Cyber mafias

How criminal organisations infiltrate digital suppliers (and how to protect yourself)

Mafia organisations are increasingly using skilled hackers and infiltration tactics to gain access to sensitive data via IT suppliers

Adobestock

4' min read

Translated by AI
Versione italiana

4' min read

Translated by AI
Versione italiana

Among the seven priorities set out by the European Union will have to tackle over the four-year period 2026–2029 in the fight against organised crime, the EU Council has also included, within the EMPACT (European Multidisciplinary Platform Against Criminal Threats), the Council of the EU has also included the fight against cyber-attacks targeting critical infrastructure, governments, businesses and private citizens, which, in addition to occurring with increasing frequency, are also being significantly accelerated by artificial intelligence and other new technologies.

It should therefore come as no surprise that the renowned criminologist Vincenzo Musacchio states that ‘the five most skilled hackers in the world have not worked for US or Russian agencies for some time now, but for organised crime’, and that ‘the new mafias now have the world’s most skilled IT specialists at their disposal’.

Loading...

Investing in cybersecurity is not enough

Whilst it is therefore important for businesses to be aware that there is a ‘Mafia 4.0’ which has turned cybercrime into a new business, on the other hand, it would be a mistake to think that simply investing in cyber security is enough to close ranks against hacker attacks and corporate data theft, because cybercriminals do not always use force to gain access to IT systems.

The famous legend of the Trojan Horse teaches us, in fact, that even the strongest walls can fall not only as a result of a frontal assault, but also because someone unwittingly opens the gates to the enemy. In Virgil’s ancient tale, the Trojans even welcomed that wooden horse into the city with enthusiasm, convinced that it was a gift and an opportunity, when in reality they were themselves bringing in the very threat that would lead to their defeat.

The same can happen in companies today. The threat does not always come in the form of a cyberattack launched from outside, but can sometimes enter through the front door via authorised personnel. According to the report “Insider Threat Statistics for 2026” published by SentinelOne, around 55–56 per cent of incidents resulting in data loss can be traced back to negligent employees who fail to follow internal procedures or who use unauthorised IT tools, but there is a far more insidious risk to which management might inadvertently throw open the door, even assuming it to be an opportunity.

The tactics of cyber mafias

Whilst it is well established that mafia organisations set up legitimate companies to use as a front for cyber-criminal activities, their ability to infiltrate legitimate IT and telecommunications companies is even more covert; they exploit these organisations as a means of gaining privileged access to infrastructure and confidential data, which can facilitate their illicit activities such as money laundering, industrial espionage, sabotage, ransomware extortion, and other cyber frauds.

Among the various tactics used to position themselves strategically within key digital ecosystems, one of the cyber mafias’ objectives is to gain credibility within the technology sector in order to establish partnerships or present themselves as service providers to particularly attractive companies, such as IT consultancy firms, software houses, cloud service providers and digital marketing agencies.

One particularly significant aspect of the evolution of Italian mafia organisations is not only the recruitment of the best hackers on the market, but also that of young professionals who are descendants of families already affiliated with the organisations; these individuals are trained to acquire advanced IT skills, thereby ensuring their loyal adherence to the codes of conduct that characterise the organisations to which they belong.

It may thus happen that companies seeking IT service providers to whom they can award contracts or tenders unwittingly bring ‘digital mafiosi’ – controlled by criminal organisations – into their own ranks, placing their trust in them, without realising it, to manage their data, without realising what is really hidden behind a seemingly impeccable façade.

Warning signs and measures to take

Faced with these tactics employed by cyber mafias to insidiously infiltrate companies in strategic sectors in order to get their hands on inside information and sensitive data, companies must therefore make every effort to select truly reliable suppliers and partners, establishing a rigorous vetting procedure that involves not only assessing their technological capabilities but also their market reputation, whilst carefully weighing up any potential red flags.

Loading...

It seems that, there is still a long way to go, however, because the “KPMG’s Global Third-Party Risk Management Survey 2026” reveals that 79 per cent of companies report difficulties in assessing the reliability of new suppliers, and only 18 per cent of organisations have a supplier management and qualification process that is fully integrated into their business procedures, whilst 53 per cent are still in the process of achieving this, with only partial integration.

Among the factors that should raise the greatest suspicion when assessing a potential supplier, are opaque ownership structures involving the use of front men or companies with frequent changes in shareholdings, shareholdings held through foreign companies or complex corporate chains that are difficult to trace, and organisational structures that are inconsistent with high turnover but, at the same time, unusually low staff costs for sectors requiring a high level of specialisation. Naturally, the reputation of directors and shareholders is one of the most immediate indicators: any previous criminal convictions, anti-Mafia disqualifications, links to companies involved in investigations or suspicious bankruptcies are damaging factors that cannot be ignored. Commercial offers with prices that are unusually lower than those of competitors should also raise red flags, as these could be signs of unusual sources of funding or aggressive strategies aimed at rapidly capturing market share.

To protect themselves against infiltration by cyber mafias, companies must therefore be able to ‘X-ray’ potential strategic suppliers – such as those handling data or accessing corporate know-how – using every available verification tool, including due diligence investigations, intelligence gathering, obtaining Chamber of Commerce extracts, commercial information, financial statements and financial stability reports, verification of beneficial owners, and the presence of legal disputes that might indicate risky or dishonest behaviour, as well as constant monitoring of the company’s reputation in the media to identify any negative reports concerning the company or its representatives, and, where possible, obtaining anti-mafia clearance to ensure the integrity of prospective candidates.

(*) President of Federprivacy

Copyright reserved ©

Brand connect

Loading...

Newsletter

Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.

Iscriviti