Comune di Alcamo
Incident posture
Linked entities
- Victim
- Comune di Alcamo
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
A wave of distributed denial-of-service attacks was launched against multiple Italian public sector websites, temporarily disrupting access to the municipal portal of the targeted local government entity alongside other local government and regional sites. The attack, which overloaded the infrastructure with fraudulent traffic, caused a temporary outage of the municipal website, while the other targeted sites experienced no significant impact. The national cybersecurity agency responded by actively monitoring the situation as the attacks continued against local governments and the transportation sector.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On 1 March 2025, a new wave of distributed denial-of-service attacks targeted the websites of several Italian public administrations, marking a renewed offensive against local government digital infrastructure. The attacks were reported by Adnkronos and covered by Verona Sera, which documented that the wave hit multiple municipal and regional portals across the country on the same day. The most prominent casualty in the reporting was the municipal website of Verona, which suffered its second hacker attack in less than a week. According to the article, the same offensive reached beyond Verona and also struck the websites of the Comuni di Roma, Milano and Catania, together with the official portals of the Regioni Lazio, Piemonte, Puglia and Valle d'Aosta. The article does not provide a specific list of source IP addresses, botnet infrastructure or attribution to any named threat actor, and it confines itself to describing the targets and the technique employed.
Technically, the incidents were characterised as distributed denial-of-service attacks, a method in which attackers attempt to render a target service unreachable by flooding it with a high volume of illegitimate requests from multiple distributed sources. The Verona Sera report explicitly states that the operations were "attacks of the DDoS type, with which the hackers tried to block the functioning of the sites by overloading them with fictitious requests." The same paragraph stresses that, despite the volume of traffic generated against the targeted portals, the consequences were not severe: the article notes that "the attacks nevertheless did not produce serious effects," and that the only immediate, observable impact was that the website of the Comune di Verona was temporarily unreachable. No data theft, defacement, ransomware encryption, or intrusion into back-end systems is described in the available reporting; the visible impact was limited to service availability of the public-facing websites during the attack window.
The Comune di Verona was the most visible target in the Italian press coverage of the day, largely because the 1 March incident followed a previous attack against the same municipal portal less than seven days earlier. Verona Sera frames the 1 March event as "the second time in less than a week" for the Veneto city, indicating a pattern of repeated targeting against the same local administration rather than a one-off opportunistic event. The article does not, however, connect the two Verona attacks to a specific campaign name, nor does it claim that the same actor was responsible for both; it simply notes the temporal proximity and the recurrence of the DDoS technique. Beyond Verona, the reporting groups the affected entities under a single narrative, suggesting that the attackers conducted the operations in parallel against several public-sector targets rather than sequentially.
In response to the renewed wave, the Italian national cybersecurity authority, the Agenzia per la cybersicurezza nazionale, was reported to be active and monitoring the situation. The Verona Sera article states verbatim that "the National Cybersecurity Agency is in any case in action and monitors the situation." The reporting does not describe specific technical countermeasures deployed by individual municipalities, such as upstream scrubbing, rate-limiting, firewall rules or routing changes, nor does it detail the duration of the outages or the exact timestamps at which service was restored. Likewise, there is no mention of law enforcement involvement, formal incident reporting procedures under national regulations, or coordination with CERT-PA, which is the Italian public administration CERT, even though the involvement of the national cybersecurity agency implies a coordinated national-level response.
The broader operational context described in the article places the 1 March wave within an ongoing campaign that also targeted the transport sector on the same day. Verona Sera specifies that the attacks on that date focused on local entities and the transport sector, although the article does not name specific transport operators, airports, or rail companies that were hit. The geographic spread of the listed targets, covering northern regions such as Piemonte and Valle d'Aosta, central administrations including Roma and the Regione Lazio, southern entities such as Catania and the Regione Puglia, alongside Verona in the north-east and Milano in Lombardy, indicates a national-scale operation rather than a regionally confined one. The reporting does not speculate on whether the attacks were politically, ideologically, or financially motivated, and there is no claim of a ransom demand, hacktivist claim of responsibility, or state-level attribution.
Taken together, the documented incident of 1 March 2025 can be summarised as a coordinated, multi-target distributed denial-of-service campaign against Italian public administration websites. The principal confirmed impact was temporary unavailability of the Comune di Verona website, while other listed municipal and regional portals, including those of Roma, Milano, Catania, Lazio, Piemonte, Puglia and Valle d'Aosta, were subjected to the same DDoS activity without reported severe effects. The technical response fell under the monitoring of the Agenzia per la cybersicurezza nazionale, whose role is described in active terms, and the affected administrations appear to have weathered the attack without data loss or service compromise beyond the temporary disruption of public web access. The reporting leaves open the longer-term question of attribution and the total duration of service impairment, but it confirms that the DDoS attempts did not escalate into deeper intrusions during the observed window.
Sources
Sources available to members: 1 source.