CSIDB logo
Incident

Alf DaFrè

Incident posture

Attack window
Feb 2025
Location
Italy
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 13:58

Linked entities

Victim
Alf DaFrè
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack compromised the servers of a furniture manufacturer in the Veneto region, blocking roughly 15% of its IT systems and prompting a ransom demand in cryptocurrency. The company refused to pay and shut down its entire IT infrastructure to contain the damage, despite having a backup available. Initial estimates suggested a 36 to 48 hour production stoppage, but restoration proved far more complex, leaving the workforce of about 350 employees largely idle for over a week. In coordination with labor unions, the firm requested the activation of temporary unemployment benefits, citing the sudden and unforeseeable production halt caused by the cyberattack. The incident was reported to the postal police, and recovery efforts have only recently begun to bring workers back on a limited basis.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

During the night between February 10 and 11, 2025, a group of cybercriminals successfully infiltrated the servers of Alf DaFrè, a historic furniture manufacturing company based in the province of Treviso, in the Veneto region of Italy. The company, known for producing modular and customizable furniture, operates two facilities in the area, located in Cordignano and Francenigo di Gaiarine, near Conegliano. Within minutes of breaching the company's network, the attackers blocked the server responsible for managing production operations and subsequently issued a ransom demand to restore access. The company promptly filed a report with the postal police, formally denouncing the cyberattack. According to preliminary investigations, the attack was carried out using ransomware, a type of malicious software that encrypts or otherwise blocks access to data stored on servers in order to extort a payment from the victim. The criminals managed to compromise approximately 15 percent of the company's entire information system before issuing their demand for payment in cryptocurrency.

Following the discovery of the intrusion, Alf DaFrè made the decision not to comply with the attackers' ransom demands. Instead, the company chose to shut down its entire information technology infrastructure as a precautionary measure. This action was taken both to prevent further damage by the attackers and to protect the portion of the systems that had not yet been compromised. Initially, company technicians estimated that production would only need to be halted for between 36 and 48 hours. This optimistic outlook was partly supported by the existence of a backup system containing data that was current as of the evening before the attack occurred. However, as technicians conducted a more thorough assessment of the situation, it became clear that restoring operations would require significantly more time than originally anticipated.

The extended outage had immediate and substantial consequences for the company's workforce. Alf DaFrè employs approximately 350 people, and for more than a week following the attack, the majority of these workers were unable to perform their duties, resulting in a complete halt to furniture production. In coordination with labor unions, the company submitted a request to Italy's National Social Security Institute, INPS, to activate cassa integrazione, a form of wage supplementation provided to workers during periods of involuntary suspension from work. The justification provided for this request was a production stoppage caused by a sudden and unforeseen event, referring directly to the ransomware attack. Only in the final days of the reporting period did the first workers manage to return to their operational roles, suggesting a gradual, partial restoration of capacity.

The attack on Alf DaFrè fits within a broader pattern observed in Italy over the preceding three years, during which numerous companies of varying sizes fell victim to similar ransomware incidents. While the most high-profile attacks during this period targeted hospitals, healthcare companies, diagnostic centers, and public outpatient clinics, institutions that are particularly attractive to cybercriminals due to their vulnerability and the essential nature of the data they hold, the manufacturing sector has also increasingly found itself in the crosshairs. Companies in the energy sector have similarly been targeted for comparable reasons. Roberto Martini, secretary of the FILCA CISL union for Belluno and Treviso, noted that there has been a common perception that large corporations are the primary targets of such attacks, when in reality businesses of any size can be affected. He emphasized that Alf DaFrè had invested substantially in cybersecurity measures, and yet these precautions proved insufficient to prevent the successful intrusion. The incident underscored the reality that even companies with significant security investments can fall victim to determined cybercriminals, and it illustrated the severe operational and human consequences that such attacks can impose on businesses and their employees.

Sources

Sources available to members: 1 source.

CSIDB