A significant data breach has impacted Italy's national railway operator, Ferrovie dello Stato Italiane (FS), following a compromise at its IT services provider, Almaviva. A threat actor claims to have stolen and leaked 2.3 terabytes of sensitive data, including confidential documents, internal communications, contracts with public entities, technical documentation, financial records, and personal data of passengers and employees. The breach reportedly exposed information marked as confidential or for internal use, as well as privileged communications, trade secrets, and legal documents, affecting multiple FS Group subsidiaries and partners.
Cybersecurity experts have confirmed the authenticity and recency of the leaked data, which includes files from the third quarter of 2025 and is organized in a manner consistent with ransomware group operations. Almaviva, a major IT and digital services provider with over 41,000 employees, has acknowledged the breach. The incident highlights the risks posed by supply chain attacks, as the compromise of a key IT provider led to the exposure of critical infrastructure data and sensitive information across Italy's railway sector.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting said the alleged Almaviva compromise may have exposed data belonging to Italian railway operator Ferrovie dello Stato through a third-party relationship. This marked an escalation from a vendor breach claim to a potential downstream customer impact event.
A threat actor claimed to have stolen 2.3TB of data from Italian technology and rail-sector contractor Almaviva. The claim appears to be the first public disclosure of the alleged intrusion.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.