CSIDB logo
Incident

Municipio di Rho

Incident posture

Attack window
Mar 2021
Location
Italy
Status
Historical
CIA posture
Available to members
Updated
2025-10-25 00:00

Linked entities

Victim
Municipio di Rho
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Mar 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Municipality of Rho suffered a cyberattack by unknown threat actors that damaged its network and disrupted normal services, including those provided by Quic – Sportello del Cittadino. Despite active antivirus and security systems, the incident prevented service continuity, prompting technicians to work on restoring technological operations while authorities prepared a formal complaint. The attack occurred alongside a similar incident affecting another municipality, though no shared infrastructure or attribution details were confirmed in available reports.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The Municipality of Rho experienced a disruptive cyberattack first detected on or around March 30, 2021, coinciding with a similar incident affecting the Municipality of Brescia. Unknown threat actors compromised Rho's network infrastructure, causing significant operational damage that prevented the delivery of standard municipal services. Critical citizen-facing platforms, including the Quic – Sportello del Cittadino (Citizen's Desk) portal, became unavailable due to the attack. Municipal authorities confirmed the breach through an official notice published on April 1, emphasizing that existing antivirus and cybersecurity systems failed to prevent the intrusion. Service disruptions persisted through the Easter holiday period, with technicians urgently working to restore technological systems and online procedures. The municipality planned to file formal complaints with law enforcement agencies but did not publicly identify suspects during the initial response phase.

Technical recovery efforts focused on repairing damaged network components and restoring full operational capacity to affected systems. While the Brescia attack was later attributed to DoppelPaymer ransomware operators using Cryptolocker malware, Rho's incident documentation did not explicitly confirm the same threat actor or malware variant. Both municipalities issued nearly identical public statements regarding attack timelines, operational impacts, and response measures, though no evidence confirmed shared IT infrastructure between them. The Rho attack notably impaired digital citizen services during a holiday period when administrative closures could compound delays. No data theft or financial demands were disclosed in available reports, with damage primarily characterized as network disruption requiring reconstruction. Restoration timelines remained contingent on technical remediation progress rather than predetermined deadlines.

Sources

Sources available to members: 1 source.

CSIDB