Comune di Pisa
Incident posture
Linked entities
- Victim
- Comune di Pisa
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
A cyber gang known as Nova claimed responsibility for a ransomware attack against the municipality, publicly asserting the intrusion on a Saturday evening. Evidence from the leaked samples indicates that file encryption was applied only a few hours prior to the claim, suggesting a rapid intrusion-to-encryption timeline. The group also alleged the exfiltration of approximately 2TB of data from the compromised environment, pointing to a possible double-extortion scheme combining data theft with system encryption.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
During the evening of Saturday, May 2025, a criminal claim of cyber attack against the municipality of Pisa was published by the cyber gang known as Nova, which is known for ransomware-type attacks. According to the claim, the attack targeted the systems of the Comune di Pisa, and technical analysis of the available samples suggests that the encryption phase of the ransomware operation was likely applied only a few hours before the public claim was issued. The Nova cyber gang announced responsibility for the intrusion during a Saturday evening publication, a timing that allowed the group to communicate its involvement while the encrypted state of the targeted systems was still fresh. The nature of the incident aligns with the typical modus operandi of Nova, which has built a reputation through previous ransomware campaigns directed at public and private organizations.
Based on the technical samples and indicators examined following the publication of the claim, the incident appears to involve a probable exfiltration of approximately 2 terabytes of data from the municipality's systems, in addition to the encryption of files. The reference to 2TB of data being exfiltrated indicates that the attackers may have had sustained access to the municipal network long enough to aggregate and remove a substantial volume of information before triggering the encryption payload. This combination of data theft and file locking is consistent with the double-extortion technique commonly employed by modern ransomware operations, in which victims face both the loss of access to their own data and the threat of public disclosure of stolen information if ransom demands are not met.
The claim was issued specifically against the Comune di Pisa, one of the major Italian municipal administrations, suggesting that the attackers identified the local government as a high-value target likely to contain sensitive citizen data, administrative records, and operational information. The Saturday timing of the claim is notable because it occurred during a weekend period, when many administrative offices operate with reduced staff, potentially slowing initial detection and response coordination within the affected organization. The publication of the claim represents the standard communication channel used by the Nova ransomware group to publicize its successful intrusions and to pressure victim organizations toward ransom payment. The technical artifacts referenced in the claim, including sample data, indicate that the encryption process was applied in the immediate timeframe preceding the Saturday evening announcement, placing the active encryption stage of the attack within a narrow window of the same day.
The available evidence points to a ransomware incident combining file encryption with large-scale data exfiltration, claimed publicly by the Nova cyber gang against the municipal administration of Pisa, with technical indicators suggesting the encryption phase was executed in the hours immediately preceding the public claim of responsibility on the evening of Saturday, May 2025.
Sources
Sources available to members: 1 source.