Cyber Incident Victim: Correggio Speed Cameras database
Date:
Dec 2017
Location:
Italy
Summary
Anonymous compromised a local police computer system in Correggio, Italy, gaining unauthorized access to delete the municipality's speed camera ticket database containing 40 gigabytes of traffic infringement photographs. The attackers substantiated their actions by distributing screenshots of the erased data to Italian media outlets and additionally leaked internal police communications, including emails and operational documents.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On December 31, 2017, individuals identifying with the hacktivist collective Anonymous breached the computer systems of the local police department in Correggio, Italy. The attackers gained remote access to the law enforcement network and deliberately erased the database containing speed camera violation records. This deletion targeted approximately 40 gigabytes of photographic evidence tied to traffic enforcement operations. Following the data destruction, the perpetrators captured screenshots documenting their unauthorized access and the deletion process. These images were subsequently distributed to multiple Italian news organizations, including Gazzetta di Reggio, as verification of the successful compromise. The breach extended beyond the speed camera records, with attackers exfiltrating and leaking internal police communications, documents, and operational information to media outlets.

The incident resulted in the permanent loss of photographic evidence supporting pending traffic violation cases, directly impacting the municipality’s enforcement capabilities. The release of internal police materials to the press introduced additional reputational and operational risks for the agency. No technical details regarding the attack vector or vulnerability exploitation were disclosed in public reports. Similarly, the affected municipality did not release information about detection methods, containment procedures, or potential data recovery efforts. The attackers’ unilateral media outreach served as the primary confirmation of the breach’s scope and success, with no verified statements from law enforcement regarding incident response or system restoration timelines.
