CSIDB logo
Incident

Civita.S

Incident posture

Attack window
Mar 2025
Location
Italy
Status
Unknown
CIA posture
Available to members
Updated
2026-04-22 04:14

Linked entities

Victim
Civita.S
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A security breachaffecting the Civita.S app was reported after its provider MyCicero S.r.l. suffered a cyber attack by unidentified external actors on its servers. The incident exposed users’ names, surnames, email addresses, telephone numbers and any mobility tickets purchased through the app, while login credentials, passwords and payment information remained secure. In response, MyCicero disabled the affected systems, conducted investigations and remediation, strengthened security measures and access policies, and set up a dedicated support channel for users. The exposed data could be used for spam, phishing attempts, suspicious calls or SMS and fraudulent requests for additional personal information.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

OnMarch 30 2025 the municipal service Civita.S issued a notice informing users that its provider MyCicero S.r.l. had experienced a security incident affecting the Civita.S application. According to the notice, MyCicero reported that unidentified external actors had carried out a cyber‑attack on the provider’s servers, leading to a breach of personal data processed through the app. Upon learning of the attack, MyCicero immediately disabled the affected systems to prevent further unauthorized access and to conduct verification and security improvements. The temporary shutdown resulted in observable malfunctions and slowdowns of the Civita.S app during the days preceding the public announcement. The notice specified that the data potentially exposed in the breach included users’ first and last names, e‑mail addresses, telephone numbers, and any mobility titles that had been purchased through the application. It explicitly stated that login credentials, passwords, payment information, and credit‑card details were not compromised in the incident. No evidence was presented indicating that any other categories of personal data had been accessed or exfiltrated by the attackers.

In response to the breach, MyCicero blocked the compromised systems, initiated a thorough analysis and remediation of its infrastructure, and reinforced its security measures and access‑control policies. The provider also activated a dedicated assistance channel for users seeking information or support related to the incident. Civita.S provided contact e‑mail addresses for both MyCicero and its own support team, enabling users to direct inquiries to the appropriate parties. The notice was dated April 17 2025 and was published on the Civita.S website to ensure transparency with the affected user base.

Sources

Sources available to members: 1 source.

CSIDB