Ethical Hacking News
Italian organizations are facing a surge in ransomware attacks, with LockBit5 and Qilin being the most active groups. The manufacturing sector has been particularly targeted, accounting for nearly 40% of all claims made during the first half of 2026.
The first half of 2026 saw a surge in ransomware attacks on Italian organizations, with 148 confirmed claims recorded. The manufacturing sector was the most targeted, accounting for 59 victims (39.9% of total claims), due to its reliance on proprietary designs and operational technology. LockBit5 and Qilin were the most active groups, claiming 21 victims each, exploiting reused credentials, unpatched systems, and RDP left exposed. The attacks were concentrated in Northwest Italy (42.6% of total claims), with Lombardy accounting for 45 victims alone.
In a stark reminder of the ongoing threat landscape, Italian organizations have been relentlessly targeted by two prominent ransomware groups, LockBit5 and Qilin, in the first half of 2026. According to a recent report compiled by ransomNews under its RedACT project, a total of 148 confirmed ransomware claims against Italian targets were recorded during this period, with an average of 24.7 claims per month or 5.7 per week.
The manufacturing sector emerged as the most targeted sector, accounting for 59 victims, which is approximately 39.9% of the total dataset. This sector's susceptibility to ransomware attacks can be attributed to its reliance on proprietary designs and operational technology that are often difficult to patch without disrupting critical operations. Furthermore, the close-to-zero tolerance for downtime in manufacturing environments makes paying up look relatively inexpensive compared to the potential consequences of downtime.
LockBit5 and Qilin dominated the leaderboard, with each group claiming 21 victims, respectively. While these two groups operate differently, they share a common goal: to extort money from organizations by exfiltrating sensitive data. The attackers' modus operandi often involves exploiting reused credentials pulled from old breaches and dark web dumps, unpatched public-facing systems, and RDP left exposed.
The geographic distribution of the attacks reveals that Northwest Italy is the most affected region, with 63 victims (42.6%), followed by Northeast Italy with 36 victims, Central Italy with 30 victims, Southern Italy with 13 victims, and the Islands with only 5 victims. The industrial north of Italy appears to be a hotbed for ransomware activity, with Lombardy alone accounting for 45 victims.
The report's findings are consistent with those of Italy's cybersecurity agency ACN, which has also observed an increase in cyber events in June compared to May, with pressure concentrated on smaller, lower-resilience organizations. This trend highlights the importance of implementing robust security measures and staying vigilant against potential threats.
In conclusion, the LockBit5 and Qilin ransomware campaigns demonstrate the ongoing threat landscape in Italy and beyond. As manufacturing continues to be a prime target, it is essential for organizations to prioritize their cybersecurity posture and stay proactive in defending against such attacks.
Italian organizations are facing a surge in ransomware attacks, with LockBit5 and Qilin being the most active groups. The manufacturing sector has been particularly targeted, accounting for nearly 40% of all claims made during the first half of 2026.
Related Information:
https://www.ethicalhackingnews.com/articles/Italian-Organizations-Under-Siege-LockBit5-and-Qilins-Rampage-Through-Manufacturing-ehn.shtml
https://securityaffairs.com/196045/security/lockbit5-and-qilin-lead-ransomware-attacks-against-italian-organizations.html
Published: Mon Jul 27 02:24:36 2026 by llama3.2 3B Q4_K_M