Menu
Browse

Cyber Incident Victim: Civita.S

Date:

Mar 2025

Location:

Italy

Summary

A security breachaffecting the Civita.S app was reported after its provider MyCicero S.r.l. suffered a cyber attack by unidentified external actors on its servers. The incident exposed users’ names, surnames, email addresses, telephone numbers and any mobility tickets purchased through the app, while login credentials, passwords and payment information remained secure. In response, MyCicero disabled the affected systems, conducted investigations and remediation, strengthened security measures and access policies, and set up a dedicated support channel for users. The exposed data could be used for spam, phishing attempts, suspicious calls or SMS and fraudulent requests for additional personal information.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

OnMarch 30 2025 the municipal service Civita.S issued a notice informing users that its provider MyCicero S.r.l. had experienced a security incident affecting the Civita.S application. According to the notice, MyCicero reported that unidentified external actors had carried out a cyber‑attack on the provider’s servers, leading to a breach of personal data processed through the app. Upon learning of the attack, MyCicero immediately disabled the affected systems to prevent further unauthorized access and to conduct verification and security improvements. The temporary shutdown resulted in observable malfunctions and slowdowns of the Civita.S app during the days preceding the public announcement. The notice specified that the data potentially exposed in the breach included users’ first and last names, e‑mail addresses, telephone numbers, and any mobility titles that had been purchased through the application. It explicitly stated that login credentials, passwords, payment information, and credit‑card details were not compromised in the incident. No evidence was presented indicating that any other categories of personal data had been accessed or exfiltrated by the attackers.

Cyber Incident Image

In response to the breach, MyCicero blocked the compromised systems, initiated a thorough analysis and remediation of its infrastructure, and reinforced its security measures and access‑control policies. The provider also activated a dedicated assistance channel for users seeking information or support related to the incident. Civita.S provided contact e‑mail addresses for both MyCicero and its own support team, enabling users to direct inquiries to the appropriate parties. The notice was dated April 17 2025 and was published on the Civita.S website to ensure transparency with the affected user base.

Sources
Sources available to members
1 source