Sapienza University of Rome (La Sapienza) suffered a major cyber incident that forced the institution to take critical IT systems offline, leaving core digital services disrupted for several days and the university website unavailable. The university publicly acknowledged the attack via social media, stating it shut down systems as a precaution to protect data integrity while it investigated and worked to restore services; it also indicated some channels (including email and workstations) were only partially available and that recovery efforts were proceeding using backups believed to be unaffected.
Italian authorities were notified and Italy’s national cybersecurity agency (ACN) is reported to be investigating. While the university has not formally attributed the incident, Italian media reporting cited by both outlets described the disruption as consistent with a ransomware operation, including claims that attackers provided a ransom-demand link featuring a 72-hour countdown that begins only after the link is clicked; separate reporting also linked the activity to BabLock ransomware, though this attribution has not been officially confirmed. To reduce impact on students and staff during the outage, the university also set up temporary in-person “infopoints” to provide access to information normally delivered through unavailable digital systems.

See attribution, scope, and your downstream exposure.
7 events from the most recent confirmed update back to the earliest known activity.
By 2026-02-07, the university was still keeping IT systems offline while technicians and investigators worked to determine the full scope of the breach and whether backups would support full recovery. Public reporting said operations were still significantly disrupted.
As outages continued, La Sapienza said exams would proceed, with students registering directly through professors, and established on-campus infopoints to assist users. These measures were introduced to maintain essential academic operations during the disruption.
The university said it was investigating the incident and restoring services from backups that were not affected by the attack. Some services, including email, workstations, and the website, remained limited or offline during the recovery.
Follow-on media reports attributed the incident to a previously unknown or purported pro-Russian group called Femwar02 and linked the malware to BabLock, also known as Rorschach. Neither the university nor Italian authorities publicly confirmed this attribution at the time.
Early reporting on the incident said the attackers sent a ransom-demand link tied to a 72-hour countdown that would begin only if the link was clicked. The university reportedly avoided engaging with the demand while assessing the situation.
Following the attack, La Sapienza notified Italy’s National Cybersecurity Agency (ACN) and law enforcement, which began coordinating on the response and investigation. ACN was publicly identified as involved in the case as recovery efforts started.
On 2026-02-02, La Sapienza University in Rome shut down its network systems as a precaution after a cyberattack disrupted operations. The university said the move was intended to protect data integrity and prevent the threat from spreading.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcescworld.com
Open sourcethecyberexpress.com
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.