Italy's Ministry of Foreign Affairs confirmed on October 8, 2026, that its website was under cyberattack. The ministry stated that its protection systems successfully mitigated the incident, preventing any disruption to its services.
Foreign Minister Antonio Tajani indicated that the ministry is actively monitoring the situation in collaboration with the Polo Strategico Nazionale, Italy's national cloud hub, and other relevant authorities. Tajani emphasized that cybersecurity has been a central focus of the Farnesina's reform efforts over the past year, leading to strengthened capabilities in prevention, monitoring, and response, including technological countermeasures.
Following the attack, Italian authorities are also inspecting the websites of Italian embassies and consulates abroad for similar malicious activity.
The ministry's statement also outlined Italy's intention to collaborate with Romania and other European Union member states to propose measures in upcoming EU meetings aimed at officially designating the entities responsible for cyberattacks, particularly those targeting Italian institutions.
While the ministry did not identify the perpetrators or the specific nature of the attack, analysts note that the pattern of targeting Italian government and critical infrastructure aligns with previous campaigns by pro-Russian hacktivist groups. One such group, NoName057(16), which emerged in March 2022, has a history of using DDoS attacks against governments supporting Ukraine.
NoName057(16), often associated with the crowdsourced DDoSia Project, has previously targeted Italian entities. In January 2025, during a visit by Ukrainian President Volodymyr Zelensky to Rome, the group reportedly attacked various ministries, government sites, banks including Intesa and Monte dei Paschi di Siena, and the ports of Taranto and Trieste. Prior to that, in December 2024, Malpensa and Linate airports were reportedly targeted. Another wave of attacks in February 2025 was linked to a speech by President Mattarella.
The Ministry of Foreign Affairs itself experienced a similar incident in late December 2024, when its website was reportedly taken offline by Russian hackers, though it was restored the following day. DDoS attacks primarily impact availability rather than data integrity.
Reports indicate that the DDoSia project's target list for the current campaign includes the Farnesina (Ministry of Foreign Affairs), five Italian embassy sites, several services belonging to the Interior and Defence Ministries, and other Italian organizations. Specific targets identified include ambbruxelles.esteri.it, ambbucarest.esteri.it, ambcopenaghen.esteri.it, ambdublino.esteri.it, and ambhelsinki.esteri.it, along with various government and defense-related domains.
This incident is not the first time the Italian Foreign Ministry has faced cyber intrusions. In 2017, a months-long intrusion into the ministry's systems was reported, with attackers reportedly targeting staff email accounts at the ministry and Italian embassies, though not the encrypted systems used for sensitive communications. At that time, a senior ministry security official noted that attacks often coincide with significant events for Italy.






