Security1 publisherNot yet confirmed elsewhere2 min readPublished
Italy's Foreign Ministry says it held off an October 8 attack on its website
Italy's Foreign Ministry says its protection systems mitigated an attack on its website on the morning of October 8, with no disruption. Rome will now work with Romania and other EU states on proposals to formally name the actors behind cyberattacks on Italian institutions.
The Watch · Security desk

What happened
- The ministry's statement did not say who was behind the attack or what kind of attack it was.
- The ministry is monitoring the situation with the Polo Strategico Nazionale, Italy's national cloud hub, and the competent authorities.
- Analysts are checking the websites of Italian embassies and consulates abroad for similar attempts.
- ANSA reported that Russian hackers knocked the ministry's website offline in late December 2024. Tajani said the site was restored the following day.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Embassy and consulate sites are where Italians abroad look for appointments and instructions, so an outage there hits hardest during a crisis abroad, and lookalike pages give scammers an opening, Security Affairs argues.
- precedent EU designation would give attacks on Italian institutions a consequence that outlasts the outage; Security Affairs notes a name on an official list is harder to shrug off than a blocked page.
- constraint Any case for designating whoever hit the Farnesina on October 8 rests on outside evidence such as the DDosia list until a group claims the attack or Italy publishes its own findings.
Five Italian embassy sites are on a DDoS target list, according to Security Affairs. The outlet wrote that the list shared on DDosia shows administrators planned attacks against the Farnesina, as the Foreign Ministry is known, the five embassy sites, several Interior and Defence Ministry services and other Italian organizations [21]. DDosia is a crowdsourced DDoS operation linked to NoName057(16) [9]. That group is pro-Russian, went public in March 2022 and posts its targets on Telegram [8]. Avast researchers had already seen it running DDoS attacks through the Bobik botnet by September 2022 [8].
The list shows intent against the ministry. It does not tie the October 8 attack to the group. Nobody has claimed that attack, and Security Affairs goes only as far as calling the pattern familiar [20].
The pattern is well documented. Italy is a regular target, and the timing of the waves follows politics [10]. Over a weekend in January 2025, while Zelensky was in Rome, the group went after ministries and government sites that Saturday and turned on Sunday to banks, among them Intesa and Monte dei Paschi di Siena, and to the ports of Trieste and Taranto [10]. It went after Malpensa and Linate airports at the end of December 2024 and tied a February 2025 wave to a speech by President Mattarella, according to Infosecurity Magazine [11].
DDoS takes availability, not data. The site goes dark and comes back [13]. Security Affairs adds that a loud attack can pull attention away from a quiet one, and says that is a reason to look closer, not a claim about this case [19]. The ministry has had a quiet one before. In 2017 The Guardian reported a months-long intrusion into its systems, and later Italian press reports said the intruders had gone after the email accounts of staff at the ministry and at Italian embassies, not the encrypted system used for sensitive communications [14]. A senior ministry security official said at the time that attacks often happen before important events for Italy. The Kremlin denied any involvement [15].
Tajani tied the response to last year's ministry reform. "Cybersecurity is a central element of the reform of the Foreign Ministry approved last year. In recent months, we have strengthened our capabilities to prevent, monitor and respond to threats, adopting all necessary countermeasures, including on the technological side," Tajani said [5]. The ministry said he had explained the technical capabilities of its CSIRT Operations Room to German Foreign Minister Johann Wadephul during Wadephul's recent visit to Rome [16].
What to watch
- A NoName057(16) claim on Telegram for the Farnesina or any of the five embassy sites on the DDosia target list.
- The text of the Italy-Romania proposals at the next EU meetings, and which other member states back designating named actors.
- Any outage or lookalike page at an Italian embassy or consulate site after the October 8 attempt.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence40
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
On the morning of October 8, Italy's Ministry of Foreign Affairs said its website was being attacked.
- [2]
According to the ministry's statement, its protection systems have mitigated the attack so far, with no disruption.
- [3]
The ministry's statement does not say who is behind the attack or what kind of attack it is.
- [4]
The ministry is monitoring the situation with the Polo Strategico Nazionale, Italy's national cloud hub, and with the competent authorities.
- [5]
"Cybersecurity is a central element of the reform of the Foreign Ministry approved last year. In recent months, we have strengthened our capabilities to prevent, monitor and respond to threats, adopting all necessary countermeasures, including on the technological side," Foreign Minister Antonio Tajani said.
- [6]
The Foreign Ministry statement reads: "Italy has decided to work with Romania and other EU member states to include proposals in upcoming European meetings to designate the actors responsible for cyberattacks, including attacks targeting Italian institutions."
- [7]
Analysts are checking the websites of Italian embassies and consulates abroad for similar attempts.
- [8]
NoName057(16) is a pro-Russian group that declared itself in March 2022 and announces its targets on Telegram; Avast researchers saw it using the Bobik botnet for DDoS attacks as early as September 2022.
- [9]
The DDoSia Project (DDosia) is a crowdsourced DDoS operation linked to the pro-Russian hacktivist group NoName057(16).
- [10]
Italy has been a regular target of NoName057(16) and the timing follows politics: over a weekend in January 2025, as Zelensky visited Rome, the group hit ministries and government sites on Saturday, then banks including Intesa and Monte dei Paschi di Siena and the ports of Taranto and Trieste on Sunday.
- [11]
At the end of December 2024 NoName057(16) went after Malpensa and Linate airports, and in February 2025 it tied a new wave to a speech by President Mattarella, according to Infosecurity Magazine.
- [12]
ANSA reported that Russian hackers took the Foreign Ministry's website down in late December 2024, and Tajani said it was back up the next day.
- [13]
DDoS attacks hit availability, not data, so the site goes dark and comes back.
- [14]
In 2017 The Guardian reported a months-long intrusion into the Foreign Ministry's systems; Italian media later reported the attackers had targeted staff email accounts at the ministry and Italian embassies, rather than the encrypted system used for sensitive communications.
ReportedSupportedSource: The Guardian and Italian media, as cited by Security AffairsView cited source - [15]
A senior ministry security official said that attacks often happen before important events for Italy, while the Kremlin denied any involvement.
- [16]
According to the ministry statement, Tajani had explained the technical capabilities of the CSIRT Operations Room to German Foreign Minister Johann Wadephul during his recent visit to Rome.
- [17]
Security Affairs argues that embassy and consulate sites are where citizens abroad look for appointments, contacts and instructions, that the worst moment for an outage is a crisis abroad, and that a lookalike page is an easy way to scam someone already stressed.
- [18]
Security Affairs: a blocked page is forgotten in a day, while a name on an official list is harder to shrug off.
- [19]
Security Affairs says a loud attack can pull attention away from a quiet one, which it calls a reason to look closer, not a claim about this case.
- [20]
Nobody has claimed the October 8 attack; Security Affairs says the pattern is familiar.
- [21]
Security Affairs says the list of targets shared on DDosia shows administrators planned attacks against the Farnesina (Italy's Foreign Ministry), five Italian embassy sites, several Interior and Defence Ministry services, and other Italian organizations.
ReportedInsufficientSource: Security Affairs, from its review of the DDosia target listView cited source
Sources
1 independent publisher whose own reporting we read for this story.
- securityaffairs.comItaly’s Foreign Ministry Under Cyberattack as Embassy Sites Come Under Review
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.