Skip to main content
Back to overview
Medium

Data of Italian rail operator FS Italiane Group exposed via Almaviva data breach

Hacker claims to steal 2.3TB data from Italian rail group, Almaviva Data from Italy's national railway operator, the FS Italiane Group, has been exposed after a threat actor breached the organization's IT services…

Key points

  • Data exposed due to a breach at IT services provider Almaviva.
  • FS Italiane Group is Italy's national railway operator.
  • 2.3 TB of data stolen from Almaviva, impacting FS Italiane Group.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Threat source not confirmed

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
Nov 20, 2025
Updated
Jul 22, 2026
Confidence
Medium
Evidence
3 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch ransomware, endpoint compromise and business interruption exposure.

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data, Server or cloud data store

Mentioned entities

FsitalianeData DisclosureFS Italiane GroupAlmavivaHackerItalianItalyAlmaviva. TheAccordingCRM

Quick context

Questions about this signal

What happened in this signal?

Hacker claims to steal 2.3TB data from Italian rail group, Almaviva Data from Italy's national railway operator, the FS Italiane Group, has been exposed after a threat actor breached the organization's IT services provider, Almaviva. The hacker claims to have stolen 2.3 terabytes of data and leaked it on a dark web forum. According to the threat actor's description, the leak includes confidential documents and sensitive company information. Almaviva is a large Italian company that operates globally, providing services such as software design and development, system integration, IT consulting, and customer relationship management (CRM) products. Andrea Draghetti, Head of Cyber Threat Intelligence at D3Lab, says the leaked data is recent, and includes documents from the third quarter of 2025. The expert ruled out the possibility that the files were recycled from a Hive ransomware attack in 2022. "The threat actor claims the material includes internal shares, multi-company repositories, technical documentation, contracts with public entities, HR archives, accounting data, and even complete datasets from several FS Group companies," Draghetti says. "The structure of the dump, organized into compressed archives by department/company, is fully consistent with the modus operandi of ransomware groups and data brokers active in 2024–2025," the cybersecurity expert added. Almaviva is a major IT services provider with over 41,000 employees across almost 80 branches in Italy and abroad, and an annual turnover of $1.4 billion last year. FS Italiane Group (FS) is a 100% state-owned railway operator and one of the largest industrial companies in the country, with more than $18 billion in annual revenue. It manages railway infrastructure, passenger and freight rail transport, and also bus services and logistics chains. While BleepingComputer’s press requests to both Almaviva and FS went unanswered, the IT firm eventually confirmed the breach via a statement to local media . “In recent weeks, the services dedicated to security monitoring identified and subsequently isolated a cyberattack that affected our corporate systems, resulting in the theft of some data,”  Almaviva said. “Almaviva immediately activated security and counter-response procedures through its specialized team for this type of incident, ensuring the protection and full operability of critical services.” The company also stated that it has informed authorities in the country, including the police, the national cybersecurity agency, and the country’s data protection authority. An investigation into the incident is ongoing with help and guidance from government agencies. Almaviva promised to transparently provide updates as more information emerges from the investigation. Currently, it is unclear if passenger information is present in the data leak or if the data breach is impacting other clients beyond FS. BleepingComputer has contacted Almaviva with additional questions, but we have not received a response by publication time. In a public statement regarding the incident, Almaviva said that it identified and isolated the cyberattack "resulting in the theft of some data." "Almaviva immediately activated safety and response procedures through its specialized team for this type of incident, ensuring the protection and full operation of critical services," the company stated. The incident did not impact activities and operations, "thanks to the business continuity measures and procedures specifically designed for this type of scenario." Update [November 22]: Article updated to include information from Almaviva's public statement released after publishing. Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen. The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. NAIC says public data stolen in ShinyHunters' PeopleSoft breach DentaQuest data breach exposed info of 2.6 million accounts U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalog OpenAI AI models exploited zero-days to reach Hugging Face in benchmark test Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522 Zimbra 10.1.20 patches multiple security issues, including a critical command injection bug Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access Dutch Intelligence Warns Russia Uses Hacked IP Cameras for Military Espionage Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now! CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits OpenSSL Fixes HollowByte Memory Exhaustion Bug Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer's Network U.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog Ernst & Young (EY) Investigates Data Breach Involving Third-Party Support Tickets A cyberattack hit Nichirei, one of Japan's largest food companies New Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RAT U.S. CISA adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog Internet Archive was breached twice in a month The Internet Archive was breached again, attackers hacked its Zendesk email support platform through stolen GitLab authentication tokens. The Internet Archive was breached via Zendesk, with users receiving warnings about stolen GitLab tokens due to improper token rotation after repeated alerts. BleepingComputer first reported the news of the incident, after it received several messages from people who received replies to their old Internet Archive removal requests, warning that the organization had been breached again because they did not correctly rotate their stolen authentication tokens. The message highlights a poor security posture by the Internet Archive. Despite being informed weeks prior, the organization’s failure to rotate exposed API keys, particularly the Zendesk token with access to over 800,000 support tickets, reflects poor incident response. Poor cyber hygiene increases the risk of further data breaches and could undermine user trust.

When was this signal reported?

Shadow Tier lists Nov 20, 2025 as the signal date.

Which organization is connected to this signal?

Fsitaliane is the organization connected to this public signal.

Explore Fsitaliane
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence