s
RansomNews

ransomNews

Cut through the noise.
The cyber threat landscape moves fast. We move faster.
Deep analysis, sharp intelligence - delivered by the ransomNews team.

learn more about us

🇮🇹 RedACT NOW

👉🏻 we moved our Italian only dashboard to GitHub, check it NOW!

🇮🇹 Italian
Threat Landscape

since january 2026

Since January 2026, Italy has recorded 148 verified ransomware claims, with 13,200.22 GB of confirmed exfiltrated data.

The most active threat actors so far are Qilin and LockBit5, both responsible for 21 claims, followed by TheGentlemen with 16.

The manufacturing sector remains the primary target with 60 victims, ahead of transportation and commerce, both recording 17 incidents during 2026.

Most active groups in 2026

scenario

Geographically, Lombardy remains the most targeted region with 45 verified victims, followed by Emilia-Romagna (17) and Veneto (14).

Together, these three regions account for the largest share of publicly claimed ransomware incidents in Italy during 2026.

Initial access continues to rely primarily on spear phishing, supply chain compromises, credential stealing, and credential stuffing.

Attackers are exploiting trusted relationships and compromised identities rather than relying solely on software vulnerabilities.

1504
Ransomware victims
Italy, 2026
62
Active groups
world, 2026
26
Italian claims
June, 2026
13
Total claims
Italy, since 2020
ransomNews RedACT Italy 2026 H1

Exfiltrated data comparison
2025–2026, Italy

This comparison highlights the volume of data exfiltrated and publicly released by ransomware threat actors across 2025 and mid 2026, providing a perspective on how the scale of exposed information has evolved over time.

2024 (31,142.25 GB) already represented a significant level of activity and marked a clear escalation compared to 2025, both in the number of incidents and in the overall volume of leaked data.

published data in 2025

25.740,97 GB

published data in 2026*

13.405,22


* all 2026 values presented here are based on verified incidents and are updated as of June 30 2026.

Top 5 Threat Actors Italy 2026
  • 1 • Qilin
  • 2 • LockBit5
  • 3 • TheGentlemen
  • 4 • Deadlock
  • 5 • Safepay
Top 5 Regions 2026
  • 1 • Lombardia
  • 2 • Emilia Romagna
  • 3 • Veneto
  • 4 • Piemonte
  • 5 • Lazio
Top 5 Sectors 2026
  • 1 • Manufacturing
  • 2 • Logistics & Transportation
  • 3 • Retail & Wholesale
  • 4 • IT
  • 5 • Professional Services

About ransomNews

watchdogs in the age of digital warfare

real data. real threats.


ransomNews is an independent observatory dedicated to tracking and analyzing global ransomware activity. We monitor cyber extortion claims across the world, verify each incident manually, and compile clear, data-driven insights with a sharp focus on Italy.

Every six month, we publish RedACT, in-depth report to inform, educate, and raise awareness - empowering businesses, institutions, and individuals to better understand the evolving ransomware landscape.

Our mission: to turn raw data into actionable knowledge, making cybersecurity a shared responsibility.

2026, RedACT H1

What we do

ransomware disclosure, activity tracking & more

Ransomware Events Tracking

We monitor ransomware claims published by threat actors, verify their credibility, and enrich the data to provide structured intelligence on global ransomware activity.

Reports and Insights

We compile RedACT and RedACTinsights, free resources offering rigorously verified, data-driven reporting on ransomware activity and threat actors.

Open Source Threat Intel

We conduct deep OSINT and SOCMINT investigations to extract, verify, and contextualize threat actor claims and more.

Technical Data Support

We support organizations and institutions with tailored ransomware intelligence reports, sector-specific and data-driven.

Threat Landscape Briefings

We deliver curated threat landscape briefings, sector-specific, timely, and actionable, relevant to any organization.

Awareness

We raise awareness around invisible exposure: how our digital habits, overlooked traces, and public signals can silently map our vulnerabilities.

Where our data Speak

From global stages to specialized forums, our insights power the conversation

CyberAct Forum
Viterbo, Italy
ForumPA
Rome, Italy
Public Sector Stakeholders
Italy, Switzerland, Estonia
Private Consulting
Italy, Switzerland, Estonia

The Team

behind the firewall

follow us

FOLLOW US

Every alert starts with messy data.
We dig through claims, leaks, and fragments, verify what’s real, and connect the dots so the picture makes sense.

Follow us for real-time ransomware news, emerging threat groups, critical vulnerabilities, and the signals that often get missed.
Cybersecurity awareness isn’t noise. It’s knowing what actually matters.