CSIDB logo
Incident

Comune di Torre del Greco

Incident posture

Attack window
Nov 2022
Location
Italy
Status
Historical
CIA posture
Available to members
Updated
2026-03-09 07:24

Linked entities

Victim
Comune di Torre del Greco
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Nov 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The municipality of Torre del Greco suffered a ransomware attack where hackers demanded €200,000 to restore access to compromised data, prompting the immediate suspension of municipal office operations. Mayor Giovanni Palomba publicly denounced the incident, refusing any illicit negotiations while collaborating with the Postal Police and judicial authorities to address the breach. The attack caused significant disruption to local administrative services, with officials urging citizen cooperation during the crisis.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On November 16, 2022, the municipality of Torre del Greco, Italy, suffered a cyberattack involving unauthorized access to its computer systems. Attackers compromised municipal data and subsequently issued a ransom demand of 200,000 euros for the restoration of access to the encrypted or stolen information. Mayor Giovanni Palomba publicly disclosed the incident on November 17, confirming the extortion attempt and characterizing the event as an extremely serious breach. The attack prompted immediate operational disruptions, with municipal offices suspending all administrative activities to contain the incident and prevent further system compromise. Authorities initiated a criminal investigation coordinated with the Postal Police to identify the perpetrators.

The municipal administration categorically refused to engage with the attackers' financial demands, ruling out any illicit negotiation. Mayor Palomba emphasized full cooperation with law enforcement agencies while urging citizens to exercise patience during service interruptions caused by the attack. No technical details regarding the attack vector, specific compromised systems, or data types were disclosed publicly. The municipality filed formal legal complaints with judicial authorities to pursue criminal charges against the responsible parties. Recovery efforts and forensic analysis proceeded under law enforcement supervision, though no timeline for full operational restoration was provided in initial reports.

Sources

Sources available to members: 2 sources.

CSIDB