SITAV SpA Data Breach

Alleged

Ransomware claim involving SITAV SpA.

Published: Jul 14, 2026 DragonForce
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
SITAV SpA
Industry
Business Services
Threat Actor
DragonForce
Date of Incident
Jul 14, 2026

Executive Summary

SOCRadar has identified that SITAV SpA, an Italy-based manufacturing company, has been listed by the DragonForce ransomware group on their dark web leak portal. The listing date was July 14, 2026. This incident highlights the continued targeting of the manufacturing sector by ransomware groups due to its reliance on identity systems and production uptime. SITAV SpA is the latest Italian victim added to DragonForce’s list of recent attacks, which have predominantly targeted companies in the United States, United Kingdom, and Germany. DragonForce has been active over the 60 days prior to this listing, claiming 76 other victims. Their primary focus areas are business services, manufacturing, and technology. The group commonly gains initial access through credentials harvested by stealers, which are then sold on underground marketplaces. These credentials are used to access internal systems such as Microsoft 365, VPNs, and other remote access portals before deploying ransomware.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry revealed a significant initial access exposure for the sitav[.]eu domain. The data showed numerous employee credentials compromised on internal identity and employee portals, including SITAV’s Active Directory Federation Services (ADFS) endpoint (login[.]sitav[.]eu/adfs/ls) and an employee portal (dipendenti[.]sitav[.]eu). Multiple corporate @sitav[.]eu email addresses were found on these internal identity endpoints. The presence of at least one corporate account on both internal and third-party services suggests a potential workstation compromise or the reuse of credentials. The compromised credentials were valid from December 2024 to early July 2026, indicating they remained unrotated for over a year. While this stealer-log evidence does not definitively confirm DragonForce’s use of these specific credentials, the pattern of corporate logins against ADFS and internal identity portals aligns with the typical kill chain observed in incidents involving this class of threat actor. The information suggests a routine initial access vector for ransomware groups like DragonForce, where they leverage compromised credentials to gain entry into victim networks. Recommended next steps include resetting passwords, enforcing multi-factor authentication (MFA) on affected accounts, particularly for ADFS/SSO identities, and conducting endpoint forensics on the user whose credentials appeared on both internal and third-party services.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.