Adversary Intelligence — 2026-05-04

Salt Typhoon Breaches IBM Italy Subsidiary Managing Public Administration Infrastructure

In late April 2026, attackers breached Sistemi Informativi, an IBM Italy subsidiary providing IT infrastructure for Italian public agencies, and maintained undetected access for approximately twenty days, Decode39 reported. IBM confirmed the incident to La Repubblica, saying systems are stable and services restored, but declined to disclose the scope of access. Italian investigative reporting citing multiple intelligence sources attributed the operation to Salt Typhoon, a China-linked espionage group; IBM and Italian authorities have not confirmed that attribution, and forensic investigation is ongoing. Italy's Minister for Public Administration Paolo Zangrillo stated on May 3 that institutional actors and the national cybersecurity agency are working to determine the attack's origin and which systems were compromised.

Analysis
The breach marks a documented expansion of Salt Typhoon's European targeting into the government IT supply chain. Sistemi Informativi's managed-services role means twenty days of access likely spanned multiple agencies, a scope IBM has not disclosed. Attribution rests solely on Decode39's unnamed intelligence sources, with neither IBM nor Italian authorities confirming. Dwell time and target profile are equally consistent with a financially motivated operator whose Salt Typhoon attribution reflects pattern-matching against a politically salient actor rather than confirmed technical indicators. Minister Zangrillo's May 3 data-protection activation confirms Rome treats this as a live government response, and at least one further European compromise of a telecom or IT managed-services firm is likely before July 2026.
4 sources
  1. Salt Typhoon breach IBM subsidiary in Italy: a warning for Europes digital defenses - Security Affairs
  2. Salt Typhoon Suspected in Breach of IBM Italy Subsidiary Managing Public Infrastructure - Security Boulevard
  3. China-linked cyber intrusion targets Italy's public infrastructure - Decode39
  4. Pa hacker attack, Zangrillo: Start procedures to protect data - Il Sole 24 Ore

View in full brief →

UNCLASSIFIED // OPEN SOURCE