HomeIntelligenceBrief
BREACH BRIEF🟠 High Ransomware

LockBit5 and Qilin Ransomware Campaigns Hit 148 Italian Organizations, Manufacturing Targeted

A ransomNews tracker records 148 ransomware claims against Italian entities in H1 2026, led by LockBit5 and Qilin. Manufacturing firms suffered the greatest impact, and attackers reported exfiltrating about 13.4 TB of data. The incident underscores the need for continuous control monitoring and audit‑ready evidence under SOC 2.

LiveThreat™ Intelligence · 📅 July 27, 2026· 📰 securityaffairs.com
🟠
Severity
High
RW
Type
Ransomware
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
securityaffairs.com

LockBit5 and Qilin Ransomware Campaigns Hit 148 Italian Organizations, Manufacturing Targeted

What Happened — A semi‑annual tracker released by ransomNews documents 148 confirmed ransomware claims against Italian entities in the first half of 2026. The attacks, attributed to the LockBit5 and Qilin groups, averaged 25 claims per month and resulted in the alleged exfiltration of roughly 13.4 TB of data (reported in 64 cases). Manufacturing firms were the most affected, accounting for 59 victims (≈40 % of all incidents).

Why It Matters for Compliance & Audit Readiness

  • Ransomware incidents expose gaps in control design, testing, and continuous monitoring—core pillars of a SOC 2‑aligned program.
  • Demonstrating that critical controls (e.g., change management, privileged‑access review, backup integrity) are continuously evidenced can serve as audit‑ready proof that the organization mitigates ransomware risk.
  • Verisq’s Control Mapping capability helps map these controls to SOC 2 criteria and automatically collect evidence for a defensible audit trail.

Who Is Affected – Primarily Italian manufacturing firms, with secondary impact on commerce and transport organizations.

Recommended Actions

  • Map ransomware‑related controls (e.g., backup, incident‑response, privileged‑access) to SOC 2 Trust Services Criteria.
  • Deploy continuous evidence collection for backup integrity checks and access‑log reviews.
  • Validate that incident‑response playbooks are tested and documented as audit evidence.

Source: Security Affairs

Technical Notes – The report does not disclose specific initial infection vectors; typical ransomware entry points include phishing, credential theft, and unpatched vulnerabilities. Exfiltrated data types span proprietary designs, operational technology schematics, and business records. Source: same as above

📰 Original Source
https://securityaffairs.com/196045/security/lockbit5-and-qilin-lead-ransomware-attacks-against-italian-organizations.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →