Two further questions remain open. INC Ransom’s September 2 listing of Policlinico Triestino is a public claim by an alleged ransomware group, not established attribution. And a September 3 statement republished by NordestNews and attributed to Policlinico Triestino’s Direction said that no elements had emerged confirming theft of patient data. That was the organization’s stated position at the time, not a final forensic finding.
Those distinctions matter especially in healthcare. A cyberattack can seriously affect patients and clinical staff through loss of availability even before investigators establish whether systems were encrypted, data was taken, or a particular criminal group was responsible. The immediate story is continuity of care; attribution and breach assessment require their own evidence.
What is established about the disruption
A September 3 statement republished by NordestNews and attributed to Policlinico Triestino’s Direction described an “attacco informatico.” It said information systems, telephony and email were unavailable at the group’s Friuli Venezia Giulia sites, and that reports had been made to Italy’s national cyber authorities and incident-response structures, the privacy regulator and Postal Police.
RAI independently corroborated the operational disruption. Its reporting described appointments, operations and diagnostic examinations being affected while service restoration work continued. Outpatient activity was progressively returning, but radiology and laboratory recovery was reported as more complex. Salus operating rooms were scheduled to reopen on September 7; that was a stated plan at the time, rather than confirmation that reopening happened.
The regional qualification is important. The reported outage affected the group’s Friuli Venezia Giulia sites, not every location in its wider organization. Reporting said the group’s sites outside the region were unaffected.
The group’s current corporate material lists five care clinics in its national portfolio: Salus, Pineta del Carso, Campolongo Hospital, COF Lanzo and Policlinico San Marco, alongside several residential-care facilities. That national portfolio should not be mistaken for the affected Friuli Venezia Giulia estate. In particular, the available reporting does not place Campolongo Hospital, COF Lanzo or Policlinico San Marco within the affected regional sites; it said locations outside Friuli Venezia Giulia were unaffected. Nor does the available record establish the technical scope at each affected site or show that every clinical service experienced the same degree of interruption.
This was therefore more than a narrow back-office incident, but its precise boundaries should not be overstated. Healthcare delivery relies on interdependent scheduling, communications, records, diagnostic workflows and coordination systems. Losing phones and email alongside core IT can sharply reduce capacity and predictability even where staff can continue some work through manual fallback procedures.
INC Ransom’s claim is not proven attribution
On September 2, a ransomware tracking service recorded a Policlinico Triestino entry associated with INC Ransom. RAI reported the alleged attribution as a claim still to be verified, and said the question of responsibility remained under investigation. That qualification is central, not a minor technicality.
Criminal leak sites can provide useful early warning, but their contents are attacker-controlled assertions rather than independent forensic proof. A group may accurately claim an intrusion, exaggerate its role, make a false claim, or hold material whose origin and relevance have not been publicly validated. A tracker entry indicating the existence of a purported sample does not establish that the material is authentic Policlinico Triestino data, that it was obtained in this incident, or that INC Ransom possesses it.
The September 3 statement republished by NordestNews and attributed to the group’s Direction said no elements had emerged that could confirm a theft of patient data. This is not proof that data could never be found to have been taken. It is a contemporaneous account of what had not been established at that point in the investigation.
The available evidence supports a deliberately limited reading:
- Confirmed: A cyberattack caused substantial disruption to Policlinico Triestino’s Friuli Venezia Giulia operations.
- Reported but unverified: INC Ransom listed Policlinico Triestino on September 2.
- Not publicly established: The responsible actor, initial access route, malware used, whether encryption occurred, whether data was exfiltrated, and whether a ransom was demanded, negotiated or paid.
Blurring those categories can create unnecessary alarm for patients and obscure the operational disruption that has already been documented. It also risks turning an investigative lead into a conclusion before investigators have released supporting evidence.
Why availability alone makes this a serious healthcare incident
Ransomware discussions often focus on privacy: whether attackers stole sensitive files and might publish them. Many modern extortion operations combine data theft with encryption or threats of disclosure. But availability is an equally vital security property, particularly in a clinical environment.
A clinic or hospital can face immediate and serious disruption when it loses access to scheduling, communications, laboratory workflows or diagnostic support. That remains true if a later investigation finds no evidence of personal-data exfiltration. Inability to contact patients, coordinate staff or use ordinary digital processes can force postponements, manual workflows and reduced service availability.
The reported suspensions and limitations on examinations, admissions and interventions demonstrate that practical consequence. A confirmed data breach would raise additional privacy questions, but it is not needed to recognize the incident’s severity.
For patients, the most useful immediate information is operational rather than speculative: whether an appointment, examination or admission will proceed; which alternative contact channels are available while ordinary phones and email are impaired; and whether a future notice is needed if a data breach is confirmed. The available material does not establish how individuals would be notified should investigators ultimately identify a personal-data breach.
A prior INC campaign offers defensive leads, not a reconstruction
Italy’s CSIRT documented an INC ransomware campaign in April 2025. It described INC as a ransomware-as-a-service operation that emerged around July 2023 and uses double extortion. That bulletin can help defenders understand previously observed risks, but it does not establish how the Policlinico Triestino attack occurred.
In the earlier campaign, initial access typically involved exposed management interfaces without multi-factor authentication or unpatched perimeter systems. The observed follow-on activity included Advanced IP Scanner, Impacket SMBExec, LSASS credential dumping, Mimikatz and deployment of a file named win.exe.
Those details are threat intelligence, not a technical reconstruction of this event. Public reporting and the available statement do not establish whether the Policlinico Triestino incident involved those tools, exposed remote administration, missing patches, credential theft, encryption or any other particular technique. Applying the older chain to this case would convert a reasonable defensive hypothesis into an unsupported conclusion.
Still, the prior campaign has practical relevance for Windows administrators. Externally exposed management services deserve close scrutiny; where feasible, remote administration should be protected by multi-factor authentication. Perimeter-facing systems need timely patching and an accurate inventory, while security teams need visibility into suspicious remote execution, unexpected administrative credential use, reconnaissance activity and attempts to access credential material in LSASS.
No one detection proves an INC intrusion. SMBExec, Mimikatz and related activity require context, and attackers adapt their methods. The broader lesson is that identity protections, exposure reduction and monitoring for lateral movement are essential safeguards against the kinds of behaviors documented in the earlier campaign.
For healthcare IT, technical controls must be matched with recovery planning that reflects clinical priorities. A backup that exists but cannot restore the systems needed for care quickly enough does not by itself resolve an availability crisis. Plans need to identify restoration priorities, safe fallback processes during telephone and email outages, and clear authority for communicating changes to staff, patients and partner organizations.
NIS2 relevance does not establish NIS2 status
The incident also shows why legal scope requires careful language. NIS2 includes healthcare providers in a high-criticality sector. In the ordinary case, it applies to covered public or private entities that meet the medium-enterprise threshold or are larger, though the framework also contains size-independent exceptions.
For essential and important entities within scope, NIS2 sets staged reporting requirements for significant incidents: an early warning within 24 hours, an incident notification within 72 hours, and a final report no later than one month after the incident notification.
It would nevertheless be wrong to declare Policlinico Triestino an NIS2 essential or important entity solely because it is an accredited private healthcare provider. The available material establishes the sector connection, not the group’s specific classification, size assessment, applicable exception or formal identification under the relevant regime.
The same caution applies to privacy compliance. The September 3 statement republished by NordestNews and attributed to the group’s Direction said reports had been made to the privacy regulator. That does not establish that investigators will conclude a personal-data breach occurred, that any notification will be updated, or that notice to affected people will be required. Cybersecurity incident reporting and personal-data breach assessment can overlap, but they are not interchangeable processes.
Italy’s ransomware statistics need the same caution
A tracker reported 148 confirmed public ransomware claims against Italian targets in the first half of 2026, an average of 24.7 each month. It identified manufacturing as the most-hit sector, with 59 victims.
That number should not be recast as 148 independently verified compromises. It is a count of public claims tracked by the service: a potentially useful indicator of criminal activity, but not a complete forensic count of successful ransomware incidents. It also does not support an assertion that healthcare was Italy’s most-targeted sector in that period; the reported sector finding was manufacturing.
Healthcare does not need to top a threat ranking for the consequences to be acute. Sensitive information, time-critical services and dependence on continuously available systems make a major technology outage consequential in its own right.
What to watch next
The most meaningful further updates would answer specific operational and investigative questions. Have telephone, email, radiology, laboratory and clinical services fully recovered in the affected Friuli Venezia Giulia sites? Did the planned Salus operating-room reopening take place? Have investigators identified the malware family or initial access path? Has any patient, employee, financial or operational data been confirmed as taken? And has any attribution to INC Ransom gained independent support?
Until then, the evidence supports a firm but narrow conclusion. Policlinico Triestino suffered a disruptive cyberattack with tangible effects on healthcare services in Friuli Venezia Giulia, while sites outside the region were reported unaffected. INC Ransom’s listing is an important lead under investigation, not established responsibility, and the available record does not confirm patient-data theft.
For Windows and security teams, the enduring lesson is to treat loss of core services as a major security incident before attribution is settled. Reducing exposure of management interfaces, enforcing multi-factor authentication, patching perimeter systems, monitoring for credential access and remote execution, and rehearsing recovery around patient-facing priorities are all practical resilience measures. In healthcare, that resilience is part of continuity of care, not merely an IT performance target.