Menu
Browse

Cyber Incident Victim: Comune di Mantova

Date:

Apr 2024

Location:

Italy

Summary

The Comune di Mantova experienced a cyberattack targeting applications managed by its service provider Tea, with investigations confirming no permanent loss or deletion of personal data. A criminal group claimed responsibility for the breach, asserting they exfiltrated information including personal data and provided demonstrative samples, though the exact nature and extent of compromised data remain unverified. Tea is conducting ongoing forensic analysis to determine the categories of affected data and facilitate necessary regulatory compliance measures. The municipality has advised concerned individuals to utilize designated contact channels for additional information or guidance regarding the incident.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On April 16, 2024, the Comune di Mantova experienced a cybersecurity incident affecting technological applications managed by Tea, a service provider. The attack prompted an immediate investigation by Tea’s internal and external specialist teams. Tea formally notified the municipality regarding developments in the investigation, confirming no permanent loss or deletion of personal data occurred and asserting all data remained under the company’s full control. A criminal group claimed responsibility for the breach, alleging data exfiltration—including personal information—and provided demonstrative samples as evidence of their claims. Despite this claim, investigators could not initially verify the scope, nature, or factual basis of the alleged confidentiality breach involving data processed on behalf of the Comune di Mantova. The compromise specifically impacted systems handling municipal data processed by Tea under its contractual obligations.

Cyber Incident Image

Tea committed to continuing forensic analysis to determine which categories of data, if any, were exfiltrated during the incident. This ongoing investigation aimed to enable the Comune di Mantova, as the data controller, to fulfill any mandatory regulatory notifications or compliance steps required under data protection laws. The municipality directed concerned citizens to contact Tea’s dedicated helpline (800 903693) or its Data Protection Officer, Rosario Imperiali D’Afflitto, for clarifications and guidance on best practices following such incidents. Tea published a detailed incident notice on its corporate website to inform users and address inquiries. No operational disruptions or irreversible data destruction affecting municipal services were reported in the initial assessment. The investigation remained active to establish conclusive findings regarding the attackers’ specific access and exfiltration activities.

Sources
Sources available to members
1 source