Cyber Incident Victim: Comune di Rosignano Marittimo
Date:
Oct 2022
Location:
Italy
Summary
The Municipality of Rosignano Marittimo experienced a sophisticated ransomware attack targeting its IT infrastructure, forcing immediate precautionary shutdowns of all servers to contain the malware. Attackers encrypted both primary systems and daily online backups, crippling operations and preventing employee access. IT personnel disconnected networks and restored partial functionality using an offline backup, with external support engaged to identify the malware. Critical services including email and network access remained disrupted, though initial login server recovery showed promise under monitoring. The organization publicly acknowledged the incident and apologized for prolonged service outages, but could not estimate full restoration timelines due to the attack's complexity.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On October 5, 2022, between approximately 6:00 AM and 8:00 AM, the Municipality of Rosignano Marittimo in Tuscany suffered a ransomware attack targeting its IT infrastructure. Technical staff from the UO Sistemi Informativi detected anomalies after employees reported login failures across workstations, prompting immediate containment measures. Personnel powered down all servers as a precaution against malware propagation and disconnected the municipal network from the internet to prevent data exfiltration. Initial investigations revealed the incident involved highly sophisticated ransomware deployed for financial extortion, contrasting with a 2013 hacktivist attack against the same municipality. External IT provider TDGroup provided telephonic support during the emergency response. By late morning, forensic analysis confirmed attackers had compromised daily online backups stored within the network, rendering them encrypted and unusable for recovery.

Response teams attempted restoration using the most recent offline backup stored on an external drive, successfully rebuilding one login server for initial testing. This isolated server remained under observation to verify malware eradication while the central infrastructure stayed powered off and disconnected. Critical services including email systems and network access remained inoperable, disrupting municipal operations and public-facing functions. The administration issued formal apologies for service interruptions via their official website on the same day, acknowledging an indeterminate recovery timeline. No evidence emerged regarding data theft, though the attackās sophistication prevented immediate identification of the malware strain. Restoration efforts prioritized securing clean backups and phased reactivation of systems under external cybersecurity guidance, with full operational restoration pending further forensic analysis and system validation.
