Widespread Fallout after Cyberattack hits Italy’s National Railway Company

January 7, 2025

INCIDENT

Italian State Railways (FS) and its subsidiaries Trenitalia and Italian Rail Network (RFI) suffered a major ransomware attack on March 23 . The attack severely impacted ticketing systems, passenger information displays, and internal communications.

FS implemented emergency measures, allowing passengers to purchase tickets on trains without penalties. The primary focus was on restoring critical systems and minimizing further disruption to passenger services. Freight transport by rail was temporarily suspended for 24 hours. Reportedly affecting FS, Metrans Rail of Czech Republic, HUPAC of Switzerland and Lineas of Belgium.

Metrans Rail of Czech Republic shutdown their Italian operations for 24 hours the following day. They stated it was temporarily not possible to cross the border at Austria and Slovenia. Marc Jansen, director of operations at carrier Hupac, said trains have been standing still for 24 hours. Arno van Deursen, Country Manager Lineas NL said “Our trains to and from Italy have been standing still for about 15 hours".

Elements were found on the computer network of Trenitalia and RFI that could be linked to a cryptolocker infection. Italian authorities, including the Postal Police's National Cybercrime Center (Cnaipic) and the National Cybersecurity Agency (Acn), launched a joint investigation.

Incident Date

March 23, 2022

Estimated Cost

unknown at this time