Currently free during beta - premium features coming soon. Subscribe now to lock in early access.

Ransomware: qilin claims Sicc (IT) — Not Found

BREACH Breaches & Incidents · · ransomwarelive

AI Analysis

A new ransomware incident has been published on the ransomware.live leak site, attributed to the Qilin ransomware group, targeting Sicc, an Italian IT services company. The breach was listed on July 18, 2026, under the BREACH framework, indicating that the threat actor has claimed responsibility and likely exfiltrated data. No specific details about the data compromised or ransom demands have been disclosed, but the publication confirms a successful attack.

Organizations in the Italian IT services sector, particularly those with supply chain dependencies on Sicc, are directly affected. Any company that relied on Sicc for managed services, cloud infrastructure, or data processing should assess potential downstream exposure. The broader EU IT services sector should treat this as a warning, as Qilin is known for targeting critical infrastructure and service providers to amplify impact.

Compliance teams should immediately verify whether their organization or any third-party vendors have a relationship with Sicc. If so, initiate incident response protocols, including isolating affected systems and reviewing data access logs. Under the EU’s NIS2 Directive and GDPR, this incident may trigger mandatory breach notification obligations within 72 hours. Teams should also update their ransomware risk assessments and ensure backup integrity is tested, as Qilin often targets backups to increase leverage.

Get notified about BREACH changes

Subscribe to our free weekly digest covering 24 compliance frameworks.