www.bismark.it
Qilin Ransomware Targets Retelit, Major Telecom Provider in Italy
Article Content
The Qilin ransomware group has reportedly targeted Retelit SpA, a leading telecommunications operator in Italy. This attack is part of a broader campaign that has seen a significant increase in ransomware incidents attributed to Qilin since the start of 2026. The group exploits known vulnerabilities, particularly in Ivanti and Fortinet devices, using brute force attacks on VPN credentials. Qilin employs a Ransomware-as-a-Service model, utilizing custom ransomware developed in Rust, and follows a double extortion strategy. While the attack on Retelit has not been officially confirmed, it could have serious implications for enterprise clients and public entities relying on their services. The group has been active since 2022 and has gained notoriety for its sophisticated methods. Current details on the extent of the breach or operational impacts remain unclear, with further official communications awaited.
Key Points: • Qilin ransomware group targets Retelit, a major telecom provider in Italy. • Attack methods include exploiting vulnerabilities in Ivanti and Fortinet devices. • Qilin employs a double extortion strategy, threatening data publication if ransom is not paid.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.