CSIDB logo
Incident

SEA Group

Incident posture

Attack window
Feb 2025
Location
Italy
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 12:01

Linked entities

Victim
SEA Group
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Italian cybersecurity authorities reported that a pro‑Russian hacker group attacked several Italian websites, including those of banks and the operator of Milan’s airports, SEA. The assault, linked to the group Noname057(16), was said to be motivated by recent remarks from Italy’s president comparing Russia’s actions in Ukraine to Nazi expansionism. Although the targeted sites experienced the intrusion, officials said there was no major disruption to services. The same group had previously claimed responsibility for an attack on about ten Italian institutional websites.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On February 17, 2025, Italy's cybersecurity agency announced that approximately twenty Italian websites, including those of banks and airports, had been targeted by a cyber attack attributed to the pro‑Russian hacker group Noname057(16). The agency linked the operation to heightened tensions between Rome and Moscow that followed Italian President Sergio Mattarella’s public comparison of Russia’s war in Ukraine to the expansionist policies of Nazi Germany before World War II. According to the agency, Noname057(16) cited Mattarella’s remarks as the motivation for the attack. The announcement came on a Monday, as reported by Reuters.

The specific targets named in the agency’s statement were the online presences of Intesa Sanpaolo, Banca Monte dei Paschi, Iccrea Banca, and Milan’s Linate and Malpensa airports, the latter operated by SEA Group. SEA, together with Intesa Sanpaolo, declined to comment on the incident when approached by Reuters. A spokesman for Iccrea Banca stated that the bank experienced no disruptions as a result of the attack, while Banca Monte dei Paschi did not immediately reply to a request for comment. The agency emphasized that, despite the breadth of the targeting, the cyber attack did not cause major disruption to the affected services.

In addition to the February 17 incident, the cybersecurity agency noted that Noname057(16) had previously claimed responsibility for a cyber attack on Italy in December 2024, which had targeted roughly ten institutional websites. The response to the February event consisted of the agency’s public disclosure, the statements from the affected organizations indicating a lack of operational impact, and the absence of any reported service outages. No further details about technical mitigation or containment measures were provided in the source material.

Sources

Sources available to members: 1 source.

CSIDB