CSIDB logo
Incident

Mooney Servizi SpA

Incident posture

Attack window
Apr 2025
Location
Italy
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 11:18

Linked entities

Victim
Mooney Servizi SpA
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack targeted Mooney Servizi SpA, the third-party provider responsible for managing the ATM Milan public transport application, resulting in the unauthorized access and exfiltration of personal data belonging to registered users of the app. The breach originated through an archive hosted by WIIT SpA, where threat actors copied sensitive information to an external, unauthorized cloud storage system. The compromised data included users' personal identification details, contact information, and customer profile data, while no banking information, payment credentials, app access passwords, or home addresses were affected. In response, Mooney Servizi immediately isolated its systems to prevent further unauthorized access, while the transport company launched an in-depth investigation into the security measures employed, strengthened access controls for authorized third-party entities, and formally notified both the national data protection regulator and the national cybersecurity agency of the incident.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On Saturday evening, April 5, 2025, Mooney Servizi SpA, the company responsible for managing the ATM (Azienda Trasporti Milanesi) mobile application on behalf of the Milan public transport operator, communicated to ATM that it had suffered a cyberattack. Mooney Servizi SpA operates as the data processor for the personal information of users registered to the ATM app, meaning it handles user data on ATM's behalf. Upon discovering the intrusion, the company promptly isolated its own systems in order to protect them against any further unauthorized access attempts, a containment action taken immediately after the incident was identified.

The attack targeted an archive hosted by WIIT SpA, a third-party infrastructure provider. This archive contained the data of client companies of Mooney Servizi and its MyCicero service, including the personal data belonging to users of the ATM application. According to the available information, the attacker was able to copy the data through an unauthorized archiving system, specifically an external cloud location not sanctioned by the data owners. This method of data exfiltration involved the transfer of stored personal information to an external cloud environment controlled by the attacker, rather than a direct compromise of credentials or payment systems. The breach therefore affected data held by a managed service provider and was executed by leveraging access to an archival system to duplicate sensitive information outside the organization's authorized infrastructure.

The personal data violated in this incident consisted of anagraphic data (general identification information such as name and personal details), contact data, and customer profile data belonging to users registered to the ATM app. Importantly, the available information explicitly states that no banking data was violated in the attack. Specifically, there was no compromise of credit cards, debit cards (bancomat), or other digital payment systems. Furthermore, the incident did not involve the compromise of application access credentials, nor were home or residential addresses exposed as part of the breach. The scope of the data exposed was therefore limited to identifying, contact, and profile information rather than financial or authentication data.

The risks stemming from the violation center on the loss of confidentiality of the affected personal data, with the possibility that this information could be disclosed or used in an unauthorized manner. As ATM is the data controller for the personal information of its application users, and Mooney Servizi SpA operates as the data processor, the responsibility for managing the relationship with the affected users and coordinating the response falls within this controller-processor framework. The exposure of anagraphic, contact, and profile data creates a risk of identity-related misuse, unsolicited contact, or profiling based on the exfiltrated information, even though the absence of financial credentials and authentication data limits the immediate financial impact.

In response to the incident, ATM activated a series of countermeasures without delay in order to protect its customers and the organization itself. The company requested from Mooney Servizi SpA an updated and detailed reporting on all the security measures undertaken to respond to the attack, signaling an ongoing investigative and audit process directed at the processor. In terms of mitigation, ATM strengthened the security of access to its own systems by authorized third parties, addressing the vector through which the processor relationship might have contributed to the incident. Additionally, ATM notified the event to the Garante per la Protezione dei Dati Personali (the Italian Data Protection Authority) and to the Agenzia per la Cybersicurezza Nazionale (the National Cybersecurity Agency), fulfilling the formal regulatory and governmental reporting obligations associated with a personal data breach in Italy. The chronology of the incident therefore extends from the initial compromise and detection on the evening of April 5, 2025, through the immediate isolation of Mooney Servizi's systems, to the subsequent coordinated response involving the data controller ATM, the processor Mooney Servizi SpA, the hosting provider WIIT SpA, and the relevant Italian supervisory and cybersecurity authorities.

Sources

Sources available to members: 1 source.

CSIDB