LockBit5 and Qilin Ransomware Campaigns Hit 148 Italian Organizations, Manufacturing Targeted
What Happened — A semi‑annual tracker released by ransomNews documents 148 confirmed ransomware claims against Italian entities in the first half of 2026. The attacks, attributed to the LockBit5 and Qilin groups, averaged 25 claims per month and resulted in the alleged exfiltration of roughly 13.4 TB of data (reported in 64 cases). Manufacturing firms were the most affected, accounting for 59 victims (≈40 % of all incidents).
Why It Matters for Compliance & Audit Readiness
- Ransomware incidents expose gaps in control design, testing, and continuous monitoring—core pillars of a SOC 2‑aligned program.
- Demonstrating that critical controls (e.g., change management, privileged‑access review, backup integrity) are continuously evidenced can serve as audit‑ready proof that the organization mitigates ransomware risk.
- Verisq’s Control Mapping capability helps map these controls to SOC 2 criteria and automatically collect evidence for a defensible audit trail.
Who Is Affected – Primarily Italian manufacturing firms, with secondary impact on commerce and transport organizations.
Recommended Actions
- Map ransomware‑related controls (e.g., backup, incident‑response, privileged‑access) to SOC 2 Trust Services Criteria.
- Deploy continuous evidence collection for backup integrity checks and access‑log reviews.
- Validate that incident‑response playbooks are tested and documented as audit evidence.
Source: Security Affairs
Technical Notes – The report does not disclose specific initial infection vectors; typical ransomware entry points include phishing, credential theft, and unpatched vulnerabilities. Exfiltrated data types span proprietary designs, operational technology schematics, and business records. Source: same as above