Italy's Ministry of Foreign Affairs and International Cooperation (the Farnesina) said its public website had been under cyberattack since the morning of 8 October 2026. In its official press release, the ministry said its security systems had "effectively mitigated" the attack "without causing any disruption to services." The ministry has not said who is responsible or what kind of attack it was. Italian news agencies, as reported by Euronews, European Pulse and Il Sole 24 Ore, attribute the activity to the pro-Russian hacktivist collective NoName057(16) and describe it as a distributed denial-of-service (DDoS) attack. Neither the ministry nor Reuters has confirmed either claim. No data loss has been reported.
What Happened
According to the ministry's statement, which was published on esteri.it and distributed via Public at 09:14 on 8 October, the attack began that morning. The ministry says it is monitoring the situation together with the National Strategic Hub (Polo Strategico Nazionale, Italy's national government cloud) and "in coordination with the relevant authorities." Reuters, via The Straits Times, reported the same facts and noted that the ministry "did not name any suspects."
The ministry also said analysts are checking the websites of Italian embassies and consulates abroad "for any similar attempts." Euronews and European Pulse describe these checks as following "a suspected similar cyberattack by pro-Russian hackers" on mission sites. The ministry's own wording is more cautious and does not confirm that any mission site was hit.
Il Sole 24 Ore adds several details that the ministry has not confirmed:
- Italy's National Cybersecurity Agency (ACN) detected the attack and alerted the ministry.
- The Rome Public Prosecutor's Office is involved. The paper's own reporting is inconsistent on this point: its subheading says prosecutors are "awaiting the filing of a report," while the article body says an investigation "has been launched." The investigation's formal status is therefore unclear.
- The attack followed public criticism of Foreign Minister Antonio Tajani by Russian foreign ministry spokesperson Maria Zakharova. Tajani had warned about possible Russian interference in Italy's upcoming parliamentary elections. Il Sole 24 Ore calls the timing "suspicious" and argues there is a link. That is the paper's own analysis, not an official finding.
Euronews and European Pulse report that Italy's cybercrime police (Polizia Postale) spent 8 October responding to the incident.
The ministry's statement ended with a policy step. Italy will work with Romania and other EU member states to put forward proposals at upcoming European meetings "to designate those responsible for cyber-attacks, including those targeting Italian institutions." Tajani said he had recently shown the ministry's CSIRT Operations Centre to German Foreign Minister Johann Wadephul during Wadephul's visit to Rome.
What Was Taken
No source reports any data theft, unauthorised access or compromise of internal systems. Every account describes an attack on the availability of a public-facing website, and the ministry says that attack was mitigated. If the DDoS reports are accurate, that fits: DDoS attacks overload services but do not normally involve stealing data.
The ministry's English headline refers to "fresh attempts at cyber-attacks on its website and national infrastructure." The word "fresh" suggests earlier attempts, and "national infrastructure" suggests a wider scope than the website. The body of the release does not explain either point. Readers should not assume anything beyond the website and the mission-site checks unless the ministry says more.
Why It Matters
- Hacktivist pressure tied to political events. NoName057(16) has a long record of DDoS campaigns against European government and media sites. European Pulse notes that its targets often follow political decisions it sees as anti-Russian. If the attribution holds, this attack fits that pattern: a short-lived, symbolic disruption campaign timed to a diplomatic dispute. Il Sole 24 Ore calls the group's attacks "merely symbolic actions."
- Elections raise the risk. With Italian parliamentary elections coming up and a public row with Moscow over interference, Italian public-sector, media and electoral-adjacent websites should expect more attempts like this in the coming weeks.
- Diplomatic missions widen the attack surface. The ministry is checking embassy and consulate sites, which shows that a ministry's attack surface includes dozens of overseas web properties. These may be hosted, patched and protected differently from the main site.
- Italy is moving toward attribution. The Italy–Romania initiative to name cyber attackers at EU level suggests Rome wants a more formal, coordinated attribution process. That could feed into future EU cyber-sanctions decisions.
- Earlier enforcement has not stopped the group. Il Sole 24 Ore notes Operation Eastwood, the multinational law-enforcement action against NoName057(16) across 14 European countries. If the group is behind this attack, that operation slowed its activity but did not end it.
The Attack Technique
Officially, the attack type is undisclosed. The ministry's statement does not describe the method.
Euronews and European Pulse, citing "initial reports" from Italian news agencies, describe a DDoS attack that floods the website with fake requests to overwhelm it. Il Sole 24 Ore also links the incident to NoName057(16)'s DDoS operations. NoName057(16) is known for:
- Using a volunteer-driven DDoS tool (historically "DDoSia") that turns participants' machines into a botnet.
- Focusing on application-layer (Layer 7) HTTP floods against specific URLs, often search pages or other resource-heavy endpoints, rather than raw volumetric floods.
- Announcing targets and posting "proof" screenshots on Telegram, even when the target stays online.
The ministry says there was no disruption. That suggests upstream scrubbing, CDN or WAF rate limiting, or protections at the hosting layer (the ministry mentions the National Strategic Hub) absorbed the traffic. Until the ministry or ACN publishes technical details, treat the DDoS characterisation and the NoName057(16) attribution as credible but unconfirmed.
What Organizations Should Do
- Put critical public sites behind DDoS protection with Layer 7 controls. Use a CDN or scrubbing provider with WAF rate limiting, bot management and challenge pages. Make sure origin IPs are not publicly exposed so attackers cannot bypass the protection.
- Protect resource-heavy endpoints. Find pages that trigger database queries, such as search, filters and form handlers. Cache, rate-limit or require challenges on them, since hacktivist HTTP floods tend to target exactly these pages.
- Inventory and harden satellite web properties. Embassy, branch, regional and campaign sites often sit outside central protection. Bring them under the same DDoS and WAF coverage, or at least monitor them for availability.
- Monitor hacktivist channels during politically sensitive periods. Track NoName057(16) and similar groups' Telegram target lists ahead of elections, diplomatic disputes and policy announcements, so you can raise mitigation thresholds before an attack starts.
- Rehearse the DDoS playbook and the public message. Pre-agree escalation paths with your ISP, CDN and national CERT. Have a holding statement ready: the ministry's quick "mitigated, no disruption" message limited the reputational benefit the attackers were after.
- Check that availability attacks are not hiding something else. Review authentication, admin-panel and WAF logs during and after the attack, in case the noise was covering credential-stuffing or exploitation attempts.
Sources: Italy's foreign ministry website under cyberattack | Italy foreign ministry says it has come under cyber attack The Str... | Italian Foreign Ministry under cyber-attack following Moscow’s accu... | Pro-Russian hackers target Italian foreign ministry in DDoS attack... | Italy’s Foreign Ministry Under Cyberattack as Embassy Sites Come Un... | The Ministry of Foreign Affairs has fended off fresh attempts at ... | Pro-Russian hacker group NoName targets Italian Foreign Ministry we... | Ministero degli Affari Esteri e della... (via Public) / The Ministr...