Article Details
Scrape Timestamp (UTC): 2025-11-20 19:05:10.003
Original Article Text
Click to Toggle View
Hacker claims to steal 2.3TB data from Italian rail group, Almavia. Data from Italy's national railway operator, the FS Italiane Group, has been exposed after a threat actor breached the organization's IT services provider, Almaviva. The hacker claims to have stolen 2.3 terabytes of data and leaked it on a dark web forum. According to the threat actor's description, the leak includes confidential documents and sensitive company information. Almaviva is a large Italian company that operates globally, providing services such as software design and development, system integration, IT consulting, and customer relationship management (CRM) products. Andrea Draghetti, Head of Cyber Threat Intelligence at D3Lab, says the leaked data is recent, and includes documents from the third quarter of 2025. The expert ruled out the possibility that the files were recycled from a Hive ransomware attack in 2022. "The threat actor claims the material includes internal shares, multi-company repositories, technical documentation, contracts with public entities, HR archives, accounting data, and even complete datasets from several FS Group companies," Draghetti says. "The structure of the dump, organized into compressed archives by department/company, is fully consistent with the modus operandi of ransomware groups and data brokers active in 2024–2025," the cybersecurity expert added. Almaviva is a major IT services provider with over 41,000 employees across almost 80 branches in Italy and abroad, and an annual turnover of $1.4 billion last year. FS Italiane Group (FS) is a 100% state-owned railway operator and one of the largest industrial companies in the country, with more than $18 billion in annual revenue. It manages railway infrastructure, passenger and freight rail transport, and also bus services and logistics chains. While BleepingComputer’s press requests to both Almaviva and FS went unanswered, the IT firm eventually confirmed the breach via a statement to local media. “In recent weeks, the services dedicated to security monitoring identified and subsequently isolated a cyberattack that affected our corporate systems, resulting in the theft of some data,” Almaviva said. “Almaviva immediately activated security and counter-response procedures through its specialized team for this type of incident, ensuring the protection and full operability of critical services.” The company also stated that it has informed authorities in the country, including the police, the national cybersecurity agency, and the country’s data protection authority. An investigation into the incident is ongoing with help and guidance from government agencies. Almaviva promised to transparently provide updates as more information emerges from the investigation. Currently, it is unclear if passenger information is present in the data leak or if the data breach is impacting other clients beyond FS. BleepingComputer has contacted Almaviva with additional questions, but we have not received a response by publication time. The 2026 CISO Budget Benchmark It's budget season! Over 300 CISOs and security leaders have shared how they're planning, spending, and prioritizing for the year ahead. This report compiles their insights, allowing readers to benchmark strategies, identify emerging trends, and compare their priorities as they head into 2026. Learn how top leaders are turning investment into measurable impact.
Daily Brief Summary
A threat actor breached Almaviva, an IT services provider for FS Italiane Group, stealing 2.3TB of data and leaking it on a dark web forum.
The compromised data reportedly includes sensitive documents, technical documentation, HR archives, and accounting data, impacting FS Italiane Group's operations.
FS Italiane Group, a state-owned railway operator, manages critical infrastructure and transport services, with annual revenues exceeding $18 billion.
Almaviva confirmed the breach, stating that security monitoring identified and isolated the attack, and initiated counter-response procedures to protect critical services.
Authorities, including the police and national cybersecurity agency, have been informed, and an investigation is underway with government assistance.
The breach's full impact remains uncertain, particularly regarding passenger information and the potential effect on other clients.
Almaviva has committed to providing transparent updates as the investigation progresses, highlighting the importance of robust incident response protocols.