LockBit5 and Qilin Lead Ransomware Attacks Against Italian Organizations

A new report links 148 ransomware attacks to Italian organizations in H1 2026, with manufacturing the most targeted sector.
Six months, 148 confirmed ransomware claims against Italian targets, and one sector taking the brunt of it. That’s the headline number from a new semi-annual tracker compiled by ransomNews under its RedACT project, which pulls together OSINT and SOCMINT sources to build a manual, deduplicated picture of who’s getting hit and by whom.
The pace works out to roughly 25 claims a month, just under six a week. Attackers claim to have exfiltrated over 13,400 GB of data across the period, though that figure only covers 64 of the 148 cases; where a volume is actually disclosed, it averages around 61 GB. Read that gap as a reminder that leak-site numbers are marketing copy from criminals, not audited disclosures.
“During the reporting period, 148 confirmed ransomware claims were recorded against Italian organizations, averaging 24.7 per month or 5.7 per week.” reads the report published by ransomNews. “The geographic distribution by NUTS macro-region shows Northwest Italy as the most affected area with 63 victims (42.6%), followed by the Northeast (36), Central Italy (30), Southern Italy (13), and the Islands (5). One claimed victim could not be geographically identified. Attackers claimed to have stolen a total of 13,405.22 GB (approximately 13.4 TB) of data, although data volume was disclosed in only 64 of the 148 cases (43.2%). Where reported, the average amount of exfiltrated data was 61.1 GB.”

Geography tells its own story here. The industrial north carries the weight: the northwest alone accounts for 63 victims, and combined with the northeast that’s two-thirds of every claim in the country. Lombardy alone racks up 45 victims, more than the center, south, and islands combined if you set Lazio aside, and Milan’s province leads every other with 22 claims on its own.
Manufacturing is the sector everyone should be watching, and not because it’s surprising. Factories carry proprietary designs, run operational technology that’s brutal to patch without stopping the line, and have close to zero tolerance for downtime, which makes paying up look cheap by comparison. That combination hands manufacturing 59 victims, nearly 40% of the whole dataset, well ahead of commerce and transport, which trail with 17 each.
Two groups dominate the leaderboard, tied at 21 claims apiece: LockBit5 and Qilin. They couldn’t look more different in how they operate.
“The most active ransomware groups were LockBit5 and Qilin, with 21 claimed victims each. The manufacturing sector was the hardest hit, accounting for 59 victims (39.9% of the total).” continues the report.

LockBit5, the rebrand that surfaced on the RAMP forum after law enforcement’s Operation Cronos took down its predecessor, dumped almost half its Italian activity into a single month, March, which lines up with a broader global surge researchers clocked around the same time. Qilin, by contrast, just kept showing up all six months, steady enough that Italy’s CSIRT put out a dedicated advisory calling out its systematic targeting of small and medium businesses.
June was the loudest month of the half, with 31 claims, a 72% jump from May’s quiet stretch of 18. Don’t read that as organic growth, though. A group called Deadlock dumped 12 Italian victims in a single day, and Safepay separately claimed three targets worth nearly 1,900 GB on its own. Strip those two bursts out and June looks a lot less dramatic, which is the sort of detail that matters if you’re briefing leadership on trend lines rather than headlines.
Data volume, interestingly, doesn’t track victim count at all. February produced the smallest number of claims for its size but the largest data haul of the half, over 4,700 GB, and that’s almost entirely down to two single claims of roughly 2,000 GB each, against Gruppo SEAC and Sofinter Group. Two big fish can outweigh a dozen small ones on paper.
The access methods behind all this aren’t exotic. Reused credentials pulled from old breaches and dark web dumps, unpatched public-facing systems, and RDP left exposed do most of the damage; there’s little sign of exotic tradecraft driving these numbers. CL0P’s four Italian claims in January and February trace directly back to its mass-exploitation campaign against Oracle E-Business Suite, a reminder that a single unpatched enterprise system can ripple into victim lists months later.
Thirty different groups claimed at least one Italian victim this half, but eleven of them show up exactly once, which is less a sign of a crowded market and more a sign of how disposable ransomware brands have become. Affiliates rebrand, spin up a new name, and vanish within weeks. Basing your threat model on which “brand” is currently trending is a bit like planning for weather using yesterday’s forecast.
The national picture from Italy’s cybersecurity agency ACN backs up what this dataset shows locally: cyber events climbed in June compared to May, with pressure concentrated on smaller, lower-resilience organizations, exactly the profile of most companies on this list. If you run a mid-sized manufacturer in Lombardy with RDP facing the internet, you’re not a hypothetical target. You’re the median one.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, cybercrime)
Click Here For The Original Source.
