Intesa Sanpaolo
Incident posture
Linked entities
- Victim
- Intesa Sanpaolo
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
A pro-Russian hacker group known as Noname057(16) targeted roughly twenty Italian websites, including those belonging to banks and major airports, in a coordinated cyberattack. The Italian cybersecurity agency attributed the incidents to tensions between Rome and Moscow following controversial remarks made by Italian President Sergio Mattarella comparing Russia's war in Ukraine to historical expansionism. Among the affected entities were Intesa Sanpaolo, Banca Monte dei Paschi, Iccrea Banca, and Milan's Linate and Malpensa airports. The attacks caused no major disruption to the targeted organizations, and representatives from the impacted banks and the airport management company either declined to comment or reported no operational issues. This marks the second wave of cyber operations by the same group against Italy within a short period, following a similar incident targeting around ten institutional websites.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On Monday, February 17, 2025, approximately twenty Italian websites became the targets of a coordinated cyber offensive attributed by Italy's national cybersecurity agency to the pro-Russian hacker collective known as Noname057(16). The attack touched multiple sectors, striking prominent financial institutions and critical transportation infrastructure, though the intrusion did not lead to the disruption of essential services. Italy's cybersecurity agency linked the timing and motivation of the attacks directly to a sharp deterioration in diplomatic relations between Rome and Moscow, triggered earlier in the month by public remarks made by Italian President Sergio Mattarella regarding the historical parallels between contemporary Russian military actions and the expansionist ambitions of Nazi Germany in the period leading up to the Second World War. Those comments, which drew an angry response from the Kremlin, were publicly defended by Italian Prime Minister Giorgia Meloni, setting the stage for the retaliatory online action that followed.
The list of affected entities confirmed by the cybersecurity agency included Intesa Sanpaolo, Banca Monte dei Paschi di Siena, Iccrea Banca, and SEA, the company responsible for managing Milan's Linate and Malpensa airports, along with several other Italian institutional and corporate websites targeted in the same campaign. The Noname057(16) group publicly stated that its actions were motivated by Mattarella's controversial statements, marking the second recorded instance of the group directing cyber operations at Italian targets within a two-month span, following a December 2024 incident in which the same collective claimed responsibility for intrusions affecting roughly ten Italian institutional websites. The February operation appears to have been planned as a broader, more visible continuation of that earlier pressure campaign, with the group deliberately selecting high-profile banks and major international aviation hubs to maximize the symbolic impact of the attack, even though the technical consequences remained limited.
Despite the wide scope of the targeting, none of the affected organizations reported significant operational damage. Intesa Sanpaolo, Italy's largest banking institution, declined to provide any official commentary on the incident, a posture consistent with a cautious institutional response aimed at avoiding the amplification of the attackers' claims. Banca Monte dei Paschi di Siena did not immediately respond to media inquiries regarding the breach, while Iccrea Banca confirmed through a spokesperson that its services had experienced no disruptions as a result of the attack. SEA, the airport management authority, similarly declined to comment on the specifics of how its web presence had been affected, though the continued operation of both Linate and Malpensa airports on the day of the attack suggested that any compromise was confined to external-facing web properties rather than operational control systems. The pattern of impact, distributed across multiple unrelated sectors but lacking destructive depth, aligns with the typical operational profile of ideologically motivated hacktivist collectives, which often favor high-visibility website defacements and distributed denial-of-service campaigns designed to attract media attention over technically complex intrusions intended to steal data or sabotage infrastructure.
The Italian cybersecurity agency took the lead role in publicly identifying the perpetrator and contextualizing the geopolitical motivation behind the attack, thereby framing the incident as part of a wider pattern of state-aligned retaliatory cyber activity rather than an isolated criminal operation. By publicly attributing the campaign to Noname057(16) and explicitly connecting the attacks to Mattarella's earlier remarks, the agency effectively communicated both the technical attribution and the political narrative surrounding the incident to the Italian public and the international community. The reporting on the event was handled by journalists Stefano Bernabei and Gianluse Semeraro, with editorial oversight provided by Cristina Carlevaro and Alvise Armellini, reflecting the seriousness with which both Italian institutions and international news organizations treated the incident. Although the immediate technical fallout was minimal, the broader significance lies in the confirmation that pro-Russian cyber actors continue to view Italian digital infrastructure as a legitimate target in response to public criticism of Russian foreign policy, underscoring the persistent vulnerability of publicly accessible institutional websites to politically motivated disruption campaigns.
Sources
Sources available to members: 1 source.