SYS::ONLINE
Wasteland.
Briefs1714
Issues22
SinceFeb 2026
LIVE
█ Ransomware RETELIT-QILIN-RANS 2026-08-05

Retelit: Qilin Ransomware Data Leak

"Qilin has published roughly 300 gigabytes of data it says was stolen from Retelit SpA, an Italian telecommunications and cloud operator whose customer base reportedly includes 193 public administrations, three digital…"

Qilin has published roughly 300 gigabytes of data it says was stolen from Retelit SpA, an Italian telecommunications and cloud operator whose customer base reportedly includes 193 public administrations, three digital identity providers and defence group Leonardo. The claim was first indexed on Qilin's leak site on 11 July 2026 (Dark Eye, Dark Web Informer) and was reported in detail on 4 August 2026 by IrpiMedia, whose investigation is relayed in full by the account at pasqualepillitteri.it. That reporting puts the compromise in the first days of June 2026 and says Retelit had made no public statement about it nearly two months later. Retelit has neither confirmed nor denied the reconstruction, and every figure below sits on either attacker-published material or single-source reporting the company has not validated.

What Happened

The load-bearing account is the IrpiMedia investigation, built from sources consulted by the outlet and from documents the attackers themselves published. It states that Retelit suffered a cyberattack claimed by the Qilin ransomware group and that at least 300 GB of internal documents, spread across roughly 270,000 files, were exfiltrated. The intrusion was identified, per that reconstruction, in the first days of June 2026. When contacted, the company did not provide an immediate comment.

The leak-site side of the story is thinner but independently datestamped. Dark Web Informer's ransomware recap for 11 July 2026 lists Retelit SpA PIVA as one of four Qilin victims named that day, in a 24-hour period totalling 34 claims across five groups and 18 countries. Dark Eye's victim record carries the same 11 July publication date, tags the victim as Italian telecommunications with 101 to 1,000 employees, and shows proof-of-breach screenshots posted by the operator with filenames including file_tree.png, finance_2024.xlsx, passport_scan.jpg and contract_signed.pdf.

The timeline does not fully reconcile across sources, and readers should treat it as unsettled. IrpiMedia places discovery in early June with silence running to early August. Dark Eye's tracker records a publication date of 11 July 2026 but a "Disclosed / Notified" date of 25 April 2026, producing a negative 77-day exposure window, a value that reads as a data-quality artefact rather than evidence of an earlier disclosure. No source produces a Retelit statement, a regulator filing or a CERT advisory naming the company.

Bismark.it, reporting the leak-site listing from Italian monitoring circuits, was explicit that the claim was not officially confirmed by the company at the time of writing, and framed the impact conditionally. Intelfusions applies the same caveat at the category level: these are unverified extortion claims posted to pressure payment, some listings recycle earlier attacks, and some victims dispute them.

What Was Taken

Volume figures are consistent where they exist and absent everywhere else. The 300 GB and roughly 270,000 file counts come from IrpiMedia via S1 and are not corroborated by a second reporting outlet; the leak-site trackers list the victim without publishing a byte count (Dark Eye's attack summary field is empty). No source gives a record count, a customer-data count or a breakdown of affected public administrations, so any number circulating in those terms is not supported here.

On content, the only direct evidence is Qilin's own sample gallery indexed by Dark Eye: a directory tree, a 2024 finance spreadsheet, a passport scan and a signed contract. That mix points at internal corporate documents, commercial agreements and at least some identity documents rather than a bulk subscriber database, but four thumbnails are a sample, not an inventory. IrpiMedia characterises the haul as internal documents. Whether customer-side data belonging to the 193 public bodies, the digital identity providers or Leonardo sits inside the 300 GB is not established by any source available here.

Why It Matters

Retelit's significance is structural rather than reputational. Per the IrpiMedia account, the company runs more than 35 data centres in Italy and roughly 47,000 km of fibre, serves about 65,000 customers, and co-owns a submarine cable of roughly 25,000 km linking Bari to Myanmar, Marseille, Kenya, India and Oman. Bismark.it gives a slightly different infrastructure count, 38 data centres against the same 47,000 km of fibre, and adds that the group is targeting around 500 million euro in annual revenue after recent acquisitions. The data-centre figures differ by source; the fibre figure does not.

The regulatory weight comes from one specific credential. Retelit holds an ACN qualification for multi-cloud services intended for the public administration covering the 2025 to 2028 period. A supplier qualified by the national cybersecurity agency to serve public bodies, hit by data exfiltration that has not been publicly disclosed, is precisely the scenario NIS2 and GDPR notification regimes were drafted around. NIS2 imposes early-warning obligations measured in hours and follow-up reporting in days for essential entities in the electronic communications sector; GDPR Article 33 sets a 72-hour clock to the supervisory authority where personal data is involved, and the passport scan in the leak sample makes personal data at least plausible. Whether Retelit notified ACN, the Garante or its customers privately is unknown: none of the sources here establishes either notification or its absence, only the absence of public statement. That distinction matters, because private regulatory notification and public silence can lawfully coexist.

For downstream customers, the practical problem is that the entity best placed to tell 193 public bodies what was taken has said nothing publicly, while the attacker has published 300 GB anyone can index.

The Attack Technique

No source attributes the Retelit intrusion to a specific initial access vector. What follows is Qilin tradecraft context from the same reporting window, not a causal claim about this victim.

Arctic Wolf Labs reported in July 2026 that multiple Qilin affiliates are exploiting CVE-2026-0257, an authentication bypass in the Palo Alto Networks PAN-OS GlobalProtect portal and gateway, to gain initial access and then deploy Qilin ransomware across entire Windows domains. Security Affairs, covering that research on 21 July 2026, records the patch timeline: Palo Alto Networks fixed the flaw on 13 May 2026, Rapid7 confirmed active exploitation across multiple customer environments about two weeks later, and CISA added it to the Known Exploited Vulnerabilities catalog in early June 2026. Panorama and Cloud NGFW deployments are not affected.

On mechanism, Today In Cyber's aggregated write-up describes exploitation running since approximately 17 May 2026 and attributes it to a misconfiguration in which the certificate used to sign authentication override cookies was also used for the GlobalProtect HTTPS service, letting unauthenticated attackers forge override cookies and stand up unauthorised VPN sessions. That mechanical detail comes from an aggregator rather than the vendor text available here, so treat it as reported rather than confirmed.

The overlap worth noting is temporal, not evidentiary: the exploitation wave and the CISA KEV listing fall in the same window as the reported early-June compromise at Retelit. That is a hypothesis for investigators, not a finding.

Qilin itself, formerly Agenda, is a Russian-speaking ransomware-as-a-service operation active since 2022, running a Rust and Go encryptor under a double-extortion model. Intelfusions counted 31 Qilin victims named in a single week across 15 countries and roughly a dozen industries, 19 of them in three days, and notes the group's growth into one of the highest-volume brands after the LockBit disruption. Its 2024 attack on Synnovis, the pathology provider to London hospitals, forced procedure cancellations and blood rationing.

What Organizations Should Do

  1. Patch CVE-2026-0257 immediately on any PAN-OS GlobalProtect portal or gateway, and treat unpatched internet-facing instances as presumed compromised rather than merely at risk. It is in CISA KEV with confirmed multi-affiliate ransomware use.
  2. Hunt retroactively rather than only patching forward. Review VPN authentication logs from mid-May 2026 onward for sessions that lack a corresponding successful primary authentication event, for override-cookie-authenticated sessions, and for VPN logins from unusual ASNs or geographies followed by rapid internal enumeration.
  3. Rotate the certificates used by GlobalProtect, and verify that the certificate signing authentication override cookies is not the same one serving the HTTPS interface. Certificate reuse is the reported root of the forgery.
  4. If you are a Retelit customer, especially a public administration or an identity provider, request in writing a scoped statement on whether your data appears in the exfiltrated set, and set your own notification clocks running on the assumption that you may be a controller with independent GDPR obligations. Do not wait for the supplier's public position.
  5. Inventory which of your suppliers hold ACN or equivalent public-sector cloud qualifications, and confirm the incident notification terms in those contracts actually bind the supplier to tell you inside NIS2 timeframes. A qualification is a procurement credential, not a disclosure guarantee.
  6. Monitor Qilin's leak site and credible trackers for your own organisation's documents appearing inside a supplier's dump. Third-party data in a first-party leak is one of the most common ways an organisation learns it has been breached at all.
  7. Treat leak-site listings as leads, not verdicts. Trackers disagree on dates in this case, samples are curated by the attacker, and volume claims originate with the extortionist. Corroborate before acting on the numbers.

Sources: Retelit: 300 GB Leaked by Qilin, Two Months of Silence | Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorize... | Retelit SpA PIVA — QILIN Ransomware Attack Dark Eye | 🏴‍☠️ Qilin has just published a new victim : Retelit SpA PIVA Toda... | Retelit nel mirino del ransomware Qilin: colpito uno dei principali... | Qilin ransomware claims 31 victims in a week across 15 countries | Ransomware Attack Update - July 11th, 2026 | Cookie Crumbles: How Exploitation of CVE-2026-0257 ...