Gen. partnerAlgotech

Cyber incident hit an Italian company in the IBM group

The company did not disclose which systems were affected or how much data may have been impacted.

|
May 4, 2026
Cyber incident hit an Italian company in the IBM group

IBM addresses a security incident at its Italian subsidiary

At the end of April 2026 a cyber intrusion targeted the company Sistemi Informativi, which is controlled by IBM Italy. The event was first described by the Italian La Repubblica, according to Security Affairs.

IBM in its official statement confirmed identifying and containing the incident and activating incident response procedures with internal and external specialists involved.

The company said systems are stable and services have been restored, but did not provide details on the scope of the attack. The Sistemi Informativi website was unavailable for several hours during the incident response. Forensic investigation is ongoing.

The outage raised alarm among critical infrastructure operators

According to Security Affairs, the outage quickly prompted a response from cybersecurity authorities and critical infrastructure operators in Italy.

During the containment of the incident, the Sistemi Informativi website was unavailable for several hours, as Security Affairs reports. IBM activated internal and external specialists under standard response protocols.

The company did not disclose which systems were affected or how much data may have been impacted.

La Repubblica, citing its sources, reported suspicions pointing to the Salt Typhoon group, but a publicly confirmed attribution is not yet available.

Sistemi Informativi manages IT infrastructure for public and private institutions in Italy, and its role is, according to Security Affairs, significant for the functioning of the country's digital infrastructure.

Suspicions point to the Chinese APT group Salt Typhoon

Salt Typhoon is, according to Security Affairs, an advanced APT group associated with Chinese state interests, active at least since 2019.

According to available reports, its operations have intensified in recent years. The group is linked to exploiting vulnerabilities in edge devices, such as Citrix and Cisco platforms, and to targeting telecommunications infrastructure.

Earlier reports mention compromises of organizations in North America and Europe, including telecommunications companies and government networks. A typical characteristic of these operations is long-term stealthy presence in networks, data collection, and infrastructure mapping.

The attribution of the attack on Sistemi Informativi to Salt Typhoon remains under investigation and is not confirmed.

The scope of the attack is unknown, impacts cannot yet be quantified

IBM said services have been restored and systems are stable.

The company did not state the extent of data impact or the number of affected systems.

According to Security Affairs, the incident drew increased attention from security institutions given the company's role in Italy's digital infrastructure.

If participation by Salt Typhoon is confirmed, available analyses suggest it could be a significant incident with potential impact on sensitive data, infrastructure mapping, and indirect access to other organizations through supply chain compromise. These scenarios, however, are not yet confirmed.

The incident is under control, investigation continues

IBM confirmed the incident was contained and systems stabilized.

Forensic investigation continues, aiming to clarify the scope of the attack and any attribution.

Final conclusions, including identification of the attacker, have not yet been released.

Sources

Loading comments...

Stay in the loop

Subscribe to our newsletter and get the latest cybersecurity news delivered straight to your inbox.

Your data is safe. You can unsubscribe from the newsletter at any time.