Cyber & AI intelligence
Wasteland.
Briefs indexed3096
Issues31
Published Mondays07:30 CT
▣ Breach ITALY-FOREIGN-MINI 2026-10-09

Italy's Foreign Ministry: Website Targeted in Suspected Pro-Russian DDoS Attack

"Italy's Ministry of Foreign Affairs and International Cooperation (the Farnesina) said its public website had been under cyberattack since the morning of 8 October 2026. In its official press release, the ministry said…"

Italy's Ministry of Foreign Affairs and International Cooperation (the Farnesina) said its public website had been under cyberattack since the morning of 8 October 2026. In its official press release, the ministry said its security systems had "effectively mitigated" the attack "without causing any disruption to services." The ministry has not said who is responsible or what kind of attack it was. Italian news agencies, as reported by Euronews, European Pulse and Il Sole 24 Ore, attribute the activity to the pro-Russian hacktivist collective NoName057(16) and describe it as a distributed denial-of-service (DDoS) attack. Neither the ministry nor Reuters has confirmed either claim. No data loss has been reported.

What Happened

According to the ministry's statement, which was published on esteri.it and distributed via Public at 09:14 on 8 October, the attack began that morning. The ministry says it is monitoring the situation together with the National Strategic Hub (Polo Strategico Nazionale, Italy's national government cloud) and "in coordination with the relevant authorities." Reuters, via The Straits Times, reported the same facts and noted that the ministry "did not name any suspects."

The ministry also said analysts are checking the websites of Italian embassies and consulates abroad "for any similar attempts." Euronews and European Pulse describe these checks as following "a suspected similar cyberattack by pro-Russian hackers" on mission sites. The ministry's own wording is more cautious and does not confirm that any mission site was hit.

Il Sole 24 Ore adds several details that the ministry has not confirmed:

Euronews and European Pulse report that Italy's cybercrime police (Polizia Postale) spent 8 October responding to the incident.

The ministry's statement ended with a policy step. Italy will work with Romania and other EU member states to put forward proposals at upcoming European meetings "to designate those responsible for cyber-attacks, including those targeting Italian institutions." Tajani said he had recently shown the ministry's CSIRT Operations Centre to German Foreign Minister Johann Wadephul during Wadephul's visit to Rome.

What Was Taken

No source reports any data theft, unauthorised access or compromise of internal systems. Every account describes an attack on the availability of a public-facing website, and the ministry says that attack was mitigated. If the DDoS reports are accurate, that fits: DDoS attacks overload services but do not normally involve stealing data.

The ministry's English headline refers to "fresh attempts at cyber-attacks on its website and national infrastructure." The word "fresh" suggests earlier attempts, and "national infrastructure" suggests a wider scope than the website. The body of the release does not explain either point. Readers should not assume anything beyond the website and the mission-site checks unless the ministry says more.

Why It Matters

The Attack Technique

Officially, the attack type is undisclosed. The ministry's statement does not describe the method.

Euronews and European Pulse, citing "initial reports" from Italian news agencies, describe a DDoS attack that floods the website with fake requests to overwhelm it. Il Sole 24 Ore also links the incident to NoName057(16)'s DDoS operations. NoName057(16) is known for:

The ministry says there was no disruption. That suggests upstream scrubbing, CDN or WAF rate limiting, or protections at the hosting layer (the ministry mentions the National Strategic Hub) absorbed the traffic. Until the ministry or ACN publishes technical details, treat the DDoS characterisation and the NoName057(16) attribution as credible but unconfirmed.

What Organizations Should Do

  1. Put critical public sites behind DDoS protection with Layer 7 controls. Use a CDN or scrubbing provider with WAF rate limiting, bot management and challenge pages. Make sure origin IPs are not publicly exposed so attackers cannot bypass the protection.
  2. Protect resource-heavy endpoints. Find pages that trigger database queries, such as search, filters and form handlers. Cache, rate-limit or require challenges on them, since hacktivist HTTP floods tend to target exactly these pages.
  3. Inventory and harden satellite web properties. Embassy, branch, regional and campaign sites often sit outside central protection. Bring them under the same DDoS and WAF coverage, or at least monitor them for availability.
  4. Monitor hacktivist channels during politically sensitive periods. Track NoName057(16) and similar groups' Telegram target lists ahead of elections, diplomatic disputes and policy announcements, so you can raise mitigation thresholds before an attack starts.
  5. Rehearse the DDoS playbook and the public message. Pre-agree escalation paths with your ISP, CDN and national CERT. Have a holding statement ready: the ministry's quick "mitigated, no disruption" message limited the reputational benefit the attackers were after.
  6. Check that availability attacks are not hiding something else. Review authentication, admin-panel and WAF logs during and after the attack, in case the noise was covering credential-stuffing or exploitation attempts.

Sources: Italy's foreign ministry website under cyberattack | Italy foreign ministry says it has come under cyber attack The Str... | Italian Foreign Ministry under cyber-attack following Moscow’s accu... | Pro-Russian hackers target Italian foreign ministry in DDoS attack... | Italy’s Foreign Ministry Under Cyberattack as Embassy Sites Come Un... | The Ministry of Foreign Affairs has fended off fresh attempts at ... | Pro-Russian hacker group NoName targets Italian Foreign Ministry we... | Ministero degli Affari Esteri e della... (via Public) / The Ministr...