Ransomware victim disclosure
← All victimsItaly
Claimed by ImNotAVillain · listed 5 hours ago
Status timeline
- ListedSep 24, 2026
- Data leakeddate unknown
At a glance
- Group
- ImNotAVillain
- Status
- Data leaked
- Country
- Italy
- Sector
- Government & Defense
- Listed on leak site
- Sep 24, 2026
About the victim
AI dossier — public-source company profileThe victim is identified only as 'Italy', referring to Italian state institutions or government agencies. No specific entity, department, or organization name is provided in the leak post.
- Industry
- Government & Defense
Attack summary
Severity: critical — Claimed exfiltration of 150 GB from multiple Italian government and defense departments represents potential exposure of state-level sensitive data, regulatory records, and national security information at significant scale.The group claims to have exfiltrated data from Italian government and defense departments, alleging violations of data protection laws. Approximately 85,000 files totaling 150 GB are stated to have been accessed across multiple top-level departments and units.
Data the group says was taken
AI dossier — extracted from the leak post- Government department records
- Defense unit files
- Institutional data
What the group claims
Italy is being exposed for failing to follow proper data protection laws. Includes 85,000+ Files — 150GB. Top departments, units, offices affected.
The leak post
captured from the group's sitePersonal information on more than 130K federal officers across top departments has been obtained by us. Official mailboxes contained unsecured copies of identity documents, including passports, health cards, immigration papers, and all other PII. Sample shown above. An arms license for an Israeli-flagged vessel was left in official email alongside hundreds of similar documents. A federal officer's full identity file and diplomatic passports were left sitting in official systems with no real protection.
Sources
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

