ransomNews
Cut through the noise.
The cyber threat landscape moves fast. We move faster.
Deep analysis, sharp intelligence - delivered by the ransomNews team.
s
Since January 2026, Italy has recorded 148 verified ransomware claims, with 13,200.22 GB of confirmed exfiltrated data.
The most active threat actors so far are Qilin and LockBit5, both responsible for 21 claims, followed by TheGentlemen with 16.
The manufacturing sector remains the primary target with 60 victims, ahead of transportation and commerce, both recording 17 incidents during 2026.
Geographically, Lombardy remains the most targeted region with 45 verified victims, followed by Emilia-Romagna (17) and Veneto (14).
Together, these three regions account for the largest share of publicly claimed ransomware incidents in Italy during 2026.
Initial access continues to rely primarily on spear phishing, supply chain compromises, credential stealing, and credential stuffing.
Attackers are exploiting trusted relationships and compromised identities rather than relying solely on software vulnerabilities.
ransomNews is an independent observatory dedicated to tracking and analyzing global ransomware activity. We monitor cyber extortion claims across the world, verify each incident manually, and compile clear, data-driven insights with a sharp focus on Italy.
Every six month, we publish RedACT, in-depth report to inform, educate, and raise awareness - empowering businesses, institutions, and individuals to better understand the evolving ransomware landscape.
Our mission: to turn raw data into actionable knowledge, making cybersecurity a shared responsibility.
2026, RedACT H1
We monitor ransomware claims published by threat actors, verify their credibility, and enrich the data to provide structured intelligence on global ransomware activity.
We compile RedACT and RedACTinsights, free resources offering rigorously verified, data-driven reporting on ransomware activity and threat actors.
We support organizations and institutions with tailored ransomware intelligence reports, sector-specific and data-driven.
We deliver curated threat landscape briefings, sector-specific, timely, and actionable, relevant to any organization.
Every alert starts with messy data.
We dig through claims, leaks, and fragments, verify what’s real, and connect the dots so the picture makes sense.
Follow us for real-time ransomware news, emerging threat groups, critical vulnerabilities, and the signals that often get missed.
Cybersecurity awareness isn’t noise. It’s knowing what actually matters.
Awareness
We raise awareness around invisible exposure: how our digital habits, overlooked traces, and public signals can silently map our vulnerabilities.