1. Executive summary
On 2026-07-10, the ransomware group "Deadlock" publicly claimed a compromise of Integra S.r.l. and L'Operosa S.p.A. (associated with C.A.A. "Giorgio Nicoli" S.r.l., domain www.caa.it), based in Italy. The actor threatens to release stolen files on 2026-05-10 (per the leak page text; this date precedes the claim date and may reflect a typo or a countdown artefact). Attribution to the "Deadlock" group is unconfirmed — the named actor has no MITRE ATT&CK profile in the verified reference data. No CVE, CVSS score, or CISA-KEV exploitation state is associated with this item. EMEA financial services clients should assess exposure to the named Italian entities and monitor for potential supply-chain or third-party impact.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 17: ICT-related incident management process | Ransomware claim involving Italian corporate entities that may sit in a financial institution's ICT third-party or supply chain. | If a client has a vendor or interconnection with Integra, Operosa, or C.A.A. Giorgio Nicoli, the incident management process must be invoked to assess impact. |
| DORA Art. 18: classification of ICT-related incidents and cyber threats | A ransomware data-theft/extortion claim constitutes a cyber threat that may require classification if it affects a client's ICT assets or services. | Classify the incident per internal taxonomy if exposure is confirmed. |
| DORA Art. 28: ICT third-party risk — general principles | The named victims are corporate entities that could function as ICT third-party providers to financial institutions. | Review third-party risk registers for any contractual relationship with the named entities. |
| NIS2 Art. 21(2)(d): supply chain security measures | Ransomware claim against entities that may be in the supply chain of NIS2 in-scope organisations. | Assess supply-chain exposure and apply security measures for suppliers if a relationship exists. |
| NIS2 Art. 23: incident reporting obligations | If a client's own ICT services are impacted via a third-party compromise, reporting obligations may be triggered. | Prepare for regulatory notification if the incident propagates to in-scope systems. |
3. Technical analysis & attack chain
Confirmed facts are limited. The source material is a ransomware leak-site listing; no forensic detail, initial-access vector, CVE, malware sample, or technical indicator is provided.
What is confirmed
- Actor claim: The group "Deadlock" posted a claim naming "Integra and Operosa" as victims.
- Victim entities: C.A.A. "Giorgio Nicoli" S.r.l., Integra S.r.l., and L'Operosa S.p.A. are named in the leak text. The associated domain is
www.caa.it. - Country: Italy (IT).
- Threat: Stolen files are stated to be made available for download. The stated release date of "May 10, 2026" precedes the claim publication date of 2026-07-10; this discrepancy is unexplained in the source and may be an error or a re-posted countdown.
- Actor context: A related Deadlock claim (corpus-1) names EDISA and INVERTIGE, Spanish companies headquartered in Valencia, indicating the group is targeting multiple geographies and sectors.
What is NOT confirmed
- Attribution: "Deadlock" has no MITRE ATT&CK profile in the verified reference data. Attribution is unconfirmed; treat the group name as a leak-site label only.
- Initial access vector: No detail provided. No CVE is associated.
- Malware/payload: No malware family, variant, or sample is identified.
- Persistence, privilege escalation, C2, lateral movement: No technical detail available.
- Data exfiltration: The claim implies data theft (files to be published), but no exfiltration volume, file types, or data categories are specified.
- Ransomware deployment vs. data extortion: The source labels this as "ransomware," but the described behaviour (file publication threat) is consistent with data-theft/extortion. No encryption activity is confirmed in the source.
Confidence caveat: All technical claims rest on a single source (ransomware.live indexing of the Deadlock leak site). No independent corroboration, forensic report, or victim statement is available. Verify before enforcement.
4. Mitigation & containment
Given the absence of technical detail, mitigation is exposure-based rather than IOC-driven.
P1 — Within 24 hours
- Identify third-party exposure: Search vendor management registers, procurement databases, and ICT third-party risk registers for any relationship with Integra S.r.l., L'Operosa S.p.A., or C.A.A. "Giorgio Nicoli" S.r.l. (domain:
www.caa.it). If a relationship exists, contact the vendor to confirm the incident and assess data exposure. - Block/monitor the leak-site domain at the network perimeter to prevent accidental or intentional access to stolen data by staff.
P2 — Within 72 hours
- Assess data flow: If a confirmed vendor relationship exists, map all data flows, integrations, API connections, and shared systems between your organisation and the named entities. Determine whether sensitive financial, customer, or operational data was accessible to the vendor.
- Review authentication: If any shared credentials, certificates, or trust relationships exist with the named entities, rotate them immediately.
- Prepare incident classification: If impact is confirmed, classify per DORA Art. 18 and prepare for potential reporting under DORA Art. 19 or NIS2 Art. 23.
P3 — Within 7 days
- Conduct a targeted threat-hunt across environment for any indicators of compromise associated with Deadlock activity — noting that no specific IOCs are available from the source. Focus on anomalous outbound data transfers, new service accounts, and scheduled-task creation if the vendor had any network or system access.
- Update third-party risk assessments for Italian and Southern European vendors, given the related Deadlock claim targeting Spanish entities (EDISA, INVERTIGE), suggesting a regional targeting pattern.
5. Indicators of compromise
No indicators of compromise available in the source material.
6. Detection
Insufficient indicators to author detection rules.
7. Sources
- Ransomware.live, "Ransomware: Deadlock named Integra and Operosa," https://www.ransomware.live/id/SW50ZWdyYSBhbmQgT3Blcm9zYUBEZWFkbG9jaw==, published 2026-07-10.
- Ransomware.live, "Ransomware: Deadlock named EDISA and INVERTIGE," https://www.ransomware.live/id/RURJU0EgYW5kIElOVkVSVElHRUBEZWFkbG9jaw== (context only).
8. Adverse Trace position
This is a low-confidence, single-sourced ransomware/extortion claim with no associated CVE, no technical indicators, and unconfirmed actor attribution (Deadlock has no MITRE ATT&CK profile). The severity for EMEA financial services clients is conditional: if a client has a direct ICT third-party relationship with Integra S.r.l., L'Operosa S.p.A., or C.A.A. "Giorgio Nicoli" S.r.l., the risk elevates to medium pending confirmation of data exposure. The related Deadlock claim against Spanish entities (EDISA, INVERTIGE) suggests the group is actively targeting Southern European companies, which broadens the relevance for clients with regional vendor footprints. We will monitor for corroborating victim statements, forensic reports, or IOC disclosures and update this advisory if technical detail emerges. Clients should not take enforcement action based solely on this leak-site listing without independent verification.
Published via PulseTrace — Adverse Trace threat intelligence.