Menu
Browse

Cyber Incident Victim: Ente Autonomo Volturno

Date:

Feb 2022

Location:

Italy

Summary

A ransomware attack targeted the organization's IT infrastructure, prompting immediate security measures and recovery efforts. The attack did not disrupt rail or road transportation services, and no data theft or leakage occurred. As a precaution, core IT systems including email were temporarily suspended, causing delays in administrative operations. Restoration of certified services began progressing the following day to minimize operational impact.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On February 23, 2022, Ente Autonomo Volturno (EAV) experienced a significant ransomware attack targeting its corporate information systems. The attack compromised critical IT infrastructure, prompting an immediate organizational response. EAV confirmed its security systems successfully contained the breach, preventing complete system takeover. Restoration efforts commenced immediately to recover affected services and data. As a precautionary measure, EAV proactively suspended primary IT services including email systems and administrative platforms. This suspension caused operational disruptions across back-office functions but did not compromise transportation services. No evidence indicated data exfiltration or theft during the incident. The company maintained rail and road transport operations without service degradation throughout the attack period.

Cyber Incident Image

The incident exclusively impacted internal administrative processes, causing delays in bureaucratic functions reliant on suspended IT systems. EAV prioritized service restoration with plans to gradually reactivate certified systems beginning February 24. Security verification protocols preceded each service reactivation to ensure system integrity. Public transportation schedules and safety-critical systems remained fully operational during both the attack and recovery phases. The company's containment strategy focused on isolating compromised segments while preserving core operational technology. Restoration timelines anticipated progressive normalization of administrative functions following cybersecurity validation. EAV's public communications emphasized maintaining service continuity while managing backend recovery efforts.

Sources
Sources available to members
1 source