Ransomware Attack on Italian Ministry of Culture by MadLiberator Exposes Sensitive Data

Incident Date:

July 17, 2024

World map

Overview

Title

Ransomware Attack on Italian Ministry of Culture by MadLiberator Exposes Sensitive Data

Victim

Ministero Della Cultura

Attacker

Mad Liberator

Location

Roma, Italy

, Italy

First Reported

July 17, 2024

Ransomware Attack on Italian Ministry of Culture by MadLiberator

Overview of the Ministry of Culture

The Italian Ministry of Culture, known as Ministero della Cultura, is a pivotal government agency responsible for preserving and promoting Italy's rich cultural heritage. Established in 1974, the ministry oversees a vast array of cultural assets, including historical buildings, monuments, artworks, and archaeological sites. Headquartered in Rome, the ministry is led by the Minister of Culture and collaborates with various public and private organizations to enhance public access to Italy's cultural treasures. The ministry has embraced digital technologies to improve its services, notably through the "DIG.IT MIBAC" initiative.

Details of the Ransomware Attack

On July 17, 2024, the Ministry of Culture fell victim to a ransomware attack orchestrated by the notorious group MadLiberator. The attack was publicly announced on MadLiberator's Data Leak Site (DLS), where the group posted images showing directories and files exfiltrated from the ministry's systems. The compromised data includes agreements, documentation, and photographs, with timestamps ranging from 2017 to 2024. The ministry has yet to release an official statement confirming the breach, leaving the authenticity of the leaked data unverified.

Profile of MadLiberator

MadLiberator is a well-known ransomware group that has gained notoriety for its high-profile attacks on various organizations worldwide. The group employs sophisticated encryption methods, such as AES/RSA, to lock victim files and uses aggressive extortion tactics to coerce victims into paying ransoms. MadLiberator's operations are characterized by legal threats and intimidation, warning victims of potential legal repercussions and the misuse of stolen data for fraudulent purposes.

Potential Vulnerabilities and Penetration Methods

The Ministry of Culture's extensive digital infrastructure, which includes managing state museums and archaeological sites, may have presented vulnerabilities that MadLiberator exploited. The group's sophisticated encryption techniques and aggressive tactics suggest a well-coordinated attack, potentially involving phishing schemes, exploitation of software vulnerabilities, or insider threats. The ministry's ongoing digital transformation initiatives, while aimed at improving accessibility, may have inadvertently exposed it to cyber threats.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.