Italian university La Sapienza still offline to mitigate recent cyber attack
嗯,用户让我用中文总结这篇文章,控制在一百个字以内,而且不需要特定的开头。首先,我得通读文章内容,抓住主要信息。 文章讲的是罗马的La Sapienza大学遭受了网络攻击,导致系统离线。攻击发生在2月2日,学生们无法进行考试预约、查看学费支付情况或访问教师联系方式。大学通过社交媒体发布有限的信息,并没有给出恢复的时间表。确认是网络攻击后,大学关闭了基础设施以防止威胁扩散,这可能是一次勒索软件攻击。 文中提到可能是一个名为Femwar02的俄罗斯网络犯罪团伙所为,使用了Bablock勒索软件。这种恶意软件通常不加密俄语设备,增加了攻击来自亲俄集团的可能性。大学已经向执法部门和意大利国家网络安全局报告了事件,正在处理紧急情况,并与相关部门协调。 技术团队正在评估安全漏洞的范围,并尝试从备份中恢复数据。但不清楚备份是否包含所有数据,有些可能在加密后无法访问。 总结一下,重点包括:大学遭受网络攻击导致离线、勒索软件嫌疑、俄罗斯背景、恢复情况不明、影响学生日常操作等。 现在需要把这些信息浓缩到100字以内,确保涵盖主要事件和影响。 </think> 罗马La Sapienza大学因网络攻击自2月2日起离线,学生无法进行考试预约等操作。初步判断为勒索软件攻击,可能由俄罗斯相关团伙实施。学校已关闭系统以防止威胁扩散,并向执法部门报告事件。目前尚不清楚数据恢复情况及攻击全部影响。 2026-2-7 18:2:53 Author: securityaffairs.com(查看原文) 阅读量:0 收藏

Italian university La Sapienza still offline to mitigate recent cyber attack

Pierluigi Paganini February 07, 2026

Rome’s La Sapienza University was hit by a cyberattack that disrupted IT systems and caused widespread operational issues.

Since February 2, Rome’s La Sapienza University, one of the most important Italian universities, has been offline due to a cyberattack. For days, students have been unable to book exams, check tuition payments, or access faculty contacts. The university has mainly communicated via social media, offering limited details and no clear timeline for full restoration.

The university only confirmed it was a victim of a cyber attack, it also added that was forced to shut down its infrastructure to mitigate the attack and prevent the threat from spreading, a circumstance that suggests a ransomware attack.

“As a precautionary measure, and in order to ensure the integrity and security of data, an immediate shutdown of network systems has been ordered,” the organization said.

Public reports confirm that the University suffered a ransomware attack that disrupted its operations. Some media reported that a new Russian cybercrime group tracked as Femwar02 is behind the attack

““What appears certain is the use of a next-generation ransomware strain known as ‘Bablock,’ the most widely used and destructive in 2025. The same malware was allegedly used by the previously unknown ‘Femwar02’ crew to breach Sapienza University’s IT systems two days ago and bring them to a standstill.” reported the Italian media outlet La Stampa. “This form of extortion malware, employed by criminal groups, typically avoids encrypting devices set to Russian or other post-Soviet languages, which has fueled concrete suspicions—confirmed by investigators—that the attack on Europe’s largest university by enrollment, with around 122,000 students, was carried out by a pro-Russian group.””

“Cyber ​​Attack Update (February 3, 2026) Sapienza is managing the emergency in a unified and coordinated manner, meeting all deadlines within its remit and working in conjunction with the other institutions involved.” reads an update published by the university. “Decisions are being made in close coordination with offices, learning and administrative structures, and student representatives on the University’s governing bodies, evaluating extensions and flexible arrangements to protect careers.”

The university reported the incident to law enforcement and Italian National Cybersecurity Agency (ACN), who are involved in the response.

“Due to the IT infrastructure shutdown, the Infopoints will not be able to provide further information that, under normal circumstances, would require access to digital systems and databases” reads the last update. “[more details on the opening hours and days of the Infopoints are on the social media pages of the individual faculties]”

The media report links the security breach to Bablock/Rorschach ransomware based on malware traits and tactics. First seen in 2023, this malware family borrows code from leaked Babuk, LockBit v2.0, and DarkSide code.

As the investigation continues, university technicians are working to determine the scope of the security breach before restoring data from backups. It’s also unclear whether the backups contain all data or if some remains inaccessible after ransomware encryption.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, La Sapienza)




文章来源: https://securityaffairs.com/187702/cyber-crime/italian-university-la-sapienza-still-offline-to-mitigate-recent-cyber-attack.html
如有侵权请联系:admin#unsafe.sh