Menu
Browse

Cyber Incident Victim: Ferrovie dello Stato Italiane

Date:

Mar 2022

Location:

Italy

Summary

Ferrovie dello Stato Italiane temporarily suspended ticket sales at physical offices and self-service machines following detection of a suspected cryptolocker infection on its computer network. Online ticket services remained operational, and rail traffic was unaffected by the disruption. Security sources speculated about potential involvement by Russian hackers, though authorities did not confirm this attribution. The company initiated precautionary network checks in response to the incident while maintaining normal train operations across its extensive rail network.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On March 23, 2022, Ferrovie dello Stato Italiane (FS), Italy's state-controlled railway operator, announced it had temporarily suspended ticket sales at physical offices and self-service machines in train stations due to suspected cyber activity. The company detected anomalies on the computer networks of its passenger service subsidiary Trenitalia and infrastructure manager RFI that morning, with initial analysis suggesting possible indicators of a cryptolocker infection—a type of ransomware that encrypts data and demands payment for decryption. FS initiated immediate network diagnostics to assess the scope and origin of the incident but did not confirm whether data encryption or ransom demands had occurred. As a precautionary containment measure, the company halted all point-of-sale transactions at station counters and automated kiosks while maintaining normal online ticket sales through digital channels. Rail operations across the national network, including high-speed services spanning over 16,700 kilometers, continued uninterrupted with no reported delays or safety impacts.

Cyber Incident Image

The disruption exclusively affected ground-based ticketing systems, causing localized inconvenience to passengers purchasing fares through physical channels. FS emphasized the preventive nature of the sales suspension, stating no operational technology controlling trains or signaling infrastructure was compromised. Italian news agency Ansa cited unidentified security sources speculating about potential Russian hacker involvement based on the attack's characteristics, though neither FS nor the Italian Interior Ministry verified this attribution when contacted by Reuters. The company provided no additional details regarding infection vectors, data exfiltration, or remediation timelines beyond confirming ongoing network analysis. No ransomware group claimed responsibility for the incident publicly during the initial disclosure period.

Sources
Sources available to members
1 source