CSIDB logo
Incident

Milan Linate Airport

Incident posture

Attack window
Feb 2025
Location
Italy
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 11:56

Linked entities

Victim
Milan Linate Airport
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Undetermined
Disclosed
Feb 2025
Resolved
Pending

Summary

A pro-Russian hacker group known as Noname057(16) carried out distributed denial-of-service attacks against roughly 20 Italian websites, targeting banks such as Intesa Sanpaolo, Banca Monte dei Paschi, and Iccrea Banca, along with Milan's Linate and Malpensa airports. The Italian cybersecurity agency reported the attacks were motivated by controversial remarks made by Italian President Sergio Mattarella, who drew a parallel between Russia's war on Ukraine and Nazi Germany's expansionism, provoking outrage from Moscow. The incidents caused no major disruption to the targeted institutions, with affected entities either declining to comment or confirming normal operations continued.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On February 17, 2025, Italy's national cybersecurity agency reported that approximately 20 Italian websites were targeted in coordinated cyberattacks attributed to a pro-Russian hacker group known as Noname057(16). The attacks affected a range of high-profile organizations, including major Italian banks and airport operators. Among the financial institutions hit were Intesa Sanpaolo, Banca Monte dei Paschi di Siena, and Iccrea Banca. The airport sector was represented by SEA, the company that manages Milan's airport infrastructure, with both Milan's Linate and Malpensa airports listed among the targeted websites. The Italian cybersecurity agency confirmed that the hacker group explicitly cited recent geopolitical tensions as motivation for the campaign, linking the cyber activity to public statements made by Italian President Sergio Mattarella earlier in the month regarding Russia's war in Ukraine.

The geopolitical backdrop for these attacks centered on remarks made by President Sergio Mattarella in early February 2025, in which he drew a parallel between Russia's military actions against Ukraine and the expansionist policies pursued by Nazi Germany prior to World War II. These comments provoked a strong reaction from Moscow but were subsequently defended by Italian Prime Minister Giorgia Meloni. According to the Italian cybersecurity agency, Noname057(16) referenced Mattarella's statements as a direct justification for launching the cyberattacks against Italian targets. This marked the second reported incident involving the same group targeting Italian interests in a short period, following a December 2024 operation in which the group claimed responsibility for attacks on approximately 10 institutional websites in Italy.

Despite the broad scope of the campaign, which spanned multiple sectors of Italian critical infrastructure and public-facing services, the actual technical impact appears to have been limited. The Italian cybersecurity agency characterized the attacks as not causing major disruption to the targeted organizations. Specific responses from the affected entities varied. Intesa Sanpaolo and SEA, the operator of Milan's airports, declined to provide comment when approached by reporters. A spokesperson for Iccrea Banca stated that the bank experienced no service disruptions as a result of the incident. Banca Monte dei Paschi di Siena did not respond to requests for comment prior to the publication of initial reporting on the event.

The pattern of attacks against Italian organizations aligned with broader trends observed in pro-Russian hacktivist activity, which has frequently targeted countries whose political leaders make public statements critical of Russian foreign policy. Noname057(16) had previously been associated with similar campaigns against other European nations, typically employing distributed denial-of-service techniques and website defacements rather than more destructive intrusion-based attacks. The February 2025 operation against Italy appeared consistent with this established pattern, focusing on visibility and symbolic impact rather than causing significant operational damage to the underlying services or compromising sensitive data.

The incident occurred during a period of heightened diplomatic strain between Italy and Russia, with the cyber dimension supplementing broader political tensions that had been escalating since Mattarella's controversial remarks. Italian authorities, through the national cybersecurity agency, were responsible for coordinating the public disclosure of the incident and attributing it to Noname057(16). The agency's role in monitoring and reporting on such threats reflects the ongoing effort to track hacktivist groups that operate in alignment with Russian geopolitical objectives. While the attacks did not result in reported damage to airport operations or banking services, the targeting of critical national infrastructure websites served as a demonstration of capability and intent by the threat actor.

Sources

Sources available to members: 1 source.

CSIDB