The Russian hacker group Lockbit has claimed responsibility for the ransomware attack that in the last ten days has hit public administrations in Italy that make use of Westpole's services.

Faced with encrypted and inaccessible databases, cyber pirates apparently sent ransom requests in cryptocurrencies to the provider that hosts various services of Pa Digitale , a private company of the Buffetti group that provides services to 1,300 Italian public administration entities. Among the products supplied and still blocked are the payroll reporting and electronic invoicing systems but the blocking of December and thirteenth salaries has been averted .

The cyber attack reached the series of servers in Milan and Rome of Westpole , the development house whose cloud is used by the company Pa Digitale. The company's infrastructure was heavily compromised by Lockbit ransomware, the group most active in this type of attacks targeting Italian targets. The hackers may have exploited already known vulnerabilities in the systems. For a good half of the services the recovery procedure has been started through backup; the other half may be difficult to recover.

The slowdowns in digital services that occurred this morning, says the National Cybersecurity Agency, "are due to the congestion of simultaneous accesses and do not represent a direct consequence of the attack".

The Agency announces that it has been in contact with Westpole SpA and PA Digitale SpA for several days to give them maximum support in containing the disruptions caused by the ransomware-type cyber attack carried out by the Russian-speaking hacker group Lockbit 3.0 . The activity carried out allowed the restoration of all the affected services , as well as the recovery of the data subject to the attack for more than 700 of the national and local public entities linked to the supply chain of PA Digitale SpA". For the remaining Administrations - there are approximately 1,000 public entities contractually linked to PA Digitale SpA for the provision of management services of various kinds - « the need remains to recover data dating back to the 3 days preceding the attack, which occurred on the 8th December ", adds the Agency.

(Unioneonline/D)

© Riproduzione riservata