Skip to content

Security1 publisherNot yet confirmed elsewhere2 min readPublished

Italy's Foreign Ministry says it held off an October 8 attack on its website

Italy's Foreign Ministry says its protection systems mitigated an attack on its website on the morning of October 8, with no disruption. Rome will now work with Romania and other EU states on proposals to formally name the actors behind cyberattacks on Italian institutions.

The Watch · Security desk

How we use AISend a correction

Photograph accompanying Italy's Foreign Ministry says it held off an October 8 attack on its website
Photo: euronews.com

What happened

  • The ministry's statement did not say who was behind the attack or what kind of attack it was.
  • The ministry is monitoring the situation with the Polo Strategico Nazionale, Italy's national cloud hub, and the competent authorities.
  • Analysts are checking the websites of Italian embassies and consulates abroad for similar attempts.
  • ANSA reported that Russian hackers knocked the ministry's website offline in late December 2024. Tajani said the site was restored the following day.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Embassy and consulate sites are where Italians abroad look for appointments and instructions, so an outage there hits hardest during a crisis abroad, and lookalike pages give scammers an opening, Security Affairs argues.
  • precedent EU designation would give attacks on Italian institutions a consequence that outlasts the outage; Security Affairs notes a name on an official list is harder to shrug off than a blocked page.
  • constraint Any case for designating whoever hit the Farnesina on October 8 rests on outside evidence such as the DDosia list until a group claims the attack or Italy publishes its own findings.

Five Italian embassy sites are on a DDoS target list, according to Security Affairs. The outlet wrote that the list shared on DDosia shows administrators planned attacks against the Farnesina, as the Foreign Ministry is known, the five embassy sites, several Interior and Defence Ministry services and other Italian organizations [21]. DDosia is a crowdsourced DDoS operation linked to NoName057(16) [9]. That group is pro-Russian, went public in March 2022 and posts its targets on Telegram [8]. Avast researchers had already seen it running DDoS attacks through the Bobik botnet by September 2022 [8].

The list shows intent against the ministry. It does not tie the October 8 attack to the group. Nobody has claimed that attack, and Security Affairs goes only as far as calling the pattern familiar [20].

The pattern is well documented. Italy is a regular target, and the timing of the waves follows politics [10]. Over a weekend in January 2025, while Zelensky was in Rome, the group went after ministries and government sites that Saturday and turned on Sunday to banks, among them Intesa and Monte dei Paschi di Siena, and to the ports of Trieste and Taranto [10]. It went after Malpensa and Linate airports at the end of December 2024 and tied a February 2025 wave to a speech by President Mattarella, according to Infosecurity Magazine [11].

DDoS takes availability, not data. The site goes dark and comes back [13]. Security Affairs adds that a loud attack can pull attention away from a quiet one, and says that is a reason to look closer, not a claim about this case [19]. The ministry has had a quiet one before. In 2017 The Guardian reported a months-long intrusion into its systems, and later Italian press reports said the intruders had gone after the email accounts of staff at the ministry and at Italian embassies, not the encrypted system used for sensitive communications [14]. A senior ministry security official said at the time that attacks often happen before important events for Italy. The Kremlin denied any involvement [15].

Tajani tied the response to last year's ministry reform. "Cybersecurity is a central element of the reform of the Foreign Ministry approved last year. In recent months, we have strengthened our capabilities to prevent, monitor and respond to threats, adopting all necessary countermeasures, including on the technological side," Tajani said [5]. The ministry said he had explained the technical capabilities of its CSIRT Operations Room to German Foreign Minister Johann Wadephul during Wadephul's recent visit to Rome [16].

What to watch

  • A NoName057(16) claim on Telegram for the Farnesina or any of the five embassy sites on the DDosia target list.
  • The text of the Italy-Romania proposals at the next EU meetings, and which other member states back designating named actors.
  • Any outage or lookalike page at an Italian embassy or consulate site after the October 8 attempt.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence45
Adoption
Insufficient
Hype gap+10
Incentives55
Confidence40
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    On the morning of October 8, Italy's Ministry of Foreign Affairs said its website was being attacked.

    ReportedSupportedView cited source
  2. [2]

    According to the ministry's statement, its protection systems have mitigated the attack so far, with no disruption.

    ReportedSupportedView cited source
  3. [3]

    The ministry's statement does not say who is behind the attack or what kind of attack it is.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. securityaffairs.com

    1 article · October 8, 2026

    Italy’s Foreign Ministry Under Cyberattack as Embassy Sites Come Under Review

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Entities

Loading related stories