Hackers using the names Infrastructure Destruction Squad and Dark Engine claimed they breached the hydraulic pump and flood risk reduction system protecting Venice’s Piazza San Marco, saying they obtained administrative and root-level access to the operational technology environment. The group published screenshots of the control interface as purported proof of access, said the intrusion began in late March and lasted for months, and claimed it could disable defenses and flood coastal areas. The attackers also advertised alleged full root access for sale for $600.
Authorities said systems directly protecting the Basilica di San Marco were not affected, but the reported intrusion raised fresh concerns about the exposure of internet-connected operational technology tied to physical infrastructure. The incident follows broader warnings from the FBI, CISA, and NSA that Iran-linked actors are targeting internet-exposed OT systems across critical infrastructure sectors, underscoring how compromises of control systems can create immediate real-world safety and resilience risks.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
Following reports of the breach, authorities stated that critical systems directly protecting the Basilica di San Marco were not affected. The response sought to limit concern about immediate impact on the most sensitive flood protection assets.
The attackers claimed administrative and root-level access to the Venice San Marco flood defense system, published screenshots of control interfaces as evidence, and offered root access for $600. They said they could disable defenses and flood coastal areas, presenting the breach as proof of critical infrastructure weakness and political leverage.
The FBI, CISA, and NSA warned that Iran-linked actors were targeting internet-exposed operational technology systems across critical infrastructure sectors. The advisory provided broader context for rising risks to OT environments.
According to reporting, attackers calling themselves "Infrastructure Destruction Squad" or "Dark Engine" began compromising the hydraulic pump and flood risk reduction system protecting Venice’s Piazza San Marco in late March. The group claimed it maintained access for months and obtained administrative-level control.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.