CSIDB logo
Incident

Radio Azzurra

Incident posture

Attack window
Dec 2020
Location
Italy
Status
Historical
CIA posture
Available to members
Updated
2025-12-07 00:00

Linked entities

Victim
Radio Azzurra
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Dec 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Radio Azzurra experienced a cyberattack involving ransomware after its owner downloaded a malicious application extension, resulting in a demand for hundreds of dollars to restore access. The incident caused significant operational disruption to the long-running media organization, with the attacker exploiting the compromised system to extort payment.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or around December 4, 2020, Italian broadcaster Radio Azzurra experienced a cyberattack involving ransomware. The incident began when owner Ugo Ponzio attempted to download an application extension, though the specific software or source was not disclosed. Upon opening a file generated during this process, Ponzio encountered a ransomware demand requiring payment of hundreds of dollars to regain access to affected systems. The attack disrupted normal operations of the station, which had operated for 45 years prior to the incident. Ponzio expressed both surprise and dismay at the situation, emphasizing he "would not have expected this too" despite his extensive career experience. No technical details about the ransomware variant, initial attack vector beyond the downloaded extension, or scope of encrypted systems were disclosed in available reports.

The ransomware demand’s appearance immediately upon file opening suggests the malware activated rapidly after execution. Radio Azzurra’s public statements did not specify whether payment was made, what systems were compromised, or whether data was exfiltrated. Operational disruption was implied by Ponzio’s characterization of the event as unprecedented in the station’s history. No containment measures, system restoration processes, or engagement with law enforcement or cybersecurity firms were detailed in the limited public accounts. The incident highlighted ransomware threats to small media entities, though Radio Azzurra’s recovery timeline and financial or data loss impacts remained undocumented in available sources.

Sources

Sources available to members: 1 source.

CSIDB