News

Cyber-attacks at +53% in the first six months of 2025. Threat against PA, telecoms and energy explodes

Data from the National Cybersecurity Agency. 1,549 cyber events and 346 major incidents reported. DDoS, data exposure and phishing on the rise. Over 1,900 botnet nodes identified thanks to proactive monitoring by Csirt Italia

2' min read

2' min read

In the first half of 2025, Italy witnessed a surge in cyber events and incidents, according to data just published by the National Cybersecurity Agency (NCA). In the January-June period, 1,549 cyber events were recorded, a 53% increase compared to the same six months of 2024. Of these, 346 were classified as confirmed impact incidents, almost twice as many (+98%) as in the previous year.

The detected increase is partly attributed to the increased detection capacity of the Csirt Italia (Computer Security Incident Response Team), thanks also to the enactment of Law No. 90 and Legislative Decree No. 138 of 2024. However, it is mainly Distributed Denial of Service (DDoS) campaigns, data exposure and phishing that have an impact.

Loading...

Most affected sectors: Pa, telecommunications, healthcare and energy

.

Local and central public administration, together with the telecommunications sector, remain among the main targets of cyber attacks. In April, a wave of spearphishing targeted the Telco sector, while in March, a breach at a web service provider involved several local authorities. The central public sector suffered mainly DDoS attacks and phishing campaigns.

There were 91 ransomware attacks recorded in the six months, virtually stable compared to 92 in 2024. Among the hardest hit victims were universities, the health sector, the energy sector, and digital providers for the PA, with serious incidents disrupting operations and causing ripple effects in February.

DDoS and pro-Russian campaigns: 77% more attacks

DDoS attacks increased by 77 per cent from 336 in the first half of 2024 to 598 in 2025. The campaign conducted in June by pro-Russian actors was particularly intense: 13 days of attacks, 275 incidents directed against 124 targets. Although the impacts were mostly contained, CSIRT Italy played a crucial role in mitigating the disruptions.

Phishing, data exposure and stolen credentials: the numbers of the threat

The phishing phenomenon saw the detection of 1,530 malicious URLs, with a significant campaign in May in the energy sector. There were 186 episodes of data exposure, up sharply from 91 in 2024, with data leaks from streaming platforms, e-commerce and public administrations. Alarm bells also sounded for the theft of banking credentials, which were then put up for sale on illegal circuits.

Active monitoring identified 638 IP addresses exposed to critical vulnerabilities on Citrix NetScaler (such as CitrixBleed 2) and over 1,977 compromised devices within botnets such as IcedID, Smokeloader and Bumblebee. In March, 1,245 Italian video surveillance devices were found to be involved in the DDoS botnet Eleven11bot.

Csirt Italy's activity: early warning and countermeasures

During the six-month period, CSIRT Italy issued 23,144 early warning notices (+9% over 2024), notifying affected or vulnerable subjects in a timely manner. In addition, 329 technical alerts were issued with specific countermeasures against the main cyber threats.

2025: High six-month period for cyber threats in Italy

The Acn report portrays a first half of 2025 marked by a strong intensification of cyber attacks, which are increasingly targeted and sophisticated. The strengthening of monitoring and prevention activities is confirmed as a central lever for the defence of the country's digital security.

Copyright reserved ©
Loading...

Brand connect

Loading...

Newsletter

Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.

Iscriviti