A new tracking report has cataloged 148 ransomware claims targeting Italian organizations in the first half of 2026, with the LockBit 5 and Qilin operations topping the list of implicated groups. The manufacturing sector absorbed the brunt of this activity, according to analysis of data compiled by the RedACT project and reported by Security Affairs.

The 148-figure represents verified public claims rather than confirmed attacks or payments, as tracked by ransomNews and its RedACT initiative. This method, which aggregates data from leak sites and public postings, provides a consistent view of which threat actors are actively claiming victims in specific regions. While a claim does not automatically equal a successful encryption or ransom payment, the dataset is a key indicator of the threat landscape.

LockBit 5 and Qilin were responsible for the highest volume of claims against Italian entities. LockBit’s continued evolution, marked by the “5” version, demonstrates the group’s resilience despite prior law enforcement actions. Qilin, similarly, has been a persistent focus on European targets. The data highlights their dominant volume, not that they were the sole actors operating in the region.

The concentration of claims within manufacturing aligns with ongoing trends. Industry targets are often prized for the severe operational disruption and financial losses caused by even short periods of downtime, complicating recovery in industrial environments. This pattern mirrors observations across other European economies where production facilities face repeated extortion pressure.

For defensive teams, the report underscores the importance of tracking geographic targeting trends. Groups often concentrate efforts where they identify exposed services or perceived vulnerabilities. Open-source intelligence tools like RedACT become valuable for supplementing internal monitoring, helping organizations prioritize patches, detection rules, and incident response planning based on active campaigns.

The vulnerabilities exploited—such as unpatched VPNs, exposed RDP, and credentials from infostealer logs—are universal to any organization with internet-facing systems. This makes the data relevant beyond Italy, emphasizing the need for collective defense through rapid threat sharing and coordinated mitigation. The methods targeting Italian firms are seldom confined by national borders.

The analysis from Security Affairs adds to the 2026 ransomware record by documenting current claim patterns without making broad assumptions about global trends. It serves as a direct indicator of which groups are most active against Italian infrastructure right now. For security leaders, the prominence of LockBit 5 and Qilin is a clear signal to review foundational controls: immutable backups, strict identity access management, and network segmentation, particularly in operational technology environments.

As threat trackers continue to publish, the enduring value lies in identifying consistent patterns: the dominant brand names, the hardest-hit sectors, and how quickly new group variants emerge to replace disrupted ones. Italian organizations, and indeed any enterprise with similar profiles, now have a data-driven view of the primary ransomware adversaries they faced in early 2026.


最新追踪報告顯示,2026年上半年共錄得148宗針對意大利機構的勒索軟件索償,其中 LockBit 5 及 Qilin 兩個運營組織在涉及團伙中名列前茅。根據 RedACT 項目數據分析並由 Security Affairs 報導,製造業是此次攻擊浪潮的主要受影響領域。

該 148 宗索償數字代表經核實的公開聲明,而非確認的攻擊或支付紀錄,由 ransomNews 及其 RedACT 計劃追蹤。此方法透過整合洩漏網站及公開發佈的數據,能一致呈現哪些威脅行為者正積極在特定地區宣稱受害者。儘管索償聲明未必等同於成功的加密攻擊或贖金支付,該數據集仍是評估威脅態勢的關鍵指標。

LockBit 5 與 Qilin 對意大利機構的索償數量居首。LockBit 持續演進(以「5」版本為標誌),顯示該組織在先前執法行動後仍具韌性。Qilin 同樣長期針對歐洲目標。數據凸顯其主導的索償數量,但並非代表它們是該區域唯一運作的攻擊者。

索償集中在製造業與持續趨勢相符。工業目標常因其營運中斷及財務損失(即使短暫停工亦會引發嚴重後果)而成為攻擊對象,且工業環境的恢復過程往往複雜。此模式與其他歐洲經濟體觀察到的現象一致,當地生產設施同樣面臨持續的勒索壓力。

對防禦團隊而言,報告強調追蹤地域性攻擊趨勢的重要性。攻擊團伙常在發現暴露服務或感知漏洞的地區集中行動。RedACT 等開源情報工具能有效補充內部監控,協助組織根據活躍攻擊活動,優先處理補丁更新、偵測規則及事件回應規劃。

被利用的漏洞——如未修補的 VPN、暴露的 RDP 以及資訊竊取器日誌中的憑據——對任何具備互聯網暴露系統的機構皆屬普遍問題。這使得數據的適用範圍超越意大利,凸顯透過快速威脅共享及協調緩解措施實現集體防禦的必要性。針對意大利企業的攻擊手段鮮少受國家邊界限制。

Security Affairs 的分析透過記錄當前索償模式(而非對全球趨勢作廣泛假設),豐富了2026年勒索軟件紀錄。這直接反映哪些團伙目前對意大利基礎設施最為活躍。對安全主管而言,LockBit 5 與 Qilin 的顯著地位明確提示應審視基礎控制措施:不可變備份、嚴格的身份存取管理及網絡分段,尤其在營運技術環境中。

隨著威脅追蹤器持續發布情報,其持久價值在於識別一致模式:主導的品牌名稱、受創最嚴重的領域,以及新興團伙變體取代被瓦解者之速度。意大利機構及任何具備相似特徵的企業,現已掌握數據驅動的視角,了解其在2026年初面臨的主要勒索軟件對手。

新聞來源 / Original News Source