Saturday, October 10, 2026

Italy checks diplomatic websites after DDoS attack on foreign ministry

October 10, 2026
2 mins read
Italy checks diplomatic websites after DDoS attack on foreign ministry
Italy checks diplomatic websites after DDoS attack on foreign ministry

Italy’s foreign ministry website was targeted by a distributed denial-of-service attack on 8 October 2026, prompting checks of the country’s embassy and consular websites abroad. The reported attack was linked to NoName057(16), a group commonly described as pro-Russian, but the available information does not establish a direct operational relationship with the Russian state.

A specialised Italian police unit that tackles cybercrime worked to counter the attack. Officials then examined the online services of Italian diplomatic missions to determine whether the same activity had reached other government domains.

A flood of traffic, not necessarily a break-in

A DDoS attack is designed to overwhelm an internet-facing service with a large volume of artificial requests. Servers, network connections or systems that filter incoming traffic can become overloaded, leaving legitimate users facing delays or unable to open the website.

That is different from penetrating a ministry’s internal network. A public website becoming unavailable does not, by itself, show that attackers accessed protected systems, altered government data or stole diplomatic files. The information available about this incident concerns disruption to the ministry’s online service, rather than a confirmed compromise of its restricted infrastructure.

The effect can nevertheless be substantial. A foreign ministry’s website is a public gateway for consular instructions, travel information, official announcements and contact details for embassies and consulates. If that gateway is disrupted, citizens abroad and people preparing to travel may struggle to find urgent guidance even while the ministry’s internal systems remain intact.

Why embassies and consulates came under review

The decision to inspect diplomatic websites reflected a question about the attack’s reach. Italy’s authorities needed to establish whether the foreign ministry’s site was an isolated target or part of a wider operation affecting several parts of the country’s digital diplomatic presence.

The checks do not mean that every embassy or consulate under review had been attacked. They were a precaution intended to identify signs of similar activity and distinguish a single disruption from a coordinated campaign.

Diplomatic websites are conspicuous targets for this kind of operation. They are open to the public, clearly associated with a government and relied upon by people seeking practical information. Disabling one can create an immediate public and media effect without requiring access to the more heavily protected systems behind it.

Reporting by Euronews attributed the attack to NoName057(16), which has been associated in public reporting with politically motivated DDoS campaigns against European institutions and organisations. The description of the group as pro-Russian indicates how it is generally characterised in that reporting; it does not, on its own, prove that Russian authorities directed or controlled the operation.

The separate problem of attribution

Cyber incidents can be attributed at several different levels. Investigators may examine the traffic used in an attack, the infrastructure behind it and any public claims made by a group. Establishing who ultimately ordered, supported or benefited from an operation is a separate and more difficult question.

That distinction matters when a temporary outage is used to support broader claims about state policy or a widening campaign against European countries. The attack demonstrates that an Italian government service was exposed to disruption; it does not, on the information available, establish a chain of command leading to the Kremlin or confirm an intrusion into classified systems.

For Italy, the immediate response has two parts: keep the foreign ministry’s public portal available and determine whether diplomatic missions abroad faced comparable traffic. A campaign against several websites would present a different operational problem from an attack confined to one prominent domain, requiring authorities to assess the security and resilience of a broader online network.

The outstanding issue is therefore the scope of the incident. The checks on embassy and consular websites should show whether the foreign ministry was the principal target or one element of a wider attempt to disrupt Italy’s digital diplomatic services.

Leave a Reply

Your email address will not be published.

Don't Miss

Fico Reopens Slovakia’s Military Door to Moscow

Fico Reopens Slovakia’s Military Door to Moscow

Slovakia is restoring military-diplomatic links with Russia after a four-year break, sending
How Italy’s IDI turns sanctions into a case against Europe

How Italy’s IDI turns sanctions into a case against Europe

Italy’s small far-right party Italia delle Identità is presenting sanctions against Russia