CSIDB logo
Incident

Nationalist Party of Malta

Incident posture

Attack window
Apr 2021
Location
Malta
Status
Historical
CIA posture
Available to members
Updated
2025-10-25 00:00

Linked entities

Victim
Nationalist Party of Malta
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Apr 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Nationalist Party of Malta experienced a ransomware attack by the Avaddon group, which infiltrated its IT infrastructure and exfiltrated sensitive data. After the party refused to pay the ransom, the attackers published a portion of the stolen documents, including financial records, employee personal information, and private client data. The group claimed possession of additional compromised materials, but the victim maintained a firm stance against negotiating with or paying the cybercriminals.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or around April 8, 2021, the Avaddon ransomware group infiltrated the IT infrastructure of Partit Nazzjonalista (Nationalist Party of Malta). The attackers exfiltrated sensitive data, including financial records, employee personal documents, and private client information. After the party failed to pay the demanded ransom, Avaddon initiated a partial data leak on their dark web platform. The group publicly claimed responsibility for the breach and detailed the types of compromised data to pressure the victim into payment. This marked a typical double-extortion tactic, where attackers threaten both operational disruption and reputational damage through data exposure. The initial leak occurred overnight following the expiration of the ransom deadline, though the exact timeframe between the initial breach and the leak was not specified in available reports.

The incident exposed highly sensitive organizational and personal data, escalating concerns about privacy violations and potential misuse. Partit Nazzjonalista’s leadership, including its party head, publicly affirmed a policy of non-negotiation with threat actors, ruling out any ransom payment to halt further leaks. This stance was formally communicated to Times of Malta by April 25, 2021, emphasizing a commitment to resisting cybercriminal demands despite the risks of additional data exposure. The published data samples served as proof of the breach’s validity, though the full scope of exfiltrated material and operational disruptions remained undisclosed. No subsequent reports clarified whether Avaddon released additional data or whether the party implemented technical countermeasures beyond its public refusal to engage.

Sources

Sources available to members: 1 source.

CSIDB