CSIDB logo
Incident

Trevi

Incident posture

Attack window
Jun 2026
Location
Italy
Status
Unknown
CIA posture
Available to members
Updated
2026-09-08 23:18

Linked entities

Victim
Trevi
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Jun 2026
Disclosed
Pending
Resolved
Pending

Summary

The Italian consumer electronics company Trevi experienced a cyberattack in which its official brand portal trevi.it was compromised by the Nova ransomware group. The breach was identified on a ransomware leak site that publishes details about compromised organizations and listed the company among its recent victims. Such leak sites typically provide attackers with a platform to pressure victims into paying ransom demands.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On June 9, 2026, the ransomware.live feed recorded a new victim entry for Trevi, indicating that the attack was discovered yesterday relative to the article date of June 10, 2026. The entry attributes the intrusion to the ransomware group known as Nova. The record notes that the compromised asset is the trevi.it website, which is described as the official brand portal for the Italian consumer electronics company Trevi. The timestamp shows the discovery occurred approximately 24 hours before the article’s publication. No further technical details about the intrusion vector or the systems affected are included in the source. The entry appears alongside other recent victims listed in the same feed.

The source material does not contain any information regarding the impact of the attack on Trevi’s operations, the extent of data exfiltration, or any ransom demand that may have been communicated. Likewise, there are no details about any response actions taken by Trevi, such as containment measures, notification procedures, or engagement with law enforcement or incident response firms. Because the article only provides the discovery date, the responsible ransomware group, and a brief description of the compromised web asset, the narrative is limited to these confirmed facts. Consequently, any discussion of consequences or mitigation efforts would require additional information not present in the provided text.

Sources

Sources available to members: 1 source.

CSIDB