Cyber Incident Victim: Comune di Cagliari
Date:
Jun 2021
Location:
Italy
Summary
A ransomware attack disrupted services for the Municipality of Cagliari, forcing extraordinary maintenance that significantly reduced functionality across counter services and call centers. Officials advised the public to avoid in-person visits unless urgent and to use online alternatives, while instructing employees via WhatsApp to keep workstations powered off and disconnected from networks to prevent further spread of the CryptoLocker malware. Although partial restoration occurred shortly after the incident, operational limitations persisted due to ongoing recovery efforts. The ransom demand specifics remained undisclosed at the time of reporting.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On June 27, 2021, the Municipality of Cagliari publicly disclosed a disruptive cyber incident through a notice on its website, attributing widespread service interruptions to a computer virus. The attack significantly degraded the functionality of municipal information systems, impacting both in-person counter services and call center operations. Officials characterized the event as requiring "extraordinary maintenance intervention" to restore operations, advising residents to avoid visiting municipal offices except in cases of extreme urgency and to prioritize online services where possible. Internal communications obtained by EveryEye revealed the municipality instructed employees via WhatsApp message to keep all office computers powered off with network cables disconnected—a containment measure explicitly intended to prevent further propagation of CryptoLocker ransomware. This directive indicated the malware’s presence in municipal systems, though authorities did not publicly confirm the ransomware variant at the time of their initial statement.

By June 28, municipal services began resuming operations, though functionality remained reduced due to continued maintenance activities. The municipality confirmed restoration progress in subsequent updates but cautioned that service limitations would persist through at least June 29 as recovery efforts extended. The incident caused sustained operational disruption across multiple public-facing channels, forcing adaptations in citizen engagement strategies during the remediation period. No details regarding ransom demands, payment status, or initial infection vectors were disclosed in available communications. Containment relied heavily on isolation protocols for endpoint devices alongside infrastructure maintenance, reflecting a response prioritizing system integrity restoration over immediate public disclosure of technical specifics.
