Menu
Browse

Cyber Incident Victim: Asl Città di Torino

Date:

Aug 2022

Location:

Italy

Summary

A ransomware attack targeted a public healthcare provider in Turin, causing significant operational disruptions by disabling IT infrastructure and forcing systems offline. The incident prompted manual workarounds, leading to service delays and patient inconveniences, including the inability to complete mandatory medical exams for driver's licenses. A ransom note demanding a substantial payment appeared, consistent with typical ransomware tactics. A dedicated task force involving internal technicians and external cybersecurity experts was activated to secure data, assess damage, and restore systems while law enforcement investigated the breach.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

The ASL Città di Torino experienced a significant cyber incident beginning on or around August 18, 2022, with operational disruptions becoming publicly acknowledged by August 23. The attack targeted the healthcare provider’s IT infrastructure, forcing a widespread shutdown of computer systems across affected hospitals and administrative facilities. Initial evidence pointed to a ransomware attack, as confirmed by Francesco Pensalfini, the ASL’s IT manager, who cited the appearance of a ransom note demanding a multi-million-euro payment as a key indicator. The attack immediately disrupted medical and administrative workflows, with staff unable to access digital systems, leading to the adoption of manual procedures for critical operations. Patients faced severe inconveniences, including the inability to complete mandatory medical examinations for driver’s licenses—a service directly impacted by the IT outage. The ASL’s public communication on August 23 confirmed the attack’s timeline and warned of ongoing service delays due to reliance on paper-based workarounds.

Cyber Incident Image

In response, the ASL activated an emergency task force comprising internal technicians and external experts from Italy’s CSIRT (Computer Security Incident Response Team), following national cybersecurity guidelines for such incidents. All corporate IT systems were proactively disconnected to contain the threat, facilitate forensic analysis, and initiate data recovery efforts. The Postal Police also launched a parallel criminal investigation into the attack’s origins and perpetrators. While the ASL prioritized securing sensitive data and restoring applications, no timeline for full recovery was provided in initial statements. The incident remained under active investigation, with lingering operational disruptions affecting a defined subset of healthcare services. Ongoing monitoring and system validation continued as the organization worked to resume normal operations amid unresolved cybersecurity concerns.

Sources
Sources available to members
1 source