Intesa Sanpaolo
Incident posture
Linked entities
- Victim
- Intesa Sanpaolo
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
Alleged pro‑Russian hackers linked to the group Noname057(16) carried out a distributed denial‑of‑service campaign against roughly twenty Italian online services, including the website of Intesa Sanpaolo, two other banks and the Milan airport operators Linate and Malpensa. The attackers said the action was a response to recent statements by Italy’s president likening Russia’s war in Ukraine to Nazi expansionism. Italy’s cybersecurity agency reported that the attacks caused no significant disruption and that the affected institutions either confirmed normal operation or declined to comment.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On Monday, February 17 2025, Italy’s cybersecurity agency reported that a pro‑Russian hacker group known as Noname057(16) carried out coordinated cyberattacks against approximately twenty Italian websites, including those of banks and airports. The agency linked the operation to recent tensions between Rome and Moscow, specifically citing remarks made earlier that month by Italian President Sergio Mattarella comparing Russia’s war in Ukraine to the expansionist policies of Nazi Germany before World II. Among the targets named were the online presences of Intesa Sanpaolo, Banca Monte dei Paschi, Iccrea Banca, and the Milan Linate and Malpensa airports managed by SEA. The agency emphasized that the attacks did not result in major disruption to the services of the affected organizations.
In response to the incident, Intesa Sanpaolo and SEA both declined to comment on the attacks when approached by Reuters. A spokesman for Iccrea Banca stated that the bank experienced no disruptions as a result of the activity, while Banca Monte dei Paschi did not immediately reply to a request for comment. The cybersecurity agency reiterated that the hacker group claimed its motivation stemmed from Mattarella’s statements, noting that Noname057(16) had previously claimed responsibility for a December 2024 operation that targeted around ten institutional Italian websites. The agency’s statement highlighted the absence of significant impact despite the breadth of the targeting.
The broader context provided by the article includes the defense of Mattarella’s comments by Italian Prime Minister Giorgia Meloni, which had provoked outrage in Moscow prior to the cyberattacks. The agency’s reporting placed the February 17 incident within a pattern of politically motivated cyber activity attributed to the same hacker group. No further details about technical methods, detection timelines, or specific remediation steps were disclosed in the source material. The narrative concludes with the confirmed facts that the attacks occurred, were attributed to Noname057(16), targeted Intesa Sanpaolo among other entities, and were assessed by authorities as having caused no major service disruption.
Sources
Sources available to members: 1 source.