Decoded – Ransomware in Italy is an accounting decision, and the attackers know your books

148 confirmed claims in six months, 30 gangs, one behavioral pattern that has not changed since the floppy disk era.

So, the first RedACT report dropped, and if you care about ransomware in Italy you should read it before you read me. The numbers, hand-verified by the people at ransomNews:

  • 148 confirmed claims against Italian organizations between January and June 2026
  • 30 active gangs
  • 13.4 declared terabytes on the leak sites
  • manufacturing takes 39.9% of the hits, Lombardy alone takes 30.4%, and the top initial access vectors are recycled credentials, unpatched perimeters and exposed RDP

Read that list of vectors again. Slooooowly. There is no 0day in it. There is no nation-state tradecraft. There is a password from a 2021 breach, a server nobody patched, and port 3389 waving at the internet.

The lock screen used to be honest

Let’s walk through this with the right eyes, because ransomware used to be a very different social contract.

In 1989 Joseph Popp mailed twenty thousand floppy disks with the AIDS trojan on them and asked for $189 to a PO box in Panama. Crude, almost polite.

Fast forward to the CryptoLocker years: the attack announced itself. Screens locked, production stopped, everyone from the warehouse to the boardroom knew within the hour. The event was loud, binary, and, strangely, honest. Your files were hostage, your leverage was your backup, and the whole thing resolved as a technical question: can we restore, yes or no?

The industry built its entire mental model on that era. Backups, segmentation, recovery time objectives. All good things, and all answers to a question the attackers stopped asking years ago.

Encryption is now the marketing department

Today the product is different, RedACT data shows it plainly: double extortion is the default, and the data leak site,is where the actual pressure lives – pressure for the victims, honestly. In 56.8% of the Italian claims this semester, no data volume was even declared. Think about what that means. The gang did not need to prove anything. The claim itself, the company name on a onion page, was the weapon.

And look at how industrial the whole thing has become. Deadlock published 12 Italian victims in a single day in June, prolly a mass datadump, a spreadsheet operation, not a campaign. Eleven of the thirty criminal groups appear exactly once and will probably not exist under that name by Christmas. LockBit got dismantled by Operation Cronos, rebranded as LockBit5 on a forum, and is back at the top of the Italian chart with 21 claims. You see, brands are disposable, model is not.

Ransomware in Italy: the most predictable link clicks nothing

Here is the part the industry keeps refusing to name. We talk about ransomware in Italy as a technology problem, and we spend accordingly: EDR, backup vendors, another dashboard. But walk the RedACT kill chain from end to end and count the human decisions in it.

Before the breach: someone reused a credential. Someone postponed a patch cycle because the production line could not stop. Someone left RDP exposed because the remote consultant needed access and the ticket was easier to close than to question. None of these people were fooled by anything. Nobody was phished with an AI-generated masterpiece. They made reasonable-feeling trade-offs under pressure, the same trade-offs the gangs’ playbooks assume they will make, because they always do.

After the breach: silence. SILENCE. SI-LEN-CE.
That 56.8% of unquantified claims is not just lazy bookkeeping by criminals. A claim on a DLS does not require the victim to confirm anything, and overwhelmingly, Italian victims confirm nothing. No disclosure, no comms, no warning to the partners whose data went out the door with theirs.

The bet underneath double extortion is not cryptographic. The bet is that your shame is worth more to you than your data, and that you will negotiate quietly rather than admit publicly. 30 groups made that bet 148 times in six months against this country, and the model keeps funding itself, so draw your own conclusion about how often the bet pays.

That is the actual product and the product is the predictability of the humans on the other end, their trade-offs before, their silence after. Everything else is packaging.

And the pattern is testable, which is what makes the silence around it so expensive: you can rehearse the trade-offs and you can pressure-test the person who approves the remote access ticket, again you can find out, before a gang does, whether your organization’s reflex under pressure is to speak or to hide. Untested is not neutral. Untested is a company that has an incident response PDF and no evidence.

Those threat actors will rebrand again before the H2 report comes out.
Bet on it. The behavior they monetize has not rebranded since a PO box in Panama, and it is the only part of the whole ecosystem nobody budgets for.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top