launched distributed denial-of-service (DDoS) attacks against multiple Italian institutional websites, including those of Italy’s parliament, military, National Health Institute, and Automobile Club d’Italia. The attacks caused temporary disruptions, with several websites remaining inaccessible for hours before being restored by technical teams. Killnet claimed responsibility for the incidents through Telegram channels, framing the operation as "military cyber exercises" targeting countries supporting Ukraine. Italy’s Senate President Maria Elisabetta Alberti Casellati confirmed the Senate’s external network was compromised but stated no lasting damage occurred due to immediate technical intervention. She characterized the incident as a serious episode requiring continued vigilance.

The attack mirrored Killnet’s previous DDoS campaign against Romanian government websites in late April 2022, which targeted the defense ministry, border police, and national railway in retaliation for Romania’s support of Ukraine. Killnet members explicitly linked the Italian attack to Italy’s provision of military and financial aid to Ukraine, taunting Italian and Spanish authorities in Telegram messages about future offensives. Microsoft had warned in April 2022 that Russian-aligned threat actors might expand cyber operations against nations assisting Ukraine, citing activity against NATO members like the Baltics and Turkey. While the Italian National Cybersecurity Agency did not publicly comment, the swift restoration of services and absence of reported data breaches or persistent system compromises indicated contained operational impacts. The incidents highlighted ongoing cyber retaliation risks for nations opposing Russia’s invasion of Ukraine.

Sources

Sources available to members: 1 source.

CSIDB