
La Repubblica broke this yesterday. The target was Sistemi Informativi, an IBM-owned company that runs IT infrastructure for Italian ministries, INPS, INAIL, national cloud, and several PNRR (EU recovery fund) projects. Essentially a single point of failure for a large chunk of Italy's public sector.
IBM confirmed the incident. This looks like intelligence gathering. Services are reportedly restored but scope of exfiltration is unknown.
Attribution to a Chinese state-linked group is being reported by Italian media but hasn't been formally confirmed by government or a major threat intel vendor yet.
Sources: https://www.repubblica.it/tecnologia/2026/05/03/news/esclusivo_pa_italiana_e_non_solo_attaccata_da_un_gruppo_di_hacker_cinesi-425320702/
https://securityaffairs.com/191638/apt/salt-typhoon-breach-ibm-subsidiary-in-italy-a-warning-for-europes-digital-defenses.html