
Offensive of cyberattacks against large companies and the Public Administration. According to the latest data presented by the National Cybersecurity Agency (ACN), 2025 was characterized by a significant increase in the volume of hostile activities (2,729 events handled), with a monthly average increase of 38%, from 165 to 227. Despite this increase, incidents with confirmed impacts grew by only +7%, reaching 615 cases. This emerges from the report “Cybersecurity, fraud and data privacy,” produced by Deloitte as Knowledge partner of the first edition of WeSec – The Security Salon, promoted by ABI, which will be held in Milan on September 22 and 23, 2026.
Read more Darializa Avila Chevalier, the new face of American socialists
Ask the Sun
The questions are automatically suggested by 24Ore AI
based on the content displayed.
“The progressive digitalization of services, payments, and critical infrastructures contributes to making cybersecurity a strategic component for the resilience of the economic and financial system, the protection of trust of citizens and businesses, and business continuity,” said Fabio Battelli, Enterprise security leader at Deloitte. “For the banking sector, cybersecurity represents an enabling factor for digital innovation and, increasingly, for the secure adoption of Artificial Intelligence, as well as an essential component of risk management and compliance with the European regulatory framework.”
The Public Administration remains the most exposed sector in absolute value. In fact, over 1,100 events detected by the ACN in 2025 and over 28% of Italian incidents in the Clusit sample (+about 290%) can be considered predominantly “demonstrative” attacks, but with insidious profiles, as they are directly linked to the exposure of public databases and compromises of web providers involving multiple entities. The manufacturing sector is the point of greatest structural vulnerability. About 16% of global attacks on the sector hit Italian organizations, with ransomware types concentrated on SMEs and IT/OT convergence turning incidents into production stoppages. The energy sector, a preferred target of targeted phishing, has systemic relevance for crime and state actors.
Read more Mediterranean Games: Italy shines with medals, swimming on the laurels for the disciplines
AI Alarm
In the planning and preparation phase of cyberattacks, criminal gangs make full use of Artificial Intelligence, which thus allows amplifying cyberattacks and fraud. ACN, Clusit, and the European Union Agency for Cybersecurity document the use of generative AI to produce more credible, personalized, and scalable phishing and spear phishing campaigns and to automate attack phases once manual, from reconnaissance to vulnerability discovery to malicious code development. On the fraud side, data from the Italian Postal Police confirm the spread of cloned voices and deepfake videos supporting scams and false investments. Technological evolution also opens up a scenario of progressively more autonomous threats, in which AI-based agents can conduct increasing portions of the attack chain with limited human supervision, further compressing the reaction times available to defenders. “The picture emerging from the report highlights how the decisive variable will be risk governance capability,” explains Daniele Frasca, Senior Partner at Deloitte. “In this context, five priorities emerge for top management: to permanently bring cyber risk onto the Board’s agenda; to shift the focus from protection alone to resilience; to strengthen the oversight of the human factor and digital identities; to govern AI simultaneously as a defense lever and a new source of risk; and finally, to extend oversight to the entire digital supply chain of all providers. Compliance must also evolve in this direction: GDPR, NIS2, DORA, CRA, and AI Act cannot be managed as separate exercises but must converge into an integrated risk and control framework.”
Thus in 2025
During 2025, over 2,700 incidents were recorded while cybersecurity investments grew by 12% according to estimates from the Politecnico di Milano Observatory, with spending of 2.78 billion euros. Cybersecurity spending increased with a trend significantly higher than the +1.5% of national digital spending. The increase was contributed to by European PNRR funds recorded in the public administration (+28%), finance (+22%), and logistics and transport (+18%). Additionally, it emerges that over one-third of large companies (34%) suffered attacks last year, and 3% recorded direct impacts on their operations. Furthermore, 57% of them initiated a structural review of incident response plans, and 70% of large companies foresee further budget increases in 2026 on the cybersecurity front. The overall criminal dimension emerges from the latest data from the Italian Postal Police, which highlights that in 2025, 51,560 cases were handled, of which 27,085 relate to cybercrime, with sums stolen exceeding 269 million euros (+16% over 2024). The increasingly widespread use of AI for fraud purposes emerges, through cloned voices, deepfakes, and personalized phishing. Added to this is the issue of personal data breaches, as notifications sent by the Privacy Guarantor have now reached 2,415 in 2025 (+10% over the previous year), with sanctioning activity of over 37 million euros specifically concentrated on security measure deficiencies. On the payment systems front, data from the Bank of Italy updated to the second half of 2025 show a fraud rate of 0.003% of transactions with 10 fraudulent activities per 100,000 transactions. In particular, remote operations remain among the most exposed to possible fraud attempts: cards 0.060% in value regarding card use in e-commerce, against 0.006% for physical POS. The Public Administration remains the most exposed sector in absolute value. In fact, over 1,100 events detected by the ACN in 2025 and over 28% of Italian incidents in the Clusit sample (+about 290%) can be considered predominantly “demonstrative” attacks, but with insidious profiles, as they are directly linked to the exposure of public databases and compromises of web providers involving multiple entities. The manufacturing sector is the point of greatest structural vulnerability. About 16% of global attacks on the sector hit Italian organizations, with ransomware types concentrated on SMEs and IT/OT convergence turning incidents into production stoppages. The energy sector, a preferred target of targeted phishing, has systemic relevance for crime and state actors.
Read more Varese, bricklayer dies crushed at a construction site