Italian authorities said they blocked Russian-linked cyberattacks aimed at websites tied to the Winter Olympics, preventing disruption as organizers prepared for the games. The activity revived concerns first underscored by the 2018 Winter Olympics opening ceremony attack, when a destructive operation sought to interrupt a high-profile international sporting event and demonstrated how cyber operations can be used to undermine global broadcasts, logistics, and public confidence.
Threat intelligence reporting also described a broader surge in hacktivist activity ahead of the 2026 Winter Olympics, alongside protests and suspected sabotage risks. The combined reporting indicates that Olympic infrastructure, public-facing sites, and related organizations faced a heightened threat environment in which politically motivated actors and state-linked operators appeared poised to use cyberattacks to disrupt services, shape narratives, and embarrass host institutions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Intel 471 reported increased hacktivist activity, protests, and suspected sabotage risks in the run-up to the 2026 Winter Olympics. The report highlighted a heightened cyber threat environment surrounding the event.
Italian authorities said they had averted cyberattacks linked to pro-Russian actors targeting websites associated with the Milan-Cortina 2026 Winter Olympics. The announcement reflected active defensive measures ahead of the games.
A cyberattack targeted the opening of the PyeongChang Winter Olympics, disrupting internet, television, and IT systems tied to the event. The incident became known as a significant sabotage operation against Olympic infrastructure.
3 references tracked. Mallory keeps watching after this page renders.
intel471.com
Open sourceapnews.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.