How criminal organisations infiltrate digital suppliers (and how to protect yourself)
Mafia organisations are increasingly using skilled hackers and infiltration tactics to gain access to sensitive data via IT suppliers
Among the seven priorities set out by the European Union will have to tackle over the four-year period 2026–2029 in the fight against organised crime, the EU Council has also included, within the EMPACT (European Multidisciplinary Platform Against Criminal Threats), the Council of the EU has also included the fight against cyber-attacks targeting critical infrastructure, governments, businesses and private citizens, which, in addition to occurring with increasing frequency, are also being significantly accelerated by artificial intelligence and other new technologies.
It should therefore come as no surprise that the renowned criminologist Vincenzo Musacchio states that ‘the five most skilled hackers in the world have not worked for US or Russian agencies for some time now, but for organised crime’, and that ‘the new mafias now have the world’s most skilled IT specialists at their disposal’.
Investing in cybersecurity is not enough
Whilst it is therefore important for businesses to be aware that there is a ‘Mafia 4.0’ which has turned cybercrime into a new business, on the other hand, it would be a mistake to think that simply investing in cyber security is enough to close ranks against hacker attacks and corporate data theft, because cybercriminals do not always use force to gain access to IT systems.
The famous legend of the Trojan Horse teaches us, in fact, that even the strongest walls can fall not only as a result of a frontal assault, but also because someone unwittingly opens the gates to the enemy. In Virgil’s ancient tale, the Trojans even welcomed that wooden horse into the city with enthusiasm, convinced that it was a gift and an opportunity, when in reality they were themselves bringing in the very threat that would lead to their defeat.
The same can happen in companies today. The threat does not always come in the form of a cyberattack launched from outside, but can sometimes enter through the front door via authorised personnel. According to the report “Insider Threat Statistics for 2026” published by SentinelOne, around 55–56 per cent of incidents resulting in data loss can be traced back to negligent employees who fail to follow internal procedures or who use unauthorised IT tools, but there is a far more insidious risk to which management might inadvertently throw open the door, even assuming it to be an opportunity.

