SEA Group
Incident posture
Timeline
Summary
Italian cybersecurity authorities reported that a pro‑Russian hacker group attacked several Italian websites, including those of banks and the operator of Milan’s airports, SEA. The assault, linked to the group Noname057(16), was said to be motivated by recent remarks from Italy’s president comparing Russia’s actions in Ukraine to Nazi expansionism. Although the targeted sites experienced the intrusion, officials said there was no major disruption to services. The same group had previously claimed responsibility for an attack on about ten Italian institutional websites.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On February 17, 2025, Italy's cybersecurity agency announced that approximately twenty Italian websites, including those of banks and airports, had been targeted by a cyber attack attributed to the pro‑Russian hacker group Noname057(16). The agency linked the operation to heightened tensions between Rome and Moscow that followed Italian President Sergio Mattarella’s public comparison of Russia’s war in Ukraine to the expansionist policies of Nazi Germany before World War II. According to the agency, Noname057(16) cited Mattarella’s remarks as the motivation for the attack. The announcement came on a Monday, as reported by Reuters.
The specific targets named in the agency’s statement were the online presences of Intesa Sanpaolo, Banca Monte dei Paschi, Iccrea Banca, and Milan’s Linate and Malpensa airports, the latter operated by SEA Group. SEA, together with Intesa Sanpaolo, declined to comment on the incident when approached by Reuters. A spokesman for Iccrea Banca stated that the bank experienced no disruptions as a result of the attack, while Banca Monte dei Paschi did not immediately reply to a request for comment. The agency emphasized that, despite the breadth of the targeting, the cyber attack did not cause major disruption to the affected services.
In addition to the February 17 incident, the cybersecurity agency noted that Noname057(16) had previously claimed responsibility for a cyber attack on Italy in December 2024, which had targeted roughly ten institutional websites. The response to the February event consisted of the agency’s public disclosure, the statements from the affected organizations indicating a lack of operational impact, and the absence of any reported service outages. No further details about technical mitigation or containment measures were provided in the source material.
Sources
Sources available to members: 1 source.