> Italy’s Foreign Ministry Under Cyberattack as Embassy Sites Come Under Review
[AUTHOR: Pierluigi Paganini]
[DATE: 08/10/2026 19:33]
[LANGUAGE: EN]
Italy’s Foreign Ministry is defending its website against a cyberattack, checking embassy sites and pushing for EU action to identify attackers.
On the morning of October 8, Italy’s Ministry of Foreign Affairs said its website was being attacked. According to the ministry’s own statement, its protection systems have mitigated the attack so far, with no disruption. The statement doesn’t say who is behind it, or what kind of attack it is.
The ministry is monitoring the situation with the Polo Strategico Nazionale, the country’s national cloud hub, and with the competent authorities.
“Cybersecurity is a central element of the reform of the Foreign Ministry approved last year. In recent months, we have strengthened our capabilities to prevent, monitor and respond to threats, adopting all necessary countermeasures, including on the technological side,” Foreign Minister Antonio Tajani said.
“Tajani had also had the opportunity to explain the technical capabilities of the CSIRT Operations Room to German Foreign Minister Johann Wadephul during his recent visit to Rome.” “In this context, Italy has decided to work with Romania and other EU member states to include proposals in upcoming European meetings to designate the actors responsible for cyberattacks, including attacks targeting Italian institutions.” reads the statement published by Italy’s Foreign Ministry.
Analysts are also checking the websites of Italian embassies and consulates abroad for similar attempts. That detail matters, and I’ll come back to it.
Minister Antonio Tajani tied the response to last year’s reform of the Farnesina, which made cybersecurity a central piece. He said prevention, monitoring and response capabilities have been strengthened in recent months, including on the technology side.
The statement ends on diplomacy. Italy will work with Romania and other member states to put proposals on the agenda of upcoming EU meetings, aimed at naming those responsible for cyberattacks, including attacks on Italian institutions. A blocked page is forgotten in a day, while a name on an official list is harder to shrug off.
Nobody has claimed this attack, but the pattern is familiar. NoName057(16) is a pro-Russian group that declared itself in March 2022 and announces its targets on Telegram. Avast researchers saw it using the Bobik botnet for DDoS attacks as early as September 2022.
Later, the DDoSia Project (aka DDosia), a crowdsourced DDoS operation linked to the pro-Russian hacktivist group NoName057(16), made the headlines beacuse its involvement in DDoS attacks again governments that supported Ukraine.
Italy has been a regular target. Over a weekend in January 2025, as Zelensky visited Rome, the group hit ministries and government sites on Saturday, then banks including Intesa and Monte dei Paschi di Siena and the ports of Taranto and Trieste on Sunday. At the end of December 2024 it had gone after Malpensa and Linate airports, and in February 2025 it tied a new wave to a speech by President Mattarella, according to Infosecurity Magazine. The timing follows politics, which isn’t a coincidence.
The ministry itself has been here before. ANSA reported that Russian hackers took its website down in late December 2024, and Tajani said it was back up the next day. DDoS attacks hit availability, not data, so the site goes dark and comes back. A loud attack can also pull attention away from a quiet one, which is a reason to look closer, not a claim about this case.
Now the embassies, and this part is my analysis. A ministry homepage going dark is embarrassing. An embassy or consulate site going dark is a problem for real people, because it’s where citizens abroad look for appointments, contacts and instructions, and the worst moment for an outage is a crisis abroad. Every one of those sites is also a surface to defend, and a lookalike page is an easy way to scam someone who’s already stressed.
Giving a look to the list of targets shared on DDosia today I can confirm that administrators planned attacks against the Farnesina, five Italian embassy sites, several Interior and Defence Ministry services, and other Italian organizations.
attiva.fastweb.it
sind.it
whs.activenetwork.it
bp.activenetwork.it
sistemagalileo.it
www.activenetwork.it
webtop.we-com.it
www.fastweb.it
agenzie.interno.gov.it
ambbruxelles.esteri.it
ambbucarest.esteri.it
ambcopenaghen.esteri.it
ambdublino.esteri.it
ambhelsinki.esteri.it
concorsi.difesa.it
constoronto.esteri.it
idserver.servizicie.interno.gov.it
sondaggi.bimedia.it
www.aeronautica.difesa.it
www.cartaidentita.interno.gov.it
www.esteri.it
www.giorgiameloni.it
www.istitutospiov.it
www.marina.difesa.it
www.prenotazionicie.interno.gov.it
www.uni.com
There is a precedent. In 2017, The Guardian reported a months-long intrusion into the Foreign Ministry’s systems. Italian media later reported that the attackers had targeted staff email accounts at the ministry and Italian embassies, rather than the encrypted system used for sensitive communications. A senior ministry security official said that attacks often happen before important events for Italy, while the Kremlin denied any involvement.
That’s why checking embassy websites is more than routine work. If someone wants to damage Italy’s image at little cost, the diplomatic network offers a large and highly visible target. The ministry is responding by strengthening its technical defenses and pushing at the EU level for “proposals to designate actors responsible for cyber attacks”, as the Farnesina’s statement puts it. That could make attribution more costly for attackers than simply taking a website offline.
DDoS attacks should not be underestimated, especially when they target government institutions and diplomatic services. They can disrupt public services, create pressure and attract significant media attention. But from a technical perspective, they are not usually complex offensive operations for a state to neutralize, especially when the target has adequate DDoS protection and network capacity.
The more important question is what sits behind the noise. Authorities need to determine whether these attacks are simply disruptive actions designed to attract attention, or whether they are being used to distract defenders while more sophisticated operations take place elsewhere. If there is no evidence of intrusion, data theft or compromise, the DDoS activity may be little more than a public demonstration of intent.
That distinction matters because a long list of targets can create the impression of a much more serious threat than the technical impact actually suggests. For people outside the cybersecurity community, a website being attacked can easily be interpreted as evidence that a government has been seriously compromised. In reality, it may be a relatively simple operation whose main objective is visibility.
The risk, therefore, is not only the attack itself, but the narrative built around it. DDoS campaigns can become a useful propaganda tool, creating fear and uncertainty while requiring relatively limited technical resources. The challenge for governments is to defend against the disruption without giving a sterile attack more strategic value than it deserves, while at the same time making sure that the noise is not hiding something more serious.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
Pierluigi Paganini
(SecurityAffairs – hacking, Italy’s Foreign Ministry)