All incidents

LockBit5 and Qilin ransomware campaign targets Italian organizations in H1 2026

malwareopenJul 27, 2026 — Jul 31, 2026
LockBit5 and Qilin ransomware campaign targets Italian organizations in H1 2026

LOCKBIT5 and Qilin emerged as the most active ransomware groups targeting Italian organisations in the first half of 2026, according to a joint analysis by SuspectFile and RansomNews.online highlighting their dominance. The findings show that these two families were responsible for a significant share of the 148 ransomware incidents recorded across the country during that period.

The securityaffairs.com report details how attackers frequently relied on reused credentials and exposed remote services to gain initial access, with no public CVEs linked to the observed intrusions noting the simplicity of the tactics. Manufacturing bore the brunt of the campaign, accounting for nearly 40 % of all compromises, while the total volume of exfiltrated data surpassed 13 400 GB, although this figure was based on only 64 of the reported cases.

According to the databreaches.net overview, LockBit5 and Qilin each carried out 21 attacks, with the remaining incidents spread among other groups such as The Gentlemen bringing the combined total to 54. The report emphasises that the data was gathered manually without reliance on automated tools, aiming to provide a clear picture of the threat landscape rather than a simple ranking.

Geographically, northwest Italy, especially Lombardy, experienced the highest concentration of incidents, reflecting the region’s dense industrial base and the report’s observation of only a single healthcare breach attributed to LockBit5. Monthly attack rates hovered around 25, underscoring a steady pressure on defenders throughout the six‑month window.

Organisations should enforce multi‑factor authentication on all remote access points and rotate privileged passwords regularly to blunt credential‑reuse attacks. Patching known vulnerabilities in edge devices and segmenting critical production networks from corporate IT can limit lateral movement once a foothold is gained.

Maintaining offline, immutable backups and testing restoration procedures on a regular schedule remains essential for recovery without paying a ransom. Sharing observed indicators of compromise with sector‑specific ISACs and adopting a zero‑trust mindset for internal communications can help detect and contain similar campaigns in the future.

Intelligence briefing updated Jul 31, 2026

LockBit5
Root sourcewww.suspectfile.com
Timeline Coverage

Swipe to explore timeline