CSIDB logo
Incident

Snai

Incident posture

Attack window
Dec 2020
Location
Italy
Status
Historical
CIA posture
Available to members
Updated
2026-01-08 20:46

Linked entities

Victim
Snai
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Dec 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

An Italian gaming operator experienced a ransomware attack disrupting its website and mobile applications, causing prolonged service outages. The company confirmed unauthorized access but asserted user accounts and sensitive data remained uncompromised, though external observers questioned the reliability of such claims given common attacker tactics to conceal breaches. Technical disruptions necessitated extended downtime while incident response efforts were underway.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On December 27, 2020, Snaitech, a major legal gaming operator in Italy, experienced a cyber attack that disrupted its snai.it website and gaming applications. The company confirmed the incident through an official press release issued at 17:25 on December 28, 2020, attributing the disruption to unknown attackers. Technical staff had proactively taken systems offline prior to the attack, indicating early detection of suspicious activity. Snaitech characterized the incident as a ransomware attack but did not disclose specific malware variants or initial intrusion vectors. Service outages persisted beyond initial restoration attempts, suggesting significant infrastructure compromise. The company maintained operational isolation of gaming accounts and user data repositories throughout the incident.

The attack caused sustained malfunctions impacting online betting services for at least two days. Snaitech's press release explicitly stated that user accounts and sensitive data were unaffected by the intrusion, assuring customers no changes or losses would occur to their accounts. Technical teams prioritized containment through system isolation rather than immediate restoration, prolonging service downtime. Independent cybersecurity observers noted the prolonged outage and preventive takedown measures aligned with ransomware attack patterns. Media outlets questioned the reliability of Snaitech's data integrity claims, citing historical precedents where attackers concealed data exfiltration. No threat actor claimed responsibility or published exfiltrated data during the immediate aftermath period.

Sources

Sources available to members: 1 source.

CSIDB