Italy’s Ministry of Foreign Affairs said its protection systems mitigated a cyberattack against its website without service disruption. The ministry is coordinating with the Polo Strategico Nazionale and competent authorities, while analysts check Italian embassy and consulate websites for similar attempts. Official statements also described fresh attack attempts against the ministry’s website and national infrastructure, but did not identify the perpetrators or attack type.
Security Affairs reported that a DDoSia target list included the ministry, five Italian embassies, the Toronto consulate, other government services, and Italian organizations. That listing raises concern about coordinated denial-of-service activity but does not establish successful attacks against every target or confirm attribution. No intrusion, data theft, broader compromise, or diversionary operation has been established. Italy plans to work with Romania and other EU member states on proposals to designate actors responsible for cyberattacks; defenders should prioritize availability monitoring and DDoS readiness while investigating any separate signs of compromise.

See the actors and campaigns active against you right now.
14 events from the most recent confirmed update back to the earliest known activity.
A DDoSia target list shared on October 8, 2026, named the Foreign Ministry, five Italian embassy websites, the Toronto consulate, Interior and Defence Ministry services, and other Italian organizations. The list established planned targeting, not successful attacks or compromise of every listed website.
On the morning of October 8, 2026, Italy’s Foreign Ministry announced that its website was under cyberattack but that protection systems had prevented service disruption. The ministry did not identify the attacker or attack type, and the reporting said nobody had claimed responsibility.
According to Infosecurity Magazine, NoName057(16) linked a February 2025 attack wave to a speech by Italian President Sergio Mattarella.
On the Sunday of the same January 2025 weekend, NoName057(16) targeted Intesa, Monte dei Paschi di Siena, and the ports of Taranto and Trieste.
During a January 2025 weekend coinciding with Volodymyr Zelensky’s visit to Rome, NoName057(16) attacked Italian ministries and government websites on Saturday.
ANSA reported that Russian hackers took the Italian Foreign Ministry’s website offline in late December 2024. Foreign Minister Antonio Tajani said service was restored the following day.
NoName057(16) targeted Italy’s Malpensa and Linate airports at the end of December 2024.
Avast researchers observed NoName057(16) using the Bobik botnet for distributed denial-of-service attacks as early as September 2022.
The pro-Russian group NoName057(16) publicly emerged, announcing targets through Telegram. The group was subsequently linked to the crowdsourced DDoSia operation.
The Guardian reported that Italy’s Foreign Ministry had experienced a months-long intrusion. Italian media said ministry and embassy staff email accounts were targeted, rather than the encrypted system for sensitive communications; the Kremlin denied involvement.
The ministry coordinated incident monitoring with Polo Strategico Nazionale and competent authorities. Analysts checked Italian embassy and consulate websites abroad for similar attack attempts.
During a recent visit to Rome by German Foreign Minister Johann Wadephul, Tajani demonstrated the technical capabilities of the Foreign Ministry’s CSIRT Operations Room.
Tajani said the ministry had strengthened threat prevention, monitoring, response capabilities, and technological countermeasures in recent months.
Tajani said an approved Foreign Ministry reform made cybersecurity a central priority. The sources describe approval as occurring the previous year without providing an absolute date.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
4 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcesecurityaffairs.com
Open sourceesteri.it
Open sourceesteri.it
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.