1. Executive summary
On 25 July 2026, the ransomware actor "nova" publicly claimed a compromise of SistNet (sistnet.it), a division of Sistemi Tre s.r.l. operating in the Italian ICT services market. The actor claims to have exfiltrated stolen data and provided a file-tree and samples to the victim, alongside a decrypt sample, indicating a double-extortion model combining encryption with data theft. Attribution to the "nova" group is unconfirmed — the actor has no MITRE ATT&CK profile in the verified reference data — and the technical detail of the compromise is minimal, sourced solely from the ransomware leak portal. EMEA financial services clients should treat this as a potential supply-chain concern if SistNet or Sistemi Tre s.r.l. provides ICT or security services to their environment.
2. Regulatory framing
No specific DORA/NIS2 article is directly engaged by this item. The available facts describe a claimed compromise of a third-party ICT provider, but there is no confirmed impact on a regulated financial entity, no confirmed major-incident threshold breach, and no verified contractual relationship triggering third-party risk obligations. If a client confirms SistNet as an ICT third-party provider, DORA Art. 28 (ICT third-party risk — general principles) and DORA Art. 30 (key contractual provisions with ICT third-party providers) would engage — but that relationship is not established in the source material.
3. Technical analysis & attack chain
The source material is a ransomware leak-site entry. No technical attack-chain detail, initial access vector, CVE, malware sample, or TTP is provided. The following is limited to what the source states:
- Victim identification: SistNet (sistnet.it), a division of Sistemi Tre s.r.l., providing ICT solutions including EDR-X antivirus, networking, unified communication, cloud backup, and email services to SMEs.
- Actor claim: The group "nova" claims to have exfiltrated data from SistNet. The actor states it has provided a "tree and samples from stolen data" and a "decrypt sample" to the company upon contact with their support department — consistent with a double-extortion ransomware model (encryption + data exfiltration).
- Compromised assets (single-sourced; verify before enforcement): Hudson Rock data indexed by Ransomware.live reports 1 compromised employee, 3 compromised users, 0 third-party employee credentials, and 15 external attack-surface findings for the victim's domain. This data is sourced from a third-party infostealer-intelligence platform and has not been independently corroborated. It may indicate prior infostealer infections on employee or user machines, which could represent an initial-access vector, but this is inferential.
Confidence caveat: All claims in this section rest on a single source (Ransomware.live / Hudson Rock). No law-enforcement confirmation, victim disclosure, or independent security-vendor report is available. Attribution to "nova" is unconfirmed — the actor has no MITRE ATT&CK profile in the verified reference data. No CVE, CVSS score, or CISA-KEV exploitation state is associated with this item.
4. Mitigation & containment
No technical indicators, malware samples, or vulnerability details are available from the source to support specific containment actions. The following are process-level steps:
P1 — within 24h
- Determine whether your organisation has a direct vendor relationship with SistNet / Sistemi Tre s.r.l. for ICT, security (EDR-X), networking, cloud backup, or email services. If yes, initiate vendor incident-response enquiry: confirm whether the breach is real, what data was accessed, and whether any of your data or credentials are affected.
- If SistNet provides managed services with access to your environment, review and restrict that access pending confirmation. Disable integrations or remote-access accounts if feasible.
P2 — within 72h
- If a confirmed vendor relationship exists and the breach is validated, assess whether any of your data, credentials, or systems were exposed. Rotate any credentials shared with or managed by SistNet.
- Review logs for any anomalous activity originating from SistNet-managed infrastructure or IP ranges.
P3 — within 7 days
- If SistNet is a confirmed ICT third-party provider, document the incident against your third-party risk register and assess contractual notification obligations.
- Monitor the Ransomware.live listing and any subsequent disclosures for updated indicators or leaked data.
5. Indicators of compromise
No indicators of compromise available in the source material.
Behavioural indicators
| Behaviour | Where to observe | Confidence |
|---|---|---|
| Infostealer-related credential compromise on SistNet employee/user machines (1 employee, 3 users reported) | Hudson Rock infostealer intelligence platform; not directly observable in client environment | Low — single-sourced, uncorroborated |
| Data exfiltration from SistNet environment | Victim network egress logs (if SistNet is a managed-service provider with access to client environment) | Low — actor claim only, no technical detail |
6. Detection
Insufficient indicators to author detection rules.
7. Sources
- Ransomware.live, "Ransomware: nova named SistNet (IT)," https://www.ransomware.live/id/U2lzdE5ldEBub3Zh, published 2026-07-25.
- Ransomware.live, "Ransomware: nova named Hynet (GB)" (corpus context for nova group MO), https://www.ransomware.live/id/SHluZXRAbm92YQ==, accessed 2026-07-25.
- Hudson Rock / Ransomware.live external data for victim SistNet (compromised employee/user counts, attack surface), https://www.ransomware.live/id/U2lzdE5ldEBub3Zh, accessed 2026-07-25.
8. Adverse Trace position
This is a low-confidence, single-sourced ransomware claim against an Italian ICT services provider. The actor "nova" has no confirmed MITRE ATT&CK profile and the attribution is unconfirmed. No CVE, CVSS, or CISA-KEV data applies. The primary risk to EMEA financial services clients is supply-chain exposure: SistNet provides managed security (EDR-X), cloud backup, and networking services to SMEs, and any client using SistNet as an ICT third-party provider should treat this as a potential third-party incident requiring vendor enquiry and access review. We will monitor for corroborating reporting, leaked indicators, or law-enforcement confirmation and update this advisory if the claim is validated or technical indicators emerge.
Published via PulseTrace — Adverse Trace threat intelligence.